Head of IT Security
Job Description:
Head of IT Security
Location: Penang, Pulau Pinang, Malaysia
Work Mode: Onsite
Employment type: 12 Months Contract and convert to Perm
Experience Level: 10+ years
Oxydata Software Sdn Bhd established since 2012, helping regional enterprises drive digital transformation through Agentic AI Services, AI Automation & Integration, Data Engineering, AI Training, and IT Managed Services. We are a lean, high-impact team where engineers work directly on cutting-edge AI products serving enterprise clients across Malaysia and the region.
We are seeking an experienced Head of IT Security to lead and mature the cybersecurity function for a global manufacturing organisation.
Responsibilities
- Lead the information security and cybersecurity function across both corporate IT and manufacturing/operational environments.
- Develop and execute the information security strategy and security roadmap.
- Present cybersecurity risks, KPIs, and recommendations to senior management and executive stakeholders.
- Lead, coach, and develop the information security team.
- Oversee security operations, including vulnerability management, threat management, cyber threat intelligence, and incident response.
- Own and lead major cybersecurity incident response activities.
- Build or mature SOC/MSSP security operations capabilities.
- Establish and maintain cybersecurity policies, standards, and governance frameworks.
- Lead ISO/IEC 27001 compliance and certification-readiness initiatives.
- Apply security frameworks such as ISO/IEC 27001 and NIST Cybersecurity Framework.
- Strengthen cybersecurity across manufacturing and operational environments.
- Support improvements in network segmentation and security monitoring.
- Manage third-party and supply-chain cybersecurity risks.
- Run security awareness and phishing simulation programmes.
- Manage cybersecurity vendors, tooling, and security budgets.
Requirements
Must-have:
- Bachelor's degree in any related discipline.
- Minimum 10 years of experience in Information Security or Cybersecurity.
- At least 3 years in a cybersecurity leadership role (such as Head of Information Security, Head of Cybersecurity, Security Director, Information Security Director, Deputy CISO, or Senior Security Manager).
- Strong cybersecurity experience within manufacturing, industrial, energy, utilities, logistics, critical infrastructure, or other complex operational environments.
- Strong knowledge and practical experience with ISO/IEC 27001.
- Good knowledge of the NIST Cybersecurity Framework (NIST CSF).
- Experience leading cybersecurity incidents and incident response.
- Experience developing cybersecurity strategies, policies, and roadmaps.
- Strong stakeholder management skills with experience presenting to senior leadership.
- Experience managing cybersecurity teams, vendors, and budgets.
Nice-to-have:
- OT / ICS / SCADA cybersecurity experience.
- Experience with IEC 62443 or similar OT/industrial security standards.
- Strong understanding of industrial cybersecurity and manufacturing/plant security.
- Experience with OT network segmentation and industrial monitoring solutions.
- Experience working within a multinational or global organisation.
- Experience managing SOC or MSSP providers.
- Azure / Microsoft 365 security experience.
- ERP security exposure.
- Previous interim, consulting, or contract cybersecurity leadership experience.
- Professional certifications such as CISSP, CISM, CRISC, GICSP, ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, or other relevant cybersecurity/OT security certifications.
Why Join Us
- Join a forward-thinking global manufacturing organisation committed to excellence in cybersecurity.
- Opportunity to shape and lead a critical function, working with cutting-edge technologies and making a significant impact on both enterprise and operational security.
- Be part of a collaborative team that values innovation, professional growth, and leadership in the cybersecurity space.