← Back to job listings
BN
Manager, Data Protection (SPSU), Cyber Security (Contract)
BNMKGP · Malaysia
About The Role
- Data Protection Strategy Implementation: Implement and continuously improve the data protection strategy, including new projects and initiatives. This particularly involves defining requirements for data protection technology upliftment to address ongoing changes in the threat landscape, as well as external and internal factors such as the new PDPA, upcoming data sharing laws, and regulations.
- Risk Analysis and Mitigation: Periodically review and analyse business process/data flow diagrams, data lineage and outcome of automated data discoveries to continuously identify risk profiles, threats, blind spots, and controls to mitigate these identified risks.
- Business Rules Management: Manage business rules and exception requests from data owners for data protection tools. Conduct periodic health checks of these tools to identify unnoticed system issues and explore ways to stay clean.
- Event Analysis: Analyse events, identify trends, and detect correlations from data protection tools across Data at Rest, Data in Motion, and Data in Use. Develop action plans based on insights gained from the analysis to strengthen data protection measures.
- Stakeholder Collaboration: Collaborate with stakeholders across the Bank, including data owners and the DPO, to review and enhance the DPP Methodology. This includes updating policies, standards, procedures, and the operating model for continuous improvement, and acting as a point of contact for data protection-related matters ensuring alignment and communication across all relevant parties.
- Responding to data security protection requirement and enablement arising from new data privacy, data protection and data sharing law and regulations.
- Mapping of compliance requirement of related data protection laws with current technical controls, assess effectiveness and identify new initiatives to close any gaps encountered.
Job Complexity & Problem Solving
- Data Protection Technical Knowledge: Technical knowledge and expertise in data protection tools, technologies, and capabilities that are available and relevant to the Bank to effectively mitigate data protection risks and threats such as data lost preventions, database encryption, anonymisation, tokenisation etc.
- Maintaining and Enforcing Policies and Standards: Ability to update, and enforce data protection methodology, policies and standards with the technical knowledge of data protection and information security.
- Risk and Controls Assessment: Ability to perform comprehensive risk assessments impacting data protection, prioritise risks based on potential impact, and identify appropriate data protection controls. This includes reviewing and analysing data flow diagrams to understand risk profiles, assess threats, and determine effective data protection controls to mitigate those risks.
Leadership & Stakeholder Management
Collaborate with executive stakeholders across the Bank to communicate the data protection element DPP Methodology including key details such as program mission, vision, objectives, roadmap of the activities, structure and roles required for the ownership, oversight, management and operations.
- Academic Qualifications: Degree in Computer Science / Data Science or its equivalent. Must possessed professional certification related to data protection or information security like CISM, CRISC, ISO/IEC 27001 and ISO/IEC 27701 Lead Implementer, CISSP, CISA or CIPT, is an added advantage.
- Experience: At least 5+ years in IT and Data Analytics.
Similar roles you might like
See all →B
Executive, Data Protection Analyst, Cyber Security (Contract)
BNM
Salary not disclosedPosted today
B
Chief Information Security Officer
Bjak
Salary not disclosedPosted today
I
Advisor, Security Operations and Assurance
Iawmqy
Salary not disclosedPosted 4 days ago
PG
Intern - Information Technology Risk Assurance (ITRA), Digital Audit (July to November 2026 Intake)
PwC Global Campus
Salary not disclosedPosted 7 days ago
AI
Senior Manager, Information Security
AIA IT (M) Sdn Bhd
Salary not disclosedPosted 9 days ago
1R
Security Engineer - Vulnerability & Exposure Management
1310 Roche SSC APAC
Salary not disclosedPosted 9 days ago
OE
Markets Operations – Risk and Control
OCBC e2 Power Sdn Bhd
Salary not disclosedPosted 10 days ago
6U
Senior Security Engineer - Data Security Engineering
6255 UOB Innovation Hub 2 Sdn Bhd
Salary not disclosedPosted 11 days ago
This is an external listing. JobSpring does not represent or verify the employer. Report this listing