Apply Edge Start your job search

Head of Information Security & Risk

Robert Walters · Kuala Lumpur, Federal Territory of Kuala Lumpur, Malaysia

Apply & track with Apply Edge
An exciting opportunity for Head of Information Security & Risk has just become available in Kuala Lumpur. HEAD OF INFORMATION SECURITY AND RISK Backed by two national payment operators with world-class real-time payment experience, this position offers you the chance to influence enterprise-wide cybersecurity strategy from inception, drive operational readiness, and embed security into every layer of technology delivery. You will enjoy working closely with senior leaders, including the CEO and CTO, in an environment that values collaboration, transparency, and resilience. The organisation is committed to supporting your professional growth through exposure to cutting-edge initiatives such as Zero Trust, DevSecOps maturity, and automation. Flexible working opportunities are available to help you balance your responsibilities while contributing to a mission-critical global project. * Play a key role in building and securing a transformative global payments platform that connects instant payment systems across multiple markets. * Work directly with executive leadership to define and execute enterprise-wide cybersecurity strategies, embedding security into every aspect of technology delivery. * Enjoy flexible working arrangements and access to advanced training opportunities as you lead critical initiatives in a highly collaborative environment.What you'll do:As Head of Information Security and Risk, your day-to-day responsibilities will centre around defining strategic direction for cybersecurity across a rapidly evolving payments ecosystem. You will act as the principal advisor to executive leadership on all matters related to cyber risk management, delivering actionable insights that shape board-level decisions. Your role involves partnering deeply with technology leaders to embed security into platform design and development processes-ensuring that every engineering decision is made with resilience in mind. You will lead the creation of governance models that support both operational excellence and regulatory compliance while overseeing the build-up of internal security capabilities such as SOCs and incident response teams. By implementing advanced monitoring tools for mission-critical systems and driving continuous improvement in control maturity, you will ensure the organisation remains prepared for both operational launches and ongoing regulatory scrutiny. Collaboration is key; you will work closely with internal teams as well as external partners to foster trust among stakeholders globally. * Serve as the principal advisor on cybersecurity matters to the CEO and Board, providing independent oversight of cyber and technology risks while establishing robust governance frameworks. * Deliver board-level insights on threat landscapes, organisational posture, and investment priorities to ensure informed decision-making at the highest level. * Partner closely with the CTO to co-own secure architecture decisions, platform scalability objectives, and engineering priorities that align with business goals. * Embed security practices into engineering culture and daily operations without creating friction or hindering innovation within technology teams. * Define and execute a comprehensive global cybersecurity roadmap that supports business growth while leading initiatives such as Zero Trust adoption, DevSecOps maturity enhancement, and automation integration. * Oversee the establishment and maturation of Security Operations Centre (SOC), threat detection capabilities, incident response protocols, and cyber resilience measures across global operations. * Implement advanced tooling including SIEM, SOAR, EDR solutions for monitoring mission-critical payment switching systems operating 24/7. * Own enterprise cyber risk management processes, regulatory compliance frameworks, and serve as primary interface with regulators and auditors during audits and reviews. * Drive security readiness for operational go-live phases while continuously improving control maturity throughout steady-state operations. * Collaborate with internal teams and external partners to strengthen operational security readiness and build trust with stakeholders including industry forums.What you bring:Your extensive background in cybersecurity leadership equips you perfectly for this Head of Information Security and Risk role. With over fifteen years' experience-including significant tenure at senior levels-you bring proven expertise managing cyber risk within highly regulated sectors such as payments or banking. Your technical acumen spans mission-critical digital infrastructure protection through cloud security architectures to cryptographic controls essential for safeguarding sensitive data flows. You have successfully partnered with CTOs and engineering teams to integrate robust security practices into platform development lifecycles without impeding innovation. Regulatory compliance is second nature; you understand both local SEA/APAC requirements as well as international standards like PCI-DSS or ISO 27001. Your calm approach under complex conditions ensures effective incident response coordination while your structured thinking enables delivery accountability across diverse stakeholder groups. This combination of deep domain knowledge and interpersonal skills makes you an ideal candidate for steering enterprise-wide cybersecurity transformation. * 15+ years' experience in cybersecurity roles with at least 10 years in senior leadership positions such as CISO or Head of Information Security within payments, banking, fintech or other highly regulated environments. * Proven track record leading cybersecurity functions in organisations responsible for mission-critical digital infrastructure or real-time transaction systems. * Deep expertise partnering with CTOs, engineering teams, and technology organisations to embed security into platform design, development cycles, and operational processes. * Experience building or maturing security capabilities in evolving or regulated environments where compliance requirements are stringent. * Technical proficiency in payment switching platforms, cloud infrastructure security, application security architectures, cryptography (including HSMs), and key management protocols. * Comprehensive knowledge of PCI-DSS, ISO 27001, NIST standards, COBIT frameworks, enterprise technology risk management practices, and cybersecurity governance models. * Regulatory familiarity with Southeast Asian (SEA) and broader APAC frameworks relevant to payments-including BNM RMiT and MAS TRM-as well as cross-border compliance requirements. * Demonstrated ability supporting audit readiness efforts during platform build or transition phases alongside successful implementation of control measures. * Exceptional stakeholder coordination skills enabling effective communication across complex multi-party environments involving risk management functions. * Calm leadership style under pressure combined with structured thinking that drives execution-focused outcomes.What sets this company apart:The organisation stands out by offering you the rare opportunity to help build foundational global payments infrastructure from the ground up-backed by two national operators renowned for their expertise in real-time payment ecosystems. Here you will find an environment where collaboration between executive leaders is not just encouraged but essential; your input will directly shape strategic decisions impacting millions of transactions worldwide. The company's commitment to flexible working arrangements ensures you can balance professional ambitions with personal needs while benefiting from ongoing training opportunities designed to keep your skills sharp amid evolving industry demands. As part of a team dedicated to operational excellence in cross-border payments innovation, you'll enjoy unparalleled exposure to industry forums and regulatory bodies-building trusted relationships that enhance both your career trajectory and organisational reputation. The supportive leadership culture prioritises knowledge sharing so you can thrive alongside colleagues who value dependability and communal success above all else. What's next:If you are ready to make a lasting impact on global payments infrastructure by leading enterprise-wide cybersecurity transformation in a highly collaborative environment-this is your moment!Apply today by clicking on the link provided.Do note that we will only be in touch if your application is shortlisted.Agensi Pekerjaan Robert Walters Sdn BhdBusiness Registration Number : 729828-TLicence Number : JTKSM 423C