Head Of Cyber Risk, Policy & Assurance

Sepang, Selangor, Malaysia

Job Description


OVERVIEW:Department: Information SecurityEntity: Capital A Group, KL, MalaysiaStatus: Full-timeYOUR ROLE AS A:As a key member of the Cyber and Information Risk Management function for the group of companies, this role is accountable for information and cyber risks and security in the AirAsia Group and Capital A Group as an independent Assurance Line-of-Defence 2 (LOD2) function.As the Head of Cyber Risk, Policy & Assurance, you will be accountable for leading the cyber threat identification, risk management processes, and policy and control definition to the AirAsia Group and Capital A Group of companies within the Cyber Security function, delivering an Enterprise Cyber Risk holistic view, as well as operationalising the Cyber Risk Management function within the groups.You will work closely in coordination with Business CISOs, Head of Cyber Architecture & Strategy, Head of Cyber Defence, Group Risk, Legal, Procurement, and engineering/technical/IT teams across the portfolio of companies.In this role, you will also represent and participate in external engagements to assure alignment with regulators and industry peers.WHAT YOU\xe2\x80\x99LL CHAMPION:Cyber security is an ever evolving risk to all major organisations with new threats appearing on a regular basis. This role must create a strong network both internally and externally in order to understand those threats and ensure the flexibility of the organisation as a whole to be able to respond quickly and efficiently to new threats. In this role, you will:Lead the enterprise Risk, Assurance, Policy and Thereat team; Leads the CYBER SECURITY Risk & Assurance across the Group Companies.Be the single point accountability for Group Risk, Assurance processes, Control Framework, Security Policies, threat analysis and Enterprise Risk Visual.Drive Risk methodology developments, maturity of the Risk, Policy & Assurance function & processes.Be the custodian of the Cyber Risk, Assurance, and Security processes in the CYBER SECURITY function.Drive Cyber Behaviour change programs to ensure Group staff are aware of the threats and prepared by practising Cyber behaviours. Continuously assess via the Phishing tests and validation of some user behavioural controls.Be accountable for the Risk and assurance processes, ensure maintenance of risk register in a standardised manner across Capital A, and its suppliers, and enable reporting of risk policies (Including the Business Information Risk Process).Be accountable for raising awareness and understanding of risks and threats within the CYBER SECURITY Function & LT by actively supporting the Business CISOs and CYBER SECURITY leads.Ensure risk remediation and status of the mitigation actions in coordination with Business CYBER SECURITY, ICT & business teams.Work closely with Business Cyber Security Risk teams to apply Controls and Assurance processes as designed. Ensures active communication of the identified Cyber Risks with Business CIOs, ICT, and Businesses to manage the gaps/findings actively.Drive development of Policies and Business adaptation of Policies and related CYBER SECURITY behaviours within IT functions and businesses.Act as an advisor to Group CISO on all information Risk, Assurance, threat matters, and management in control status reporting (including all assurance inputs).Ensure delivery of Business Risk Management capabilities such as Business Risk teams, Cyber risk reporting, and interface with key assurance stakeholders.Be an active & participating member of the CYBER SECURITY LT contributing to the decisions of the function. Ensuring their team operates according to the CYBER SECURITY functions strategies and has a robust framework.Be the custodian of the Cyber Risk Management Digital Tool system and ensure high data quality in the Digital Risk Platform.Chair the Cyber Risk Council that arbitrates on risks and controls issues within Capital A and calibrates the Digital Controls Framework.Identify and incorporate CYBER SECURITY implications of new Legal and Regulatory developments (e.g. Data Privacy)Maintain close link with the Cyber Defence Team, Strategy & Programme, and Corporate Security to identify new risks and agree mitigation prioritiesWHO YOU ARE:A recognized, trusted and respected leader, able to influence without direct line management control and lead significant change across the organisation through dotted line leadership.Regarded as a role model in the areas of motivating and developing staff.At least 10 years of experience in Information SecurityProven skills to manage a team of CYBER SECURITY experts with direct and indirect reports across Capital A IT.Collaborative working and out-of-the-box thinkingLeadership behaviours to enable change and development of the Cyber Risk Management team with energy and passion.Be a champion for a risk-driven approach to risk mitigation and control implementationUnderstands the significance of commercial constraints. Commercial mindset and external focus.Comfortable working with complex, ambiguous and incomplete information and leading others through uncertainty.Sense of realism and pragmatism, openness and approachabilityDemonstrates strong interpersonal skills. Able to operate in a virtual global environmentSkilled in simplifying complex problems; achieving buy into the solutions and communicating clear actionable plansIs effective and persuasive in both written and oral communication.Proven track record in CYBER SECURITY Risk ManagementHaving worked across different businesses would be an asset.WHAT YOU\xe2\x80\x99LL ENJOY:

  • Physical Wellbeing: Key medical and insurance benefits, maternity expenses, flexible work arrangement, and health and fitness amenities.
  • Emotional Wellbeing: Paid time off, wellness programmes, and childcare amenities.
  • Financial Wellbeing: Resources relating to financial, personal skills and career growth programmes.
  • Allstars Specials: Free flights, unlimited discounted flights, and exclusive discounts with partners.
  • A unique Allstar culture like no other
OUR HIRING PROCESS:
  • Application received
  • Candidate screening
  • Interview(s) and assessment(s)
  • Background check and/or other assessments
  • Offer and negotiation
We are all different - one talent to another - that is how we rely on our differences. At AirAsia, you will be treated fairly and given all chances to be your best.We are committed to creating a diverse work environment and are proud to be an equal opportunity employer.Search Firm Representatives - AirAsia does not accept unsolicited assistance from search firms for employment opportunities. All CVs / resumes submitted by search firms to any employee at our company without a valid written search agreement in place will be deemed the sole property of our company. No fee will be paid in the event a candidate is hired by our company as a result of an agency referral where no pre-existing agreement is in place.

AirAsia

Beware of fraud agents! do not pay money to get a job

MNCJobz.com will not be responsible for any payment made to a third-party. All Terms of Use are applicable.


Job Detail

  • Job Id
    JD1041003
  • Industry
    Not mentioned
  • Total Positions
    1
  • Job Type:
    Full Time
  • Salary:
    Not mentioned
  • Employment Status
    Permanent
  • Job Location
    Sepang, Selangor, Malaysia
  • Education
    Not mentioned