Contribute to the identification and mitigation of financial industry’s cyber security risk by undertaking continuous horizontal surveillance of the cyber threat landscape and monitoring of financial institution (FI)’s technology adoption and utilisation strategy in upholding the Bank’s mandate.
- Develop and enhance effective surveillance infrastructure, supervisory tools and framework for early detection of emerging cyber risks to aid in macro / micro supervisory monitoring and risk mitigation strategies for the financial sector
- Ensure strong collaboration and able to influence / communicate with the industry players to facilitate knowledge sharing and best practices.
- Drive initiatives that enhance the ability of financial institutions and market infrastructures to prevent, detect, and recover from cyber incidents.
- Contribute to the capacity building of IT and prudential supervisors in cyber risk management.
This role enables effective risk oversight and policy development, ensuring financial institutions adopt sound practices and best practices in cyber security risk governance aligned with regulatory expectations and industry standards.
Responsibilities- Lead and perform industry-wide horizontal assessments of adopted cyber security risk management models, methodologies or practices with the aim to uncover common practices and potential gaps or areas of improvement
- Facilitate industry-wide cyber security risk improvement programs
- Develop and enhance effective surveillance infrastructure, supervisory tools and framework for early detection of emerging cyber risks to aid in macro / micro supervisory monitoring and risk mitigation strategies for the financial sector
- Develop and review prudential policies, standards, guidelines and best practices on cyber security risk management to ensure pragmatic implementation of regulatory policies
- Provide technical input on cyber risk management in new-to-market product and technology approval applications to ensure early detection of potential disruption to financial markets, technology and operations of financial industry
- Facilitate knowledge sharing on cyber risk management to strengthen capacity of supervisors in cyber risk management
- Provide views on cyber risk management in national and international policy development, where required
- Build strong collaboration with relevant stakeholders to facilitate continuous surveillance, enhance risk infrastructure developments and ensure effective supervision of cyber risk
- Effectively oversight and assist to manage industry-related cyber incidents to ensure resolution and mitigation of potential systemic risks
- Lead the coordination of industry working group for advancement of cyber risk management and sharing practices
- Undertake other ad-hoc assignments, when assigned.
Academic Qualifications
- Undergraduate/postgraduate degree in information technology related disciplines (e.g. computer science), with primary focus on network security, IT security and/or cyber security.
- Professional certifications related to information systems security, auditing, control, assurance and risk management such as Certified Information Security Manager (CISM), Certified Information System Security Professional (CISSP), ISO27001 lead auditor, Certified Information System Auditor (CISA) is an added advantage
Experience
- At least 5-7 years of experience in cyber security risk management and/or IT security / auditing, within the context of the financial industry is preferable.
- Preferred to have working IT technical knowledge and strong regulatory and compliance understanding of the financial sector, a mix of 1LOD and 2LOD experience will be most ideal
- Ideal to have experience in developing necessary documentation for the cyber security environment.
Bank Negara Malaysia (the Central Bank of Malaysia), is a statutory body which started operations on 26 January 1959. Bank Negara Malaysia is governed by the Central Bank of Malaysia Act 2009. The role of Bank Negara Malaysia is to promote monetary and financial stability. This is aimed at providing a conducive environment for the sustainable growth of the Malaysian economy.
Bank Negara Malaysia’s monetary policy stance is to maintain price stability while remaining supportive of growth. Bank Negara Malaysia is also responsible for financial system stability. This is achieved by developing a sound, resilient, progressive and diversified financial sector which serves to support the sectors of the real economy. It also plays an important function in implementing initiatives to deepen and strengthen the financial markets, including the foreign exchange market.
Bank Negara Malaysia has played a significant developmental role in developing the financial system infrastructure in advancing the financial inclusion agenda. This is to ensure all economic sectors and segments of the society have access to financial services. In addition, Bank Negara Malaysia also oversees the nation’s payment systems infrastructure which emphasize on the efficiency and security of the financial systems.
As the banker and adviser to the Government, Bank Negara Malaysia provides advice on macroeconomic policies and the management of public debt. Bank Negara Malaysia is also the sole authority in issuing the national currency and in managing the country's international reserves.
Skills Required
- Undergraduate or postgraduate degree in information technology related discipline (e.g., Computer Science) with focus on network/IT/cyber security.
- Professional certifications (CISM, CISSP, ISO27001 Lead Auditor, CISA).
- At least 5-7 years' experience in cyber security risk management and/or IT security auditing, preferably within the financial industry.
- Working IT technical knowledge and strong regulatory and compliance understanding of the financial sector, ideally exposure to 1LOD and 2LOD.
- Experience developing documentation for cyber security environments (policies, guidelines, frameworks).
What We Do
KGP Services is a leading network services provider and trusted partner to customers who build, own, and operate high-speed fiber, wireless, and cloud networks across North America. We combine complete end-to-end capabilities with a customer-first culture to provide custom services including design, engineering, installation, integration, and maintenance for all technologies. Through our new partnership with Circet, Europe’s largest network services provider, KGP Services is positioned for greater scale and expansion to help customers meet the fast-growing demand for high-speed connectivity.



