AI is analyzing your overall score…
Identifying your key strengths…
Evaluating your skill match against the job requirements…
Assessing your cultural and operational fit

GRC | InfoSec & Cybersecurity (ex-CISO/BISO) | Audit & Assurance | Internal Control (SOX) | Project & Data Management | Operations Excellence & Resilience | Transformation | Regulatory Advisory (Acting Head, Compliance)
Professional Qualifications:- Technical Risk Specialist (SIRM) awarded by IRM (https://www.theirm.org/) CRISC, CISM, CISA, CGEIT, CDPSE C|CISO, CEH, Associate C|CISO CCSK PMI-PMP TOGAF® 9 Foundation (BoK EA v9.2) Six Sigma Yellow Belt + Six Sigma Green Belt by 6SigmaStudy (https://www.6sigmastudy.com/) Scrum Fundamentals Certified (SFC™) by ScrumStudy (https://www.scrumstudy.com/) Professional Certification in Financial Accounting (AFA -> FIFA) by IFA (https://www.ifa.org.uk/) Conferred as Fellow by IPA (https://www.publicaccountants.org.au/) Fellow Financial Accountant FFA FIPA BSC Computing (Hons) Professional Memberships:- Member, IRM Member, ISACA-ITL, ISACA-MY Member, PMI Fellow Member, Institute of Public Accountants (IPA), Australia Fellow Member, Institute of Financial Accountants (IFA), UK Education: Graduated with Degree in Computing/Information Technology (Hons) Giving back to society:- Cybersecurity Mentor nominated by ECC Exploring: ISO/IEC 27001 LI Background Profile:- Being an ex-auditor with exposure to a risk-based approach coupled with an IT and accounting background has facilitated my understanding of emerging business and IT risks and associated controls in an integrated manner. I am ready to propel myself as a business partner; welcoming any opportunities rendered to me, with a strong interest in IT Risk Management, IT Governance, Compliance, Information Security, and Assurance with the opportunity to implement Framework / Program. Currently serving as Risk Management & Compliance (2nd LoD) in various subject matter capacities. Leading IT Risk and IT Compliance as well as appointed CISO in dual roles being responsible for Tech Risk function as well as technology and cyber-related policy-maker. Reporting to CRO, i am also entrusted to lead the Compliance function (interim) through the many assigned roles and responsibilities under my purv
CompTia (online)
Certification, IT Fundamentals+
January 1, 2020 – Present
SecureIOT Academy
Online Bootcamp, Information Systems Security Professional (ISSP)
January 1, 2020 – Present
MeetCyber
Member, Cyber security
January 1, 2020 – Present
ISACA
Certification, Cybersecurity Fundamentals
January 1, 2019 – Present
Member of Institute of Enterprise Risk Practitioners
Professional Certificate, ERM
January 1, 2016 – Present
Hytech Technology | Hytech Consulting Management Sdn Bhd
Head of GRC, Group BIT (Business & IT)
January 1, 2026 – Present
On-site
Hytech Technology | Hytech Consulting Management Sdn Bhd
BIT, Cyber, Information Security GRC & Audit Managing Lead | Data, Project, AI | Assurance
October 1, 2025 – Present
On-site
Hytech Technology | Hytech Consulting Management Sdn Bhd
BIT, Cyber, Information Security GRC & Audit Leader (Advisor)
October 1, 2025 – Present
On-site
QL Resources Group
Staff Club Organizing Committee - Secretary
January 1, 2025 – September 1, 2025
On-site
QL Resources Group
Cloud Governance Framework
June 1, 2025 – Present
Appointed Cloud Champion to drive the adoption of GRC across the strategy and governance management, cloud-related risk and compliance, security architecture, IAM, information and privacy protection, incident management, threat intelligence and vulnerability management, etc. to ensure cloud enablement supporting QL cloud journey.
Modern Office Transformation - M365 Migration
May 1, 2025 – Present
Appointed as Technical Security Lead & Champion for the project: Leadership in driving Microsoft 365 adoption across QL. Help evangelize M365 cloud-based. Oversee all the technical aspects of the rollout - security, architecture, integrations, etc.
Security Awareness Training (SAT)
April 1, 2025 – Present
Building a sustainable program to continously inculcate and promote a risk-aware culture across QL to ensure staff equipped with ongoing cyber hygiene practices. Exploring viable SAT offering by Proofpoint, KnowBe4, etc.
Cybersecurity Maturity Assessment
Certified in the Governance of Enterprise IT (CGEIT)
ISACA
June 23, 2026 – Present
Certificate in Financial Accounting
The Institute of Financial Accountants
June 23, 2026 – Present
Fellow Member of Institute of Public Accountant (Aus)
Institute of Public Accountants
June 23, 2026 – Present
Certified Information Systems Auditor® (CISA)
ISACA
June 23, 2026 – Present
Certified in Risk and Information Systems Control (CRISC)
ISACA
June 23, 2026 – Present
ISACA
Professional Certification, Information Security Management, IT governance, Cybersecurity
January 1, 2012 – Present
Institute of Financial Accountants
Professional Certification in Financial Accounting, Financial Accounting
January 1, 2005 – January 1, 2007
Asia Pacific University of Technology and Innovation (APU / APIIT)
Bachelor's Degree, Computing (Enterprise)
January 1, 2004 – January 1, 2005
Asia Pacific University of Technology and Innovation (APU / APIIT)
Higher Diploma, Computer System (Network, DB, OS)
January 1, 2002 – January 1, 2003
Asia Pacific University of Technology and Innovation (APU / APIIT)
Diploma, Information Technology
January 1, 2001 – January 1, 2002
SMK Maxwell (KL)
PMR, SPM, STPM, Science stream
January 1, 1994 – January 1, 2000
PMI-PMP
Project Management
N/A – Present
ISACA
CISM - Certified Information Security Manager
N/A – Present
Institute of Risk Management
SIRM, Technical Specialist
N/A – Present
Cloud Security Alliance
Cloud Computing
N/A – Present
6SigmaStudy™
Certified Six Sigma Yellow Belt Professional
N/A – Present
Good e-Learning
TOGAF® 9, Enterprise Architecture
N/A – Present
SM/CSO, Group IT/Cyber Security & GRC (Business & IT) | Data Security | AI | Cybersec PM
June 1, 2024 – September 1, 2025
On-site
Blackmores Limited (Group)
Group Cyber Security GRC Lead | Group IT
November 1, 2023 – May 1, 2024
New South Wales, Australia (based in UOA Business Park, Malaysia) · Remote
Hytech Technology | Hytech Consulting Management Sdn Bhd
Security & Risk Advisor (Security Architect), Cyber and Information Security (Director)
July 1, 2023 – November 1, 2023
KL Ecocity, Bangsar (headquartered in Sydney NSW) · On-site
Credit Guarantee Corporation Malaysia Berhad
Head, IT Risk & BCM, Risk Management (ERM|ORM)
October 1, 2022 – July 1, 2023
Credit Guarantee Corporation Malaysia Berhad
Change Agent (under Digital Transformation Office)
August 1, 2022 – July 1, 2023
Credit Guarantee Corporation Malaysia Berhad
All about Business Continuity Management (Operational + Cyber Resilience) | CGC BCM Coordinator
July 1, 2022 – July 1, 2023
Credit Guarantee Corporation Malaysia Berhad
All about IT Risk and Compliance
January 1, 2022 – July 1, 2023
PCCW Solutions Ltd. Group Business Operations (IT & Operations)
Senior Business Governance & Control (BISO)
August 1, 2021 – January 1, 2022
HQ - HK SAR; Based @Bangsar South, KL
IT Risk, CISO | Regulatory & Technology Compliance | Ops Risk | Compliance (Acting Head) | DataGov
Technology & Operational Risk (Head) | ERM | co-BCM Coordinator
January 1, 2020 – August 1, 2021
Risk Management & Compliance @ Hong Leong Assurance Berhad
IT Risk, CISO | Regulatory & Technology Compliance | Ops Risk | Compliance (Acting Head) | DataGov
Head, Regulatory & Technology Compliance
July 1, 2019 – August 1, 2021
Risk Management & Compliance @ Hong Leong Assurance Berhad
IT Risk, CISO | Regulatory & Technology Compliance | Ops Risk | Compliance (Acting Head) | DataGov
Acting Head, Compliance
July 1, 2019 – September 1, 2020
Risk Management & Compliance @ Hong Leong Assurance Berhad
IT Risk, CISO | Regulatory & Technology Compliance | Ops Risk | Compliance (Acting Head) | DataGov
Data Governance and Data Management (Appointed Data Steward)
June 1, 2019 – August 1, 2021
Risk Management & Compliance @ Hong Leong Assurance Berhad
IT Risk, CISO | Regulatory & Technology Compliance | Ops Risk | Compliance (Acting Head) | DataGov
Head, Information Security Officer (CISO)
December 1, 2018 – September 1, 2021
Risk Management & Compliance @ Hong Leong Assurance Berhad
IT Risk, CISO | Regulatory & Technology Compliance | Ops Risk | Compliance (Acting Head) | DataGov
Cyber Security Manager (Lead) | Operational Risk | Regulatory Compliance
September 1, 2018 – June 1, 2019
Risk Management & Compliance @ Hong Leong Assurance Berhad
IT Compliance, Risk & Control (SOX); InfoSecurity; Regulatory; TP/SP Review; Investment; Operations
IT Audit Lead - Pioneered IT audit; SOX Program Lead (IT/Business Controls Compliance & Advisory)
October 1, 2016 – September 1, 2018
Tokio Marine Life Malaysia, Menara Tokio Marine Life, Jalan Tun Razak
Designated IT Risk Champion | IT, Project, Ops & DA Audits in AmMetLife Insurance & Takaful
IT Audit Manager - Pioneered IT audit function (reporting regionally); Supported operational review
January 1, 2015 – October 1, 2016
Menara 1 Sentrum, Jalan Tun Sambanthan
CIMB
Reviewed Bank's project governance, compliance, risk, quality assurance and system security controls
December 1, 2012 – April 1, 2015
Menara Bumiputra Commerce, Jalan Tuanku Abdul Rahman
ASSEMBLY OF GOD CHURCH
Board Member
January 1, 2012 – Present
Jalan Ipoh, Kuala Lumpur
Uni.Asia Life Assurance (now a.k.a Gibraltar BSN Life Berhad)
Lead IT Auditor - Pioneered the IT audit function in UAL
December 1, 2011 – November 1, 2012
Bangunan Uni Asia Life, Jalan Tun Tan Siew Sin, 50050 Kuala Lumpur
Maybank
Senior Auditor - Led Head Office, Operations, Compliance, Off-shore, Finance & IT audit engagements
January 1, 2010 – December 1, 2011
Menara Maybank 100 Jalan Tun Perak 50050 Kuala Lumpur
Lonpac Insurance Berhad
Senior Executive, IT Audit
May 1, 2007 – January 1, 2010
Bangunan Public Bank, Jalan Sultan Sulaiman
Tesco Stores (Malaysia) Sdn Bhd
Supply Chain Import - Liaison on inventory, shipping, distribution (FMCG), & MIS
May 1, 2005 – April 1, 2007
Mutiara Damansara
ASSEMBLY OF GOD CHURCH
Member
January 1, 1996 – December 1, 2011
Jalan Ipoh, Kuala Lumpur
March 1, 2025 – Present
Collaborate with PwC for an independent assessment on the current state and capability of cybersecurity maturity and landscape at QL groupwide to provide an assurance to the BoD and Audit Committee. This exercise will lead to potential improvement and prioritisation roadmap in uplifting the cybersecurity maturity in the future.
Cybersecurity Risk Insurance
November 1, 2024 – March 1, 2025
Working with Howden Insurance Broker to explore, risk evaluation, assess the right adequate coverage, and acquire cyber risk insurance for QL-wide as part of the cyber risk management program.
Building QL Enterprise-wide Architecture Landscape
October 1, 2024 – April 1, 2025
My previous project engagement with EA consultants to build up and oversee the entire architectural landscapes of the company took about 6 months - that only covered Application-stack and Data-stack architecture.
QL's Cybersecurity and Risk Management Program
June 1, 2024 – Present
Ongoing Projects: Email Security, Privileged Access Management, Endpoint Security, Technology Refresh, Cyber Insurance, Modernizing Work (M365 migration). Exploratory Initiatives: Advanced Endpoint Protection, Attack Surface Management, Mobile Device Management, SOC, ZTNA, Detection & Response (DFIR).
Third Party Risk Management Program
November 1, 2023 – April 1, 2024
Driven the overall implementation of OneTrust's Third Party Risk Management (TPRM) to facilitate Blackmores vendors' due diligence, on boarding, off-boarding and security risk assessment.
Security Improvement Program Baseline
August 1, 2023 – Present
End-to-end discovery of Hytech's AWS environment against 200+ security best practices using pre-built security standards / frameworks and understand current security management and practices.
Integrated GRC Platform
February 1, 2022 – August 1, 2023
Lead the project and business case/proposal and defining requirements for ORMS and BCMS system implementation.
Various digital transformation initiatives under cloud platforms
February 1, 2022 – July 1, 2023
Projects - IPPBX (Microtel); Collection & Recovery (Stampede / Silverlake); OCR; eKYC on iMSME (WISE AI); Virtual Desktop (via AWS Workspace), Enterprise Data Warehouse CGC Digital's (FinTech) PAVE Platform leveraging on AWS cloud technologies/capabilities
SOC Compliance Certification
August 1, 2021 – January 1, 2022
Proposed, explored and drove the preparation in facilitating the SOC compliance pre-certification roadmap to establish the company’s credibility and trustworthiness as IT service provider to clients.
Data Management Standards
June 1, 2019 – August 1, 2021
Appointed to take leadership charge of the BNM SAQ Survey on Data Management Practices (2019) in accordance to BNM Guidelines on Data Management and MIS Framework, with the ensuing tasked to institute data governance practices. Collaborate with senior management, key business and technology stakeholder in driving an HLA-wide Data Governance strategy, operationalize the data management policies, procedures and standards.
Various cybersecurity engagements
September 1, 2018 – August 1, 2021
Project (modest scale) & vendor management - lead cyber-drill, phishing, CIRP, Red Team & compromise exercises in line with BNM's Risk Management in Technology Collaborated with IT on third party cybersecurity engagement - cloud computing adoption strategy (Azure, GCP, ACP, AWS), & CERT appointment.
Various digital and cloud projects
September 1, 2018 – August 1, 2021
Involved in project security advisory on proposed digital/cloud/FinTech (eg. SAS Prophet, Basecamp, Zendesk, Jira | Atlassian | Confluence, BitBucket, Yellow Messenger's AI-Chatbot Omnichannel, OCR, MSDynamics365, Revenue Monster (e-/Mobile Payments | e-wallet | Alibaba Cloud), QR, Google Workspace (G-Suite), Accordia VoIP, Kofax e-doc e-sign), Azure's Microservices Technology Governance - Supported ITD (1st LoD) oversee the enterprise-wide oversight of technology risk, including audit & regulatory compliance obligation Monitored technology projects lifecycle & delivery as main liaison supporting IT, PMO, Digital & Ops teams
Technical Specialist (SIRM)
Institute of Risk Management
June 23, 2026 – Present
Certified Data Privacy Solution Engineer (CDPSE)
ISACA
June 23, 2026 – Present
Certified Information Security Manager (CISM)
ISACA
June 23, 2026 – Present
Project Management Professional (PMP)
Project Management Institute
June 23, 2026 – Present
Associate C|CISO
EC-Council
June 23, 2026 – Present
ICA Associate Membership
International Compliance Association
June 23, 2026 – Present
Certificate of Cloud Security Knowledge (CCSK)
Cloud Security Alliance
June 23, 2026 – Present
Six Sigma Green Belt (SSGB)
6sigmastudy - The global certification body for six sigma certifications
June 23, 2026 – Present
Scrum Fundamentals Certified (SFC)
Vabro.ai and VMEdu.com (Scrum/Kanban/AI/Business Analysis/OKRs/Six Sigma/Sales and Marketing etc.)
June 23, 2026 – Present
SMstudy® Certified Digital Marketing Fundamentals (SCDM-F)
SMstudy - Global Accreditation Body for Sales and Marketing Certifications
June 23, 2026 – Present
TOGAF® 9 Foundation
The Open Group
June 23, 2026 – Present
HOW TO BECOME HIGHLY PAID HACKER
HackingFlix
June 23, 2026 – Present
Cultural Fit Analysis
The candidate's diverse project portfolio, spanning cloud governance, M365 migration, security awareness, and various risk management programs, indicates adaptability and a broad understanding of cybersecurity challenges across different business contexts. Their involvement in multiple organizations and leadership roles suggests a proactive and engaged professional. The numerous certifications (CISM, CRISC, CGEIT, CDPSE, PMP, CCSK, TOGAF) demonstrate a commitment to continuous learning and professional development, aligning well with a culture that values growth and expertise. The candidate's experience in financial services and technology consulting shows exposure to structured and dynamic environments, suggesting a good fit for organizations requiring both rigor and innovation.
Soft Skills & Operational Fit
The candidate's extensive experience in leadership, stakeholder management, and cross-functional collaboration, as detailed in various roles (e.g., 'Team Management & Collaboration', 'Leadership & Stakeholders Management'), indicates strong soft skills. Their involvement in 'Change Agent' roles and promoting 'risk culture company-wide through awareness & education' suggests an ability to drive organizational change and foster a security-conscious environment. The descriptions also highlight a proactive approach to problem-solving and continuous improvement, which are critical for operational fit in a senior cybersecurity role.