- Location
- PJC-PJ City, Malaysia
- Type
- Full-time
- Department
- Administration
- Closing date
- Today
- Source
- Workday
Description
If you are looking to excel and make a difference, take a closer look at us…
Overview:
As a core member of the Application Security and Access Management team, you will orchestrate the bank’s application security framework, user access governance, and identity management lifecycles. Shifting focus toward strategic process oversight, you will ensure access privileges—including super-user and third-party integrations—align with the bank’s risk appetite and strictly adhere to the "Need-to-Know" principle.
You will act as a key security gatekeeper for project implementations, User Acceptance Testing (UAT), and log monitoring to protect data sovereignty. This role drives compliance across regional entities (Vietnam, Cambodia, Singapore, and Hong Kong) under BNM RMiT, PCI DSS, and PDPA standards. By leading Risk and Control Self-Assessments (RCSA), automating User Access Matrix (UAM) reviews, and collaborating with cross-functional business partners, you will safeguard the bank’s critical systems against unauthorized insider and outsider threats.
Responsibilities:
Performs IDs maintenance tasks (Daily Basis)
Creation and Deletion of IDs
Reset Passwords
Enable/Disable IDs
Maintain User Profiles
Create and Delete User Roles/Groups (based on formalized User Access Matrix)
Grant and maintain access rights/functions
Performs IDs housekeeping tasks (Monthly, Half-Yearly And Ad Hoc basis)
Disable/remove dormant/inactive IDs on regular basis.
Remove resigned/transferred staff ID/accesses from systems based on HR notification
Maintain ‘ID Housekeeping Register’ for audit purposes
Review user listing with user roles/groups (compile and send user listing with user roles/groups to application business user for review)
Review user access matrix (compile and send user access matrix to application business owner for review)
Performs self- assessment on Application IDs administration
Complies with IT Security Policies & Procedures and Application User ID Administration SOP
Ensures that the password policies in the applications are set according to IT Security Operation Policies & Procedures and guidelines in respective Application IDs Administration Manual
Check, file and ensure completeness of User IDs Request Forms
Prepare and update Application ID Administration documentation and procedures.
Attends to Internal and External Auditor’s requests
Attends to User ID Request on timely manner (Service Level Agreement is within 1 day)
Provides IDs Management status reporting to Team Lead or Section Head
Reports incidents, breaches or violation on security and ID Management to Team Lead/Section Head
Assist on Application ID Management UAT testing for any application enhancement or upgrade.
Involve and participate in Identity Governance and Administration project
Skills and Experience We Are Looking For:
Professional Experience: 3–5 years in Application Security, IAM, or IT Risk within Financial Services (FSI), with proven expertise in BNM RMiT, PDPA, and internal security policies.
Technical & IAM Mastery: Deep understanding of application security controls, UAM principles, Zero Trust, and least privilege enforcement. Hands-on experience as Technical Owner for enterprise IAM/PAM platforms (e.g., SailPoint, CyberArk).
Governance & Audit Readiness: Skilled in IT security policy management, RCSA frameworks, and audit methodologies (ISO 27001, NIST, COBIT); experienced in orchestrating audits, collecting evidence, and testing controls.
Reporting & Operations: Proficient in automating executive dashboards for KRI and regulatory reporting, as well as leading operational cadences and team huddles to drive accountability.
Stakeholder Influence & Gatekeeping: Assertive in enforcing Segregation of Duties, challenging excessive access requests, and justifying security controls to business, IT, and external auditors.
Regional Experience: Exposure to supporting or standardizing security operations across regional entities (e.g., Singapore, Hong Kong, Vietnam) is highly advantageous.
Certifications: CISSP, CISA, or relevant IAM certifications are strongly preferred.
For more job opportunities, please go to HLB Careers: https://hlb.wd3.myworkdayjobs.com/HLBCareers/
We appreciate your application and will be in touch with shortlisted candidates regarding next steps
About Hong Leong Bank
We are a leading financial institution in Malaysia backed by a century of entrepreneurial heritage. Providing comprehensive financial services guided by a Digital-at-the-Core ethos has earned us industry recognition and accolades for our innovative approach in making banking simpler and more effortless for our customers. Our digital and physical offerings span across a vast nationwide network in Malaysia, strengthened with an expanding regional presence in Singapore, Hong Kong, Vietnam, Cambodia, and China.
We seek to strike a balance between diversity, inclusion and merit to achieve our mission of infusing diversity in thinking and skillsets into our organisation. Candidates are assessed based on merit and potential, in line with our mission to attract and recruit the best talent available. Expanding on our “Digital at the Core” ethos, we are progressively digitising the employee journey and experience to provide a strong foundation for our people to drive life-long learning, achieve their career aspirations and grow talent from within our organisation.
Realise your full potential at Hong Leong Bank by applying now.