Auditor | Cyber Security & Regulatory

EPF Malaysia

Petaling Jaya

On-site

MYR 120,000 - 180,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

EPF Malaysia is seeking a capable IT Audit professional to support risk-based audit engagements, focusing on cybersecurity and regulatory controls across digital technology environments.

You will execute fieldwork, test controls, analyze vulnerabilities and KRIs, prepare working papers, and contribute to analytics-enabled, AI-driven audit practices and continuous auditing to strengthen governance, risk, and compliance.

Qualifications

  • Bachelor’s degree in IT, cyber security, CS or accounting.
  • 4–7 years in IT audit, cybersecurity or technology risk management.
  • Professional certifications such as CISA, CISSP, CISM or CRISC.

Responsibilities

  • Support risk-based annual audit plans including cybersecurity and regulatory compliance.
  • Execute risk-based audit assignments in accordance with GIAS and EPF methodology.
  • Perform walkthroughs, control testing and documentation of audit evidence.
  • Identify control deficiencies and root causes in cybersecurity and regulatory areas.
  • Prepare audit observations, reports and management communications.

Skills

Cybersecurity governance
IT audit
Risk assurance
Regulatory compliance
Data analytics

Education

Bachelor’s Degree in IT / Cyber Security / CS / Accounting

Job description

Support the Manager and Head of Unit, Cyber Security & Regulatory (HOU) in executing risk-based audit engagements by delivering assigned audit assignments, assessing cybersecurity and regulatory controls, and delivering data-driven assurance across digital technology environments, while supporting the development of audit methodologies, analytics-enabled audit practices, AI-driven initiatives and real-time continuous auditing to strengthen governance, risk management, and compliance.

JOB RESPONSIBILITIES
  • Support the Manager and HOU in developing and executing risk-based annual audit plans, ensuring coverage of cybersecurity, regulatory compliance, and emerging technology risks aligned with organisational priorities
  • Execute risk-based audit assignments across cybersecurity and regulatory domains in accordance with the Global Internal Audit Standards (GIAS) and EPF audit methodology.
  • Support audit planning and execute audit fieldwork activities, including walkthroughs, control testing, and the documentation of audit evidence.
  • Execute complex audit testing activities, including risk assessments, and the identification and evaluation of key technology risks and process controls.
  • Evaluate the adequacy and effectiveness of cybersecurity and regulatory controls, including compliance with relevant laws, regulations, standards and practices covering the Cyber Security Act, PDPA, ISO ISMS, network security, security monitoring, incident management, vulnerability management, cloud security, encryption and vendor management.
  • Apply risk-based audit testing procedures and document findings, control gaps and root causes.
  • Perform risk-based control testing and evaluate audit evidence to determine compliance with policies, procedures, standards and regulatory requirements, control gaps and root causes.
  • Identify control deficiencies pertaining to cybersecurity and regulatory requirements, emerging risks and improvement opportunities through systematic analysis of processes, systems and supporting documentation.
  • Execute audit across complex IT and hybrid environments.
  • Assess the potential business impact of control weaknesses and support the development of practical and risk-based recommendations
  • Prepare and maintain audit working papers, document audit procedures, testing results, supporting evidence and conclusions in accordance with audit quality and documentation standards.
  • Prepare audit observations, reports and management communications to communicate key findings, risks and recommendations, and support informed decision-making.
  • Coordinate audit issue validation sessions with auditees to ensure factual accuracy and root cause identification
  • Perform follow-up reviews to assess the adequacy and effectiveness of corrective actions implemented by management for closure tracking.
  • Identify emerging cyber risks, regulatory changes and technology threats for incorporation into audit execution activities.
  • Ensure quality and accuracy of audit deliverables under supervision.
  • Deliver assigned audit assignments within timelines and quality standards.
  • Leverage data analytics and technology-enabled audit techniques to improve audit effectiveness, efficiency and coverage with insights generation.
  • Support continuous auditing, automation and AI-enabled audit initiatives.
  • Support the enhancement of audit methodologies, audit programmes, testing techniques and digital audit initiatives.
  • Maintain current knowledge of technology risks, cybersecurity threats, industry developments, audit practices and regulatory expectations relevant to technology assurance.
  • Support continuous learning through structured training programmes, knowledge sharing and professional development certifications.
  • Share knowledge, insights and best practices with team members to strengthen audit capability and technical competency.
JOB COMPETENCIES & SKILLS
  • Strong understanding of cybersecurity governance, IT audit and risk assurance practices.
  • Good knowledge in risk-based audit approach, execution and emerging technology risk assessment
  • Familiarity with industry frameworks, standards and regulations, including GIAS, COBIT, ITIL, ISO 27001, NIST, CIS, the Cyber Security Act, PDPA and BNM guidelines.
  • Experience in network security, vulnerability management, incident management or cloud security audit review.
  • Execute audits over security operations, monitoring and incident management, aligned to defined assurance standards and maturity models.
  • Support the application of continuous monitoring techniques and AI analyst over SIEM, SOAR, threat intelligence.
  • Ability to analyse Vulnerability Assessment (VA) and Penetration Testing (PT) results, including evaluation of control effectiveness, KRIs and residual risks.
  • Good knowledge of network infrastructure, security configurations, security posture assessment, control effectiveness and risk exposure analysis to support audit reviews and management decision-making.
  • Experience in executing audit reviews on network security architecture, defence mechanisms and third- party monitoring controls, considering emerging threats.
  • Performed audit review in-line with regulatory and compliance requirements (GIAS, Cyber Security Act, PDPA, BNM RMiT, ISO ISMS/ITSM).
  • Performed audit review on vendor risk management, control effectiveness and performance monitoring practices.
  • Knowledge on data analytics tools, digital audit techniques and AI tools.
  • Utilise data analytics and technology-enabled audit techniques to support audit activities.
  • Strong written and verbal communication skills, including audit documentation and report writing.
  • Knowledge of cloud technologies, digital platforms and emerging technology risks is an advantage
JOB REQUIREMENTS
  • Pass in Bahasa Melayu, including oral test in Sijil Pelajaran Malaysia (SPM) level or equivalent qualification recognised by the Government.
  • Possess a Bachelor’s Degree in Information Technology, Cyber Security, Computer Science, Accounting or an equivalent field recognised by the Government, from an accredited higher learning institution.
  • Minimum 4 – 7 years of relevant experience in IT audit, Cybersecurity, Technology Risk Management, IT operations or related technology assurance functions.
  • Possess professional certifications such as:

a) CISA, CISSP, CISM or CRISC (required).

b) Additional cloud or cybersecurity certifications (e.g., CCSP, CEH) would be an added advantage.

JOB STATUS

Permanent

All applications are strictly CONFIDENTIAL, and only shortlisted candidates will be called in for interview. Applications are deemed UNSUCCESSFUL if there is no feedback from the EPF 2 MONTHS after the closing date of advertisement.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity & Regulatory Audit Specialist
Cybersecurity & Regulatory Audit Specialist

EPF Malaysia • Petaling Jaya

On-site
MYR 120,000 - 180,000
INFORMATION SYSTEM / IT AUDIT EXECUTIVE
INFORMATION SYSTEM / IT AUDIT EXECUTIVE

SmartHire by SEEK • Kuala Lumpur

On-site
MYR 60,000 - 90,000
Auditor | Department Unit (Operations Audit)
Auditor | Department Unit (Operations Audit)

EPF Malaysia • Petaling Jaya

On-site
MYR 90,000 - 150,000
Executive - IT Audit
Executive - IT Audit

Sunway Berhad • Subang Jaya

On-site
MYR 60,000 - 100,000
Senior Manager/ Manager - IT Audit
Senior Manager/ Manager - IT Audit

Genting Plantations Berhad • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Senior Consultant - Tech Risk, Cyber & Privacy Advisory
Senior Consultant - Tech Risk, Cyber & Privacy Advisory

EC-Council Global Services • Kuala Lumpur

On-site
MYR 150,000 - 210,000
Information Technology Audit Manager
Information Technology Audit Manager

NTT DATA Payment Services • Kuala Lumpur

On-site
MYR 90,000 - 130,000
IT Internal Auditor
IT Internal Auditor

IJM Corporation Berhad • Petaling Jaya

On-site
MYR 90,000 - 140,000
Lead, Technology Audit
Lead, Technology Audit

Quintus Search • Kuala Lumpur

On-site
MYR 180,000 - 280,000
Senior Executive, IT Audit
Senior Executive, IT Audit

Hong Leong Investment Bank • Petaling Jaya

On-site
MYR 70,000 - 110,000