Skip to content
← Back to job listings

Head of Cybersecurity

Unknown Company · Kuala Lumpur, Malaysia

CybersecurityManager LevelQuick applyfull-time18 days ago

About The Role

About the Team

  • We're building the next generation of digital banking infrastructure that combines enterprise-grade reliability with startup agility.
  • Our Cyber Security team is the backbone of our technology organisation, ensuring that innovation and trust go hand in hand as we scale Malaysia's first AI-powered digital bank.
  • You'll collaborate with some of the sharpest minds in the industry, operating in a supportive and dynamic environment that fosters creativity, exploration, and innovation.
  • Your next thrilling adventure starts here. Be part of shaping the future of digital banking today!

About the Role

The Head of Cyber Security is Ryt Bank's most senior 1st-line security leader, responsible for building and operating the bank's entire security function across Cyber Operations, Security Engineering, and Cyber Governance. This role sits within the CTO organisation and executes the bank's Cyber Resilience Framework (CRF) and Technology Risk Management Framework (TRMF) in partnership with the 2nd-line CISO in the Risk organisation.

This is a hands-on leadership role for a security leader who can operate at the intersection of financial regulation, AI-native technology, and people leadership — someone who understands what RMIT compliance looks like in practice, not just on paper.

What You'll Do

CYBERSECURITY STRATEGY & EXECUTION

  • Own and execute the bank's 1st-line cybersecurity strategy, aligned to BNM RMIT, NIST CSF, and the bank's AI-first technology direction.
  • Lead the design, implementation, and continuous improvement of security controls across the IPDRR lifecycle (Identify, Protect, Detect, Respond, Recover).
  • Oversee the bank's Cyber Resilience Framework (CRF) and Technology Risk Management Framework (TRMF), working closely with the 2nd-line CISO on policy alignment and regulatory submissions.
  • Own the security tooling strategy and budget — including SIEM, SOAR, EDR, CSPM, CNAPP, IAM platforms, and AI security tooling.
  • Champion security awareness programmes and embed a security-first culture across engineering, product, and operations.

PEOPLE & TEAM LEADERSHIP

  • Build and lead a 1st-line security team across three pillars: Cyber Operations, Security Engineering, and Cyber Governance.
  • Apply Team Topologies principles — enabling stream-aligned product teams through platform and enabling team structures, including the Security Champions programme.
  • Hire, develop, and retain security talent suited to an AI-native, cloud-first digital bank; build career growth paths within the function.
  • Manage performance, set clear expectations, and create a culture of continuous improvement and psychological safety.

RMIT COMPLIANCE & REGULATORY ENGAGEMENT

  • Ensure the security function meets all applicable BNM RMIT requirements, including: 24x7 SOC capability, CIRP/CERT maintenance, annual cyber drill (SS11.16), and quarterly vulnerability management.
  • Support BNM foundational phase graduation, including evidence preparation for technology risk, operational resilience, and security maturity reviews.
  • Liaise with internal and external auditors, coordinate regulatory examinations, and ensure timely remediation of findings.
  • Support the bank's PDPA compliance posture in partnership with Legal and Compliance.

AI-NATIVE SECURITY

  • Oversee security of the bank's AI infrastructure — including coding agents, RAG pipelines, MCP-connected agents, and agentic workflows.
  • Ensure AI security governance is anchored in OWASP LLM Top 10, MITRE ATLAS, and Google SAIF frameworks.
  • Work with the Lead, Security Engineering to embed AI security into the SDLC.
  • Stay ahead of emerging AI threat vectors — prompt injection, data poisoning, model theft, agentic exploit patterns — and evolve the team's capabilities accordingly.

What We're Seeking

EXPERIENCE

  • Minimum 7 years of technology experience, with at least 5 years in a senior security leadership role in a regulated financial institution or fintech.
  • Demonstrated track record of building and scaling security teams from early-stage through regulated go-live.
  • Prior experience as a Head of Cybersecurity, CISO, or Deputy CISO in a bank, insurer, or fintech under central bank supervision; digital bank or neobank experience is a significant advantage.
  • Well-versed in BNM regulatory frameworks: RMIT, Outsourcing Policy, BCM, and PDPA — you understand what compliant actually means in practice.
  • Hands-on familiarity with cloud-native infrastructure (Alibaba Cloud or AWS), Kubernetes, and AI/ML system security.

SKILLS

  • Deep understanding of cybersecurity principles across ISO 27001, NIST CSF, PCI-DSS, and AI security frameworks (OWASP LLM Top 10, MITRE ATLAS, SAIF).
  • Ability to translate complex security risk into business-relevant language for the Board, BNM, and non-technical stakeholders.
  • Strong people leadership: hiring, performance management, team development, and building a culture of security ownership.
  • Excellent written and verbal communication skills; comfortable presenting to Board-level and regulatory audiences.

PREFERRED CERTIFICATIONS

  • CISSP, CISM, CISA, or equivalent.
  • Cloud security certification (AWS Security Specialty, Alibaba Cloud Security Associate, or equivalent).
  • AI/ML security credentials are a plus.

What We Value

  • Revolutionary in our thinking.
  • Innovative in our products, services and the way we work.
  • Genuine in our intentions.
  • Honourable in our actions.
  • Tenacious in overcoming challenge.

JR00000570

This listing was posted by a verified recruiter at Unknown Company. Report this listing