The Head of Security Engineering will lead the design, implementation, and continuous improvement of the banks security infrastructure. This strategic role is responsible for building secure, scalable systems and ensuring compliance with regulatory frameworks such as Bank Negara Malaysias RMiT , ISO 27001 , and NIST . The ideal candidate will drive innovation in security architecture, champion DevSecOps practices, and foster a high-performance engineering team.
Key Responsibilities
Leadership & Strategy
- Define and execute the security engineering roadmap aligned with the banks cybersecurity and digital transformation goals
- Lead and mentor a team of security engineers, promoting technical excellence and continuous learning
- Collaborate with senior leadership to align security initiatives with business objectives
Security Architecture & Design
Architect and implement security controls across on-premise, cloud, and hybrid environmentsEnsure security is embedded in enterprise architecture and application development lifecyclesEvaluate emerging technologies and recommend secure design patternsInfrastructure Security Operations
Oversee deployment and management of firewalls, IPS, DLP, endpoint protection, SIEM, and PAM solutionsEnsure high availability, scalability, and resilience of security systemsMonitor system performance and proactively address operational risksVulnerability & Threat Management
Lead the vulnerability management lifecycle : scanning, prioritization, remediation, and reportingCollaborate with the SOC team to respond to incidents and mitigate emerging threatsConduct threat modeling and penetration testing exercisesCompliance & Risk
Ensure adherence to RMiT , GDPR , MAS TRM , PCI DSS , and other relevant regulationsSupport internal and external audits, risk assessments, and regulatory reviewsMaintain documentation and evidence for compliance reportingDevSecOps Enablement
Integrate security into CI / CD pipelines and automate security testingPromote secure coding practices and support secure SDLC initiativesPartner with development teams to embed security early in the software lifecycleStakeholder Engagement
Liaise with business, risk, audit, and compliance teams to align on security prioritiesProvide executive-level reporting on security engineering maturity and effectivenessRepresent the security engineering function in cross-functional forumsRequirements :
Bachelors or Masters degree in Computer Science, Cybersecurity, Information Systems, or related field10+ years of progressive experience in cybersecurity, with 5+ years in a leadership roleExperience in the banking or financial services sector in Malaysia is highly desirableStrong technical expertise in cloud security (AWS, Azure), network security, endpoint protection, encryption, IAM, and DevSecOpsFamiliarity with regulatory frameworks : RMiT, GDPR, MAS TRM, PCI DSSCertifications such as CISSP, CISM, CCSP, GSEC, or AWS Security Specialty are advantageousKey Competencies
Strategic thinking with strong execution capabilitiesProven leadership and team development skillsEffective communication with technical and non-technical stakeholdersAnalytical problem-solving and decision-making abilitiesAbility to thrive in a highly regulated, complex, and dynamic environment