
Associate Risk Analyst/Risk Analyst, Cyber Risk Specialist Unit | Technology & Cyber Supervision Department (TCS)
BNM · Kuala Lumpur, Malaysia
About The Role
Contribute to the identification and mitigation of financial industry’s cyber security risks by undertaking continuous horizontal surveillance of the cyber threat landscape and monitoring of financial institution (FI)’s technology adoption and utilisation strategy in upholding the Bank’s mandate. Conduct thematic review on the risk management practices of identified cyber risk areas and assist in providing technical risk assessment of financial institutions technology and cyber adoption, as well as contribute to the development of cyber security policy requirements in order to strengthen the cyber resiliency of the financial industry. Contribute to the development of effective surveillance infrastructure and tools for early detection of emerging cyber security risks to facilitate macro, as well as micro level monitoring This role enables effective risk oversight and policy development, ensuring financial institutions adopt sound practices in cyber security risk governance aligned with regulatory expectations and industry standards.
Assist in conducting industry-wide horizontal assessments and thematic reviews (horizontal macro assessments) on cyber security risk management practices or topical focus areas with the aim to identify common approaches, uncover potential issues/areas of improvement, and promote best practices for industry adoption. This includes communicating outcomes and results to stakeholders, following through the implementation of recommended action plans, and contributing to the development of periodic reports or white papers as required. Assist in facilitating industry-wide cyber security risk improvement programs that aims to continuously strengthen the control measures and robustness of FIs’ risk cyber risk defenses; Contribute to the development of effective surveillance infrastructure and tools for early detection of emerging cyber risks to facilitate macro, as well as micro level monitoring; Assist in the review and development of related cyber security risk policy documents to ensure pragmatic implementation of regulatory policies; Provide oversight of cyber risk management areas in FIs’ digitalisation strategy to adopt new and emerging technologies or continued secure operation of their legacy solutions in order to ensure timely detection of potential cyber security risks; Contribute to the preparation of training materials and training exercises for capacity building and strengthening of supervisors’ knowledge and competencies in cyber risk management; Assist in building strong collaboration with internal and external stakeholders and providing information necessary to facilitate continuous surveillance and effective supervision of cyber risk; Participate or assist in the coordination of industry working group for advancement of cyber risk management and sharing practices; Assists in providing feedback/inputs/expertise to other departments in the Bank on policy developments, projects, etc., whenever needed; andTERHAD Undertake other ad-hoc assignments, when assigned.
Academic Qualifications: Undergraduate/postgraduate degree in information technology related disciplines (e.g. computer science), with primary focus on network security, IT security and/or cyber security. Professional certifications related to information systems security, auditing, control, assurance and risk management such as Certified Information Security Manager (CISM), ISO27001 lead auditor, Certified Information System Auditor (CISA) is an added advantage Experience: 2-3 years of experience in cyber security risk management and/or IT security / auditing, within the context of the financial industry is preferable.
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
