Manager I, Cyber Security
Worley
- Location
- Kuala Lumpur, Kuala Lumpur, Malaysia
- Work model
- On-Site
- Level
- Mid
- Posted
- 2h ago
Skills
About this role
About us Worley is a global company of energy, chemicals and resources experts headquartered in Australia. We partner with our customers to deliver projects and create value across the life of their assets. We specialize in consulting, engineering, procurement and construction across the project lifecycle, with services extending through to operations and decommissioning. Leveraging extensive experience and AI-enabled delivery, we support customers in navigating complexity as they meet today's needs and transition to more sustainable solutions. About the job We’re looking for a Manager I, Cyber Security to join our Malaysia team. As a Manager I, Cyber Security , you will be responsible for working with various stakeholders across Worley to assess and manage exceptions from security control implementation, including web filtering, network controls, data loss prevention controls and others. This position will also manage the process for deviations from company information security standards. Additionally, this position supports information security risk management and third-party risk management tasks to continuously improve Worley’s cybersecurity practices. To succeed in this role, you should have experience in information security or information technology. What you’ll do We are looking for a Manager I, Cyber Security to join our team Malaysia . The role responsibilities include: 2nd Line of Defence in IIA Three Lines of Defence Model. Lead the supplier information security risk management program, including security assessments, assurance reviews, remediation oversight, and ongoing monitoring of third-party security risks. Collaborate with Procurement, Legal, Privacy, Digital, and business stakeholders to ensure information security requirements are embedded within supplier onboarding processes, contractual arrangements, and business operations. Manage and continuously enhance the Information Security Management System (ISMS), including maintaining ISO/IEC 27001 certification, coordinating internal and external audits, overseeing corrective actions, and ensuring ongoing compliance with certification requirements. Own and administer the Digital Risk Register and Information Security Risk Register, including facilitating risk identification, assessment, treatment, monitoring, reporting, and periodic review in alignment with enterprise risk management requirements. Conduct and facilitate information security risk assessments, including the evaluation of proposed deviations from security standards, policies, and control requirements. Coordinate and support internal and external audits, certification activities, customer security assurance requests, and regulatory reviews. Lead, coach, and develop team members while ensuring delivery of operational objectives, continuous improvement initiatives, and strategic program outcomes. What you’ll have Education – Qualifications, Accreditation, Training: A relevant bachelor’s degree. Certifications such as – CISM, CRISC, ISO27001 Lead Auditor, ISO42001 Lead Auditor, CISSP, CISA 10 + years of experience in information security or information technology. Job Specific Knowledge / Experience: Demonstrated ability to partner and collaborate effectively with stakeholders, demonstrating an appreciation of both IT and business strategy. Advanced awareness of full technology stack. Exceptional attention to detail, with the aptitude to collect, analyze and conclude on data. Demonstrated ability to produce clear, concise, and logical risk assessment documentation. Operational knowledge of data handling and confidentiality. Ability to work in a fast-paced unstructured customer-centric environment across multiple geographies and operational contexts. Knowledge of frameworks including ITIL, COBIT, NIST CSF (Cyber Security Framework), Essential 8 and ISO27001. IT Skills: Advanced user in MS Office applications (including MS Visio) and MS SharePoint Advanced awareness of full technology