About the company:
A reputable insurance and financial services provider.
Role Purpose:
Act as the central point of contact for all client security due diligence activities. Manage end-to-end responses to Third-Party Security Assessments (TPSAs), Requests for Security Information (RFSIs), client audits, and cybersecurity questionnaires. Partner with Information Security, Legal, Privacy, Compliance, and Business Units to articulate the company’s security posture while protecting confidential information. This role is critical to enabling business growth, building client trust, and demonstrating regulatory compliance.
Key Responsibilities:
Reverse TPSA & Client Assurance
- Lead and coordinate all client security assessment requests from receipt to closure.
- Review, complete, and track security questionnaires covering cybersecurity, cloud security, data protection, operational resilience, BCP, and regulatory compliance.
- Represent the company in client discussions, workshops, and security review meetings.
- Translate technical controls into clear, business-friendly language for non-technical stakeholders.
Stakeholder & Evidence Management
- Collaborate with internal teams (InfoSec, Technology, Legal, Privacy, Compliance, Operational Risk, Corporate Solutions, TPRM) to gather evidence and validate controls.
- Maintain a centralized repository of standard TPSA responses, evidence packages, certifications, and compliance documentation.
- Ensure all externally shared information complies with classification and disclosure policies.
Regulatory & Continuous Improvement
- Support responses aligned with BNM RMiT, PDPA, ISO 27001, NIST, and Operational Resilience requirements.
- Track TPSA performance metrics, identify recurring themes, and drive automation, standardization, and process improvements.
Requirements:
Education
- Bachelor’s Degree in Information Security, Cybersecurity, IT, Risk Management, Computer Science, or related field.
Experience
- Information Security / Technology Risk
- Security Governance / Assurance
- IT Audit or Third-Party Risk Management
- Customer-facing security assurance roles
- Responding to large enterprise TPSAs (preferred)
Technical Knowledge
- Information Security Governance, Cybersecurity Risk Management, Cloud Security Controls
- Identity & Access Management, Vulnerability Management, Incident Response
- Data Protection & Privacy Controls, Business Continuity & Disaster Recovery
Frameworks & Regulations
- ISO 27001, NIST CSF, SOC Reports, CIS Controls
- BNM RMiT, PDPA Malaysia, Operational Resilience
Preferred Certifications
CISSP, CISM, CRISC, CISA, ISO 27001 Lead Auditor/Implementer, CCSP
The salary for this position is up to RM 12,000.
Kindly submit your application to sunny.khoo@peoplelake.asia
Please be informed that only shortlisted candidate will be notified.