Assistant Manager - IT (Compliance)

Genting Energy

Kuala Lumpur

On-site

MYR 180,000 - 260,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Genting Energy is seeking an experienced Assistant Manager – IT (Compliance) to establish and maintain the organization\'s IT governance, risk management, compliance, and assurance framework. The role ensures all technology systems operate in line with policies, regulatory requirements, and audit expectations.

The job focuses on IT governance, risk, compliance, and audit, with responsibilities spanning policy ownership, risk registers, control testing, and change governance across multi-site

Qualifications

  • Bachelor’s degree in IT or related discipline as required.
  • Professional certification in Microsoft, Security & Networking, or Cloud.
  • Strategic and analytical mindset with strong problem-solving abilities.
  • Excellent interpersonal skills and ability to work with audits.
  • Willingness to work outside normal business hours.

Responsibilities

  • Establish and maintain IT governance, risk, compliance, and assurance framework.
  • Own IT risk identification, assessment, and control tracking.
  • Act as primary IT liaison for internal and external audits.
  • Oversee cybersecurity governance, access governance, and data protection.
  • Define access controls, review cycles, and data retention compliance.
  • Prepare IT compliance, risk, and audit status reports for management.
  • Govern IT change management framework and ensure audit readiness.

Skills

Strategic thinking
Analytical mindset
Problem solving
Interpersonal skills
Dynamic thinking
Problem solving

Education

Bachelor’s degree in information technology
Bachelor’s degree in Computer Science
Bachelor’s degree in Information Systems
Bachelor’s degree in Cyber Security

Tools

Microsoft
Security and Networking
Cloud

Job description

The Assistant Manager – IT (Compliance) is responsible for establishing and maintaining the organization's IT governance, risk management, compliance, and assurance framework to ensure that all technology systems, processes, and services operate in accordance with corporate policies, regulatory requirements, cybersecurity standards, and audit expectations.

Job Responsibilities:
1. IT Governance & Policy Ownership
  • Develop, maintain, and enforce IT policies, standards, and procedures.
  • Ensure alignment with corporate governance frameworks.
  • Define control requirements applicable to infrastructure, systems, and data.
  • Explore IT General Controls (ITGC) and ISO 27001.
2. IT Risk & Compliance Management
  • Own IT risk identification, assessment, and treatment tracking.
  • Maintain IT risk registers, control matrices, and compliance dashboards.
  • Interpret regulatory and statutory IT requirements and translate them into control obligations.
3. Audit & Assurance (Primary Ownership)
  • Act as primary IT liaison for internal and external audits.
  • Coordinate audit walkthroughs, evidence collection, and control testing.
  • Track audit findings, corrective action plans, and closure.
4. Cybersecurity Governance
  • Own cybersecurity policies, access governance frameworks, and awareness programmes.
  • Monitor security compliance posture and report to management.
  • Ensure incident reporting, regulatory notifications, and post-incident reviews are completed.
5. Access & Data Governance
  • Define access control governance, approval workflows, and review cycles.
  • Own periodic access reviews and privileged access governance.
  • Oversee data classification, protection, and retention compliance.
6. Management & Operation Reporting
  • Prepare IT compliance, risk, and audit status reports.
  • Provide executive-level summaries to management and operation team.
7. Change Management Governance
  • Own and govern the IT Change Management framework, policies, and procedures.
  • Ensure all IT changes (infrastructure, applications, security, configurations) comply with:
  • Approved change approval workflows
  • Segregation of duties requirements
  • Documentation and impact assessment standards
  • Review and validate:
  • Emergency and retrospective changes
  • Change success and failure analysis
  • Monitor adherence to change controls and report exceptions, trends, and risks to management.
  • Ensure change records and evidence are audit-ready and retained in accordance with policy.
  • Govern IT-related contracts from a compliance, risk, and control perspective.
  • Review IT contracts to ensure inclusion of required clauses, including:
  • Information security and data protection
  • Regulatory and statutory compliance
  • Business continuity and exit provisions
  • Oversee vendor compliance obligations (security, audit, SLA, regulatory).
  • Coordinate third-party IT risk assessments and ensure remediation of identified gaps.
  • Track contract compliance milestones and accelerate non‑compliance issues.
Job Requirement:
  • Bachelor’s degree in information technology, Computer Science, Information Systems, Cyber Security, Business Information Systems, or related discipline.
  • Professional certification (Microsoft, Security and Networking, Cloud)
  • A strategic and analytical mindset.
  • Dynamic thinking and problem-solving abilities.
  • Knowledge of operating systems, current equipment and technologies, enterprise backup and recovery procedures, and system performance monitoring tools
  • Knowledge of IT infrastructure, network and systems to effectively manage and troubleshoot issues.
  • Excellent interpersonal skills.
  • Minimum 8–12 years of IT experience, with at least 5 years in IT Governance, Risk, Compliance (GRC), Information Security, Internal Controls, or IT Audit.
  • Proven experience managing IT compliance programs, risk management frameworks, and audit engagements.
  • Experience supporting multi-site, multi-country operations within a corporate or group environment.
  • Experience in managing external auditors, internal auditors, regulators, and third-party assessments.
  • Hands-on experience in IT policy development, control frameworks, and compliance monitoring.
  • Experience in vendor governance, contract management, and third-party risk management.
  • Familiarity with ITIL-based service management and change management processes.
  • Exposure to multi-entity, multi-country, or regulated environments is preferred.
  • Willingness to work outside of normal business hours.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Governance & Compliance Lead
IT Governance & Compliance Lead

Genting Energy • Kuala Lumpur

On-site
MYR 180,000 - 260,000
IT and Information Security Compliance Staff Auditor
IT and Information Security Compliance Staff Auditor

ThunderSoft • Penang

On-site
MYR 90,000 - 150,000
Executive - IT Audit
Executive - IT Audit

Sunway Group • Subang Jaya

On-site
MYR 60,000 - 100,000
Senior Analyst
Senior Analyst

Averis • Kuala Lumpur

On-site
MYR 60,000 - 100,000
IT Compliance Staff Auditor
IT Compliance Staff Auditor

ThunderSoft • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Analyst, Information Governance & Compliance
Analyst, Information Governance & Compliance

Averis Sdn Bhd • Kuala Lumpur

On-site
MYR 60,000 - 90,000
Head Governance ,Risk - Compliance
Head Governance ,Risk - Compliance

Carsome • Selangor

On-site
MYR 300,000 - 600,000
Senior Executive, IT Service Management & Governance
Senior Executive, IT Service Management & Governance

Raya Airways Sdn Bhd • Sepang

On-site
MYR 89,000 - 156,000
Associate, Cyber Security Governance, Risk & Compliance
Associate, Cyber Security Governance, Risk & Compliance

LGMS Berhad • Subang Jaya

On-site
MYR 70,000 - 120,000
Manager – ICT Governance & Compliance
Manager – ICT Governance & Compliance

Scicom MSC Berhad • Kampung Cendana

On-site
MYR 71,000 - 85,000
Salary up to RM7000
Medical insurance
Medical and hospitalization leaves
+1