Governance Risk and Compliance Senior

Hytech

Kuala Lumpur

On-site

MYR 120,000 - 180,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Public transport access
Insurance coverage (corporate)
Gym benefits
Training opportunities
Career growth projects

Job summary

Hytech, a leading management consulting firm with offices in Australia, Singapore and Malaysia, seeks a Cyber Security Governance Specialist in Kuala Lumpur. You will strengthen governance, risk and compliance frameworks and guide stakeholders on ISO 27001, NIST CSF and PCI-DSS, embedding GRC into operations.

You will develop risk registers, dashboards and policies, mentor junior analysts, and advise on regulatory changes, ensuring resilience and trust across the business.

Qualifications

  • 3+ years in cyber-security, technology risk, or security consulting.
  • Hands-on delivery of ISO 27001 and PCI-DSS certification projects.
  • Experience guiding senior stakeholders through NIST CSF or equivalent reviews.
  • Working knowledge of offensive-security methodologies to inform strategic risk decisions.
  • Strong experience building risk registers, executive dashboards, and board reports.

Responsibilities

  • Assess cyber-risk and control-maturity and translate findings into executive insights and roadmaps.
  • Build and embed cyber-risk programmes: risk registers, treatment plans, dashboards.
  • Develop policies, standards, and procedures that are compliant and practical for engineers.
  • Own and maintain the GRC framework and policy stack; embed the three lines of defence.
  • Guide stakeholders through audits and regulatory reviews (e.g., APRA CPS 234, SOC 2).
  • Monitor regulatory changes and advise business stakeholders on impact within 30 days.
  • Develop multi-year cyber-security and risk strategies aligned to corporate OKRs.
  • Present risk posture, KPI/KRI trends, and investment options to boards and regulators.
  • Mentor junior GRC analysts and upskill cross-functional teams on secure-by-design.

Skills

3+ years in cyber-security

Education

Master’s degree in Cybersecurity, Risk, Business, or MBA
CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor

Job description

Hytech is a leading management consulting firm headquartered in Australia and Singapore, specialising in digital transformation for fintech and financial services organisations. We deliver end-to-end consulting services and provide robust middle- and back-office solutions that enable our clients to optimise operations, enhance efficiency, and stay ahead in a fast-evolving digital landscape.

With more than 2,000 professionals worldwide, Hytech has a strong and growing international presence, with offices across Australia, Singapore, Malaysia, Taiwan, the Philippines, Thailand, Morocco, Cyprus, Dubai, and beyond.

About Role

We are seeking a Cyber Security Governance Specialist to strengthen our group company’s cyber-security frameworks and risk posture. In this role, you will collaborate with internal teams and guide stakeholders on key security standards and frameworks, including:

  • ISO/IEC 27001
  • NIST Cybersecurity Framework (CSF) & NIST SP 800 series
  • PCI-DSS

Your work will ensure that governance, risk, and compliance (GRC) principles are embedded into business operations, enabling the company to maintain resilience, compliance, and trust.

Key Responsibilities
1. Assess & Benchmark
  • Conduct cyber-risk and control-maturity assessments (NIST CSF, ISO 27001, Essential Eight, proprietary models).
  • Translate technical findings into executive-level insights and actionable roadmaps.
  • Build and embed cyber-risk programmes: risk registers, treatment plans, dashboards.
  • Develop policies, standards, and procedures that are both compliant and practical for engineers.
3. Governance & Compliance
  • Own and maintain the GRC framework and policy stack; embed the three lines of defence.
  • Guide stakeholders through audits and regulatory reviews (e.g., APRA CPS 234, SOC 2).
  • Monitor regulatory changes and advise business stakeholders on impact within 30 days.
4. Strategic Advisory
  • Develop multi-year cyber-security and risk strategies aligned to corporate OKRs.
  • Present risk posture, KPI/KRI trends, and investment options to boards and regulators.
5. Leadership & Coaching
  • Mentor junior GRC analysts and upskill cross-functional teams on secure-by-design and offensive-security principles.
  • Foster a culture of continuous improvement and measurable risk reduction.
Qualifications & Experience
  • 3+ years in cyber-security, technology risk, or security consulting.
  • Hands-on delivery of ISO 27001 and PCI-DSS certification projects.
  • Experience guiding senior stakeholders through NIST CSF or equivalent reviews.
  • Working knowledge of offensive-security methodologies to inform strategic risk decisions.
  • Strong experience building risk registers, executive dashboards, and board reports.
Preferred / Nice-to-Have
  • Master’s degree in Cybersecurity, Risk, Business, or MBA.
  • Professional certifications: CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor.
  • Exposure to AI governance and data ethics (e.g., NIST AI RMF).
  • Prior line-management of GRC, security architecture, or penetration testing teams.
What We Offer
  • Easy access to public transportation (LRT & KTM).
  • Corporate insurance coverage, including dental, optical, and outpatient claims.
  • Gym and fitness claims.
  • Ongoing training and development opportunities.
  • Exposure to exciting projects that support career growth and professional development.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber GRC Senior: ISO 27001 & PCI-DSS Leader
Cyber GRC Senior: ISO 27001 & PCI-DSS Leader

Hytech • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Public transport access
Insurance coverage (corporate)
Gym benefits
+2
Senior SOC Engineer
Senior SOC Engineer

Hytech • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Public transport access
Corporate insurance (dental, optical,
Gym and fitness claims
+2
Senior SOC Engineer
Senior SOC Engineer

Hytech Consulting Management Sdn Bhd • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Public transport access
Corporate insurance (dental, optical,–
Gym and fitness claims
+1
Senior Project Manager
Senior Project Manager

Atome • Kuala Lumpur

On-site
MYR 80,000 - 120,000
Collaborative workplace
Exposure to high-impact platforms
Opportunity for professional growth
Senior Security Business Partner – S-SDLC / Product Security
Senior Security Business Partner – S-SDLC / Product Security

Atome • Kuala Lumpur

On-site
MYR 180,000 - 260,000
Senior DevSecOps Security Engineer
Senior DevSecOps Security Engineer

Hytech • Kuala Lumpur

On-site
MYR 180,000 - 320,000
Public transport access
Professional development
Insurance coverage
SOC Team Lead
SOC Team Lead

Hytech Consulting Management Sdn Bhd • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Public transportation access
Corporate insurance coverage (dental,光
Gym and fitness claims
+1
Penetration tester
Penetration tester

Atome • Kuala Lumpur

On-site
MYR 60,000 - 100,000
Public transport access
Corporate insurance including dental/眼
Compliance & AML Specialist
Compliance & AML Specialist

Hytech • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Senior Financial Performance Analyst
Senior Financial Performance Analyst

Hytech • Kuala Lumpur

On-site
MYR 75,000 - 120,000
Corporate insurance (Dental, Optical,
Outpatient claims)
Gym and fitness claims
+1