Ryt Bank

Lead, Cyber Governance

Ryt Bank  •  Malaysia (Onsite)  •  23 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

About the Team

We're building the next generation of digital banking infrastructure that combines enterprise-grade reliability with startup agility.

Our Cyber Security team is the backbone of our technology organisation, ensuring that innovation and trust go hand in hand as we scale Malaysia's first AI-powered digital bank.

You'll collaborate with some of the sharpest minds in the industry, operating in a supportive and dynamic environment that fosters creativity, exploration, and innovation.

Your next thrilling adventure starts here. Be part of shaping the future of digital banking today!

About the Role

The Lead, Cyber Governance is responsible for Ryt Bank's cyber governance framework — ensuring the bank's security practices are well-documented, risk-informed, RMIT-compliant, and consistently embedded into decision-making across the organisation. This role sits as a direct report to the Head of Cyber Security and serves as the primary day-to-day bridge between the 1st-line security function and the 2nd-line CISO in the Risk organisation.

This is a senior governance role for a person who combines deep regulatory knowledge with the ability to translate complex cyber risk into clear, business-relevant language. You will own the RMIT controls register, the risk register, policy lifecycle, third-party risk, and cyber drill coordination — freeing the operational pillar leads to stay focused on detection, response, and engineering.

What You'll Do

CYBER GOVERNANCE FRAMEWORK

  • Develop, implement, and continuously improve the bank's cyber governance framework, aligned to BNM RMIT, NIST CSF, ISO 27001, PCI-DSS, and the bank's internal risk appetite.
  • Own the RMIT controls register — mapping all applicable RMIT requirements to bank controls, tracking compliance status, and producing gap analysis and remediation plans.
  • Manage the policy lifecycle for all cybersecurity policies, standards, and guidelines — drafting, reviewing, approving, and publishing on a regular cadence.
  • Monitor regulatory developments — BNM RMIT revisions, PDPA updates, PayNet requirements, PCI-DSS changes — and proactively update the bank's governance posture.

RISK MANAGEMENT & REPORTING

  • Maintain the cyber risk register — identifying, assessing, tracking, and reporting on cyber risks in line with the bank's enterprise risk management framework.
  • Produce KRI/KPI dashboards and governance reports for the Head of Cyber Security, Board Risk Committee, and BNM — including periodic cyber risk reporting required under RMIT.
  • Work with the 2nd-line CISO to ensure risk reporting is consistent between the 1st-line and 2nd-line views.
  • Support technology risk governance forums and represent cybersecurity in cross-functional risk committees.

AUDIT, REGULATORY & THIRD-PARTY

  • Coordinate cyber security reviews, BNM examinations, and internal/external audit activities — preparing evidence packs, managing audit timelines, and ensuring findings are tracked to remediation.
  • Own third-party and vendor cyber governance: due diligence assessments for new vendors, periodic reviews of existing critical vendors (cloud, MSSP, and AI tool providers), and RMIT-compliant outsourcing risk oversight.
  • Own shadow IT controls documentation (RMIT SS10.16) in partnership with the Security Engineering team.

CYBER DRILL & BUSINESS CONTINUITY

  • Own the planning, coordination, and execution of the bank's annual cyber drill (RMIT SS11.16) — including board members, senior management, and third-party providers.
  • Maintain the bank's Cyber Incident Response Plan (CIRP) documentation in partnership with the Lead, Cyber Operations.
  • Support Business Continuity Management (BCM) cyber workstreams and cyber resilience testing.
  • Maintain cyber insurance programme documentation and support annual policy review.

AI GOVERNANCE SUPPORT

  • Maintain the AI security governance documentation for the bank's AI-native stack — AI inventory, AIBOM, AI risk register, and ISO 42001-aligned AI governance artefacts.
  • Support the bank's AI Ethics Committee with cyber and security risk inputs for new AI system deployments.
  • Track BNM's evolving position on AI use in financial services and ensure the governance framework stays ahead of regulatory expectations.

What We're Seeking

EXPERIENCE

  • 5-7 years in cyber security governance, technology risk, or GRC roles, ideally in a regulated financial institution.
  • Demonstrated experience owning a controls framework and producing regulatory-grade risk reporting.
  • Strong familiarity with BNM RMIT requirements — including the November 2025 revision — and what they require in practice.
  • Experience engaging directly with regulators (BNM), external auditors, and board-level stakeholders.
  • Familiarity with AI governance frameworks (ISO 42001, NIST AI RMF, Treasury FS AI RMF) is a growing requirement and a strong differentiator.

SKILLS

  • Excellent written communication — able to produce clear policy documents, risk reports, and board papers.
  • Strong regulatory translation ability — converting dense regulatory text into actionable bank controls.
  • Organised and detail-oriented — able to manage multiple governance workstreams, deadlines, and stakeholders simultaneously.
  • Ability to influence without authority — driving compliance across teams that do not report to you.
  • Familiarity with GRC tooling (Jira GRC, ServiceNow, or equivalent) is an advantage.

PREFERRED CERTIFICATIONS

  • CISM, CISA, or CRISC.
  • ISO 27001 Lead Implementer or Lead Auditor.
  • Certified in Risk and Information Systems Control (CRISC).

What We Value

  • Revolutionary in our thinking.
  • Innovative in our products, services and the way we work.
  • Genuine in our intentions.
  • Honourable in our actions.
  • Tenacious in overcoming challenge.

JR00000614

Ryt Bank

About Ryt Bank

We are Ryt Bank, the World’s First AI-Powered Bank, fully licensed by Bank Negara Malaysia and the Ministry of Finance, and a member of PIDM.

Backed by YTL Digital Capital Sdn Bhd with Sea Limited as shareholder, we bring together decades of experience and digital innovation to reimagine what banking should be: smarter, simpler, and built entirely around you.

The future of banking is here, and it’s done right.

📲 Ryt Bank is now available on the App Store and Google Play.

Industry
Finance & Insurance
Company Size
201-500 employees
Headquarters
Kuala Lumpur, MY
Year Founded
Unknown
Social Media