Deskripsi Pekerjaan
Are you a visionary cybersecurity leader passionate about making a global impact? Our organization, a leading NGO, is seeking a strategic and forward-thinking Chief Information Security Officer (CISO) to join our executive leadership team in Malaysia. In an increasingly complex digital landscape, you will play a pivotal role in safeguarding our mission-critical data, infrastructure, and the trust of our stakeholders.
As the CISO, you will define and drive our global information security strategy, ensuring that our cybersecurity framework is robust, compliant, and agile. You will serve as the primary advisor to the Board and Executive Committee, translating complex technical risks into business-aligned strategies. This is an exceptional opportunity for a security veteran who thrives on building resilient security cultures in humanitarian or non-profit sectors.
Tanggung Jawab
- Develop and execute a comprehensive global information security strategy that aligns with NGO operational goals.
- Lead and mentor a cross-functional security team while managing external security partners and vendors.
- Oversee the implementation of security architecture, including cloud security, identity management, and threat detection.
- Manage incident response protocols and disaster recovery planning to ensure high availability of critical services.
- Provide regular reporting to the Board of Directors on the organization's cybersecurity posture and risk landscape.
- Ensure strict compliance with international data protection regulations (GDPR, PDPA, etc.) and NGO-specific governance standards.
- Foster a culture of security awareness through organization-wide training and policy enforcement.
Kualifikasi
- Minimum of 10-15 years of progressive experience in IT security, with at least 5 years in an executive or leadership capacity.
- Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Information Systems, or a related field.
- Relevant professional certifications such as CISSP, CISM, or CRISC are highly preferred.
- Deep understanding of risk management frameworks (NIST, ISO 27001) and their application in non-profit environments.
- Proven ability to manage large-scale security budgets and resource allocation.
- Excellent communication and stakeholder management skills, with the ability to influence at all levels.
- Experience navigating cybersecurity challenges in geographically dispersed or developing regions.