Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Cyber and IT Risk Manager image - Rise Careers
Job details

Cyber and IT Risk Manager

Job title: Cyber & IT Risk Manager 
Location: Malaysia 

World-changing careers, enabled by Johnson Matthey. With more than 200 years history, join us and help to accelerate the transition to net-zero! As a Cyber & IT Risk Manager, you’ll contribute to JM’s mission as a world leader in sustainable technology, transforming energy and reducing carbon emissions for a cleaner, brighter future. 


The role:
As a  Cyber & IT Risk Manager , you will help drive our goals by:
Cyber and IT risk management
•    Develop, implement, schedule and drive a cyber and IT risk management program which includes regular assessment, prioritisation, and review of remediation and mitigation activities, with clearly defined management ownership.
•    Ensure that the risk management program is aligned with business priorities and risk appetite, assessing and clearly communicating those risks in a non-technical, easily digestible manner that ensures all stakeholders can make informed decisions on these risks.
Cyber and IT controls assurance
•    Developing, maintaining and operating cyber and IT controls assurance processes, including being responsible for the JM ITGC framework and ensuring system owners understand their responsibilities.
•    Conduct thorough assessments of control environments, systems, processes, and practices to identify control gaps, including those associated with audit actions, customer and stakeholder requirements. Ensure effective action is taken to resolve any issues and identify root causes and remediations that can be addressed through continual improvement.
Cyber and IT horizon scanning
•    Keep up to date with regulatory and legislative developments relating to cyber and IT, identifying and assessing any changes that are relevant to JM and developing recommendations and action plans, communicating these as necessary to senior management.
•    Keep up to date with best practices in risk and controls management, applying this knowledge where applicable to deliver improvements that benefit JM. 


Key skills that will help you succeed in this role:

•    Knowledge and experience of cyber and IT controls and supporting associated audits 
•    Ability to communicate with business stakeholders to articulate cyber and IT risks in business terms. Technical and/or practical experience of:
•    Cyber security controls/capabilities and relevant standards e.g. ISO27001
•    IT controls implementation and assurance, including but not limited to IT general controls
•    Enterprise software capabilities and technologies, including but not limited to ERP, CRM, enterprise operating systems (e.g. Windows/Linux)
•    Relevant legislation such as NIS2, GDPR and Computer Misuse Act
•    Relevant industry standards such as MITRE and NIST 
•    Risk management best practices


Even if you only match some of the skills, we’d love to hear from you to discuss further!

What we offer:
We make sure salaries are fair, competitive and aligned to individual roles, experience and responsibilities. We are also supportive of hybrid and flexible working and where applicable, offer life, medical and other benefits that support our employees’ financial and physical wellbeing, such as:
•    Retirement savings
•    Life and disability insurance
•    Commuter allowances and loans
•    Medical plans / health assessments

Ready to make a meaningful impact on your career and the environment? Join us and help shape a sustainable future while advancing your career!


At JM, inclusivity is central to our values. We create an environment where everyone can thrive, embracing diverse perspectives to tackle challenges and ensure all colleagues feel valued and connected.


For any queries or accessibility requirements, please contact GlobalRecruit@matthey.com. We will work with you to make suitable adjustments at any stage of the recruitment process. All conversations are confidential, and your feedback is welcome to help us provide an accessible and positive recruitment experience.


Closing date for applications: This job advertisement will be posted for a minimum of 2 weeks, early application is advised.


#LI-JY1
 

To submit your application, please click the "Apply" button online.

All applications are carefully considered and your details will be stored on our secure Application Management System. This is used throughout Johnson Matthey for the selection of suitable candidates for our vacancies as they arise. Johnson Matthey respects your privacy and is committed to protecting your personal information.

For more information about how your personal data is used please view our privacy notice:  Johnson Matthey Privacy Notice. By applying for this role and creating an account you are agreeing to the notice.

Johnson Matthey Plc is an equal opportunities employer and positively encourages applications from suitably qualified and eligible candidates regardless of sex, race, disability, age, sexual orientation, marriage or civil partnership, pregnancy or maternity, religion or belief.

Average salary estimate

$70000 / YEARLY (est.)
min
max
$60000K
$80000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Cyber and IT Risk Manager, Johnson Matthey

Are you ready to make a difference in your career while contributing to a sustainable future? Johnson Matthey is on the lookout for a passionate Cyber & IT Risk Manager to join our team in Kuala Lumpur, Malaysia. With over 200 years of history, we are a leader in promoting technologies that accelerate the transition to net-zero carbon emissions. In this role, you'll be at the forefront of developing and implementing a robust cyber and IT risk management program that aligns with our business goals. Your expertise will help us identify and assess risks, ensuring that all stakeholders can understand and make informed decisions about these vital matters. You'll be responsible for maintaining our cyber and IT controls assurance processes and ensuring compliance with relevant regulations such as NIS2 and GDPR. Engaging with stakeholders in a clear and non-technical manner, you'll drive effective communication around our risk appetite and priorities. Besides, your knowledge of various industry standards will be invaluable as you conduct assessments to identify and resolve control gaps effectively. At Johnson Matthey, we believe that inclusivity lies at the core of our values, and we strive to create an environment where everyone can thrive. If you're looking for a place where your skills and expertise can truly shine while making an impact on the environment, we want to hear from you! Come and help us shape a cleaner, more sustainable future while advancing your career in a supportive and flexible working environment.

Frequently Asked Questions (FAQs) for Cyber and IT Risk Manager Role at Johnson Matthey
What are the primary responsibilities of a Cyber and IT Risk Manager at Johnson Matthey?

The primary responsibilities of a Cyber and IT Risk Manager at Johnson Matthey include developing and implementing a comprehensive cyber and IT risk management program, ensuring alignment with business goals and risk appetite, conducting thorough assessments of control environments, and maintaining assurance processes for cyber and IT controls. Moreover, this important role involves communicating risks clearly to stakeholders in a non-technical manner to enable informed decision making.

Join Rise to see the full answer
What qualifications are needed for the Cyber and IT Risk Manager position at Johnson Matthey?

Candidates for the Cyber and IT Risk Manager position at Johnson Matthey should possess a solid understanding of cyber and IT controls, relevant legislation such as GDPR, and industry standards like ISO27001. Ideal candidates will have practical experience in risk management best practices, ability to communicate effectively with business stakeholders, and background in cybersecurity controls and audit processes.

Join Rise to see the full answer
How does the Cyber and IT Risk Manager ensure compliance with regulations at Johnson Matthey?

The Cyber and IT Risk Manager ensures compliance with regulations at Johnson Matthey by staying up to date with regulatory and legislative developments related to cyber and IT. This involves assessing changes that impact the company and developing action plans to meet compliance requirements while keeping senior management informed of any relevant updates necessitating action.

Join Rise to see the full answer
What skills are essential for success as a Cyber and IT Risk Manager at Johnson Matthey?

Essential skills for success as a Cyber and IT Risk Manager at Johnson Matthey include a thorough understanding of cyber security controls and the ability to articulate cyber and IT risks in business-focused terms. Familiarity with various enterprise software technologies, IT general controls, and risk management best practices are also critical, as is the capability to identify and remediate control gaps effectively.

Join Rise to see the full answer
What benefits does Johnson Matthey offer to Cyber and IT Risk Managers?

Johnson Matthey offers several benefits to Cyber and IT Risk Managers, including competitive salaries, hybrid and flexible working options, and various health and financial wellbeing benefits. These include retirement savings, life and disability insurance, medical plans, and commuter allowances, all designed to support employees both professionally and personally in their careers.

Join Rise to see the full answer
Common Interview Questions for Cyber and IT Risk Manager
What strategies would you implement to manage cyber risks effectively?

To manage cyber risks effectively, I would establish a structured risk management program that includes regular assessments and prioritization of risks. Communication with stakeholders is key, so I would ensure risks are presented in an easily understandable manner, likely utilizing risk matrices and clear documentation to facilitate informed decisions.

Join Rise to see the full answer
Can you describe your experience with cyber security controls?

In previous roles, I have implemented and managed various cyber security controls, particularly aligned with industry standards such as ISO27001. My experience includes developing internal policies, conducting audits, and ensuring compliance, which has enabled me to identify and remediate vulnerabilities proactively.

Join Rise to see the full answer
How would you approach training stakeholders about cyber and IT risks?

I would adopt a tailored training approach, offering sessions designed for different stakeholder groups. I believe in using relatable examples and practical scenarios to make the content engaging, ensuring stakeholders understand the implications of cyber risks on the business and their roles in mitigating those risks.

Join Rise to see the full answer
What role does communication play in your responsibilities as a Cyber and IT Risk Manager?

Communication plays a vital role in my responsibilities as a Cyber and IT Risk Manager. I focus on simplifying complex technical data into business terms, ensuring that stakeholders at all levels understand potential risks and implications, enabling informed decision-making, and cultivating a risk-aware culture within the organization.

Join Rise to see the full answer
How do you keep up with the latest regulations and best practices in cyber and IT?

I actively subscribe to industry publications, attend webinars, and engage in professional networks to stay informed on the latest regulations and best practices in cyber and IT. I also participate in relevant training sessions to enhance my knowledge and exchange experiences with peers in the field.

Join Rise to see the full answer
Describe a time you identified a significant control failure and how you addressed it.

In a previous experience, I discovered a significant control failure in the IT access rights process. I led a task force to conduct a comprehensive audit, identified the root causes, and worked on implementing a new framework that included stricter access controls and regular reviews, significantly reducing similar incidents.

Join Rise to see the full answer
What techniques do you use to assess the effectiveness of cyber security measures?

I employ a mix of techniques to assess cyber security effectiveness, including internal audits, penetration testing, and regular risk assessments. By analyzing results and establishing metrics, I can continuously monitor performance and recommend improvements where necessary.

Join Rise to see the full answer
How would you handle resistance from stakeholders regarding cyber security initiatives?

To handle resistance from stakeholders, I would first seek to understand their concerns and address them directly through dialogue. Providing data and case studies that highlight the potential impacts of inadequate cyber security can help to create buy-in, and I would collaborate closely to identify mutually acceptable solutions.

Join Rise to see the full answer
What is your experience with risk assessment frameworks like NIST or MITRE?

I have worked extensively with risk assessment frameworks such as NIST. This included adapting its guidelines to fit organizational needs, conducting assessments based on MITRE ATT&CK, and utilizing best practices to fortify our cybersecurity posture against evolving threats in the industry.

Join Rise to see the full answer
What motivates you to work in cyber and IT risk management?

My motivation for working in cyber and IT risk management stems from the evolving nature of technology and its impact on business. I find it fulfilling to protect companies from cyber threats and contribute to building a more secure environment, aligning my work with sustainability and safety goals that resonate with today's world.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 8 days ago

Join Johnson Matthey as an Associate Quality Systems Engineer to contribute to sustainable solutions while ensuring quality compliance.

Photo of the Rise User
Rackspace Remote India - Remote
Posted 14 hours ago

We are in search of an experienced M365 Engineer to manage and optimize our Office 365 environments and Active Directory systems remotely.

Photo of the Rise User
Posted 8 days ago

Seeking a skilled MS Dynamics CRM Architect to design robust solutions using Microsoft Dynamics 365 Customer Engagement.

Join CACI as a SIGINT Analyst, where you'll leverage your expertise in digital network exploitation to support vital intelligence operations for the US Army.

Photo of the Rise User
Posted 7 days ago

Join Visa as a Sr. Site Reliability Engineer and make an impact in the payments technology industry.

Photo of the Rise User
ServiceNow Remote 60 Dawson Street, Dublin, Ireland
Posted 3 days ago
Inclusive & Diverse
Mission Driven
Rise from Within
Diversity of Opinions
Work/Life Harmony
Empathetic
Feedback Forward
Take Risks
Collaboration over Competition
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Conferences Stipend
Paid Time-Off
Maternity Leave
Equity

Join ServiceNow as a Senior Problem Manager and help drive innovative solutions to enhance our cloud services.

Photo of the Rise User

As an Information Security Analyst at Cambium Assessment, you will play a critical role in advancing their Information Security program.

Photo of the Rise User
Posted 8 days ago

Join Avalon Healthcare Solutions as a Technical Integration Lead and play a pivotal role in enhancing healthcare delivery through innovative IT solutions.

Photo of the Rise User
Dailymotion Remote Issy-les-Moulineaux, France
Posted 10 days ago
Dental Insurance
Disability Insurance
Flexible Spending Account (FSA)
Health Savings Account (HSA)
Vision Insurance
Performance Bonus
Family Medical Leave
Paid Holidays

Become a vital part of Dailymotion's team as a Senior Security Engineer, dedicated to safeguarding digital resources against cyber threats.

Together for a cleaner, healthier world. Motivated by our vision, united by our values, we do what’s right. Make a difference, to create a cleaner and healthier world, today and for future generations.  At Johnson Matthey we are inspired by our...

7 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
April 18, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
80 people applied to Cybersecurity Intern at Dewberry
Photo of the Rise User
Someone from OH, Alliance just viewed Store Representative - Mid-Shift at Serv-U-Success
Photo of the Rise User
Someone from OH, Eastlake just viewed (REMOTE) Account Executive at Trellis
Photo of the Rise User
12 people applied to Junior Security Engineer at Epic
Photo of the Rise User
Someone from OH, Elyria just viewed Security Officer - Factory Patrol at Allied Universal
C
14 people applied to ISSE/ ISSO at Centuria
Photo of the Rise User
Someone from OH, Cincinnati just viewed Staff Software Test Engineer, Platform at Clari
Photo of the Rise User
Someone from OH, Perrysburg just viewed Sourcing Leader, Minerals & Cullet at Owens Corning
Photo of the Rise User
Someone from OH, North Royalton just viewed Remote AI Voice Trainer (High-Quality Microphone Required) at Datadog
C
Someone from OH, Akron just viewed Phlebotomy Technician - Outpatient at CCF