GRC Analyst

Sitecore

Kuala Lumpur

On-site

MYR 60,000 - 100,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Sitecore in Kuala Lumpur is seeking a detail-oriented GRC Analyst to join our security and compliance team. You will contribute to governance, risk management, audits, and regulatory compliance across ISO and GDPR, while supporting AI governance programs.

Work with cross-functional teams across Engineering, Legal, Procurement, and IT, maintaining documentation in SharePoint, Jira, and Confluence. A bachelor’s degree and 3+ years in GRC are required; experience with OneTrust, Drata, or Vanta is a

Qualifications

  • 3+ years of experience in GRC, risk management, audit support, or compliance role.
  • Able to operate independently, anticipate needs, and drive audit activities with minimal supervision.
  • Familiarity with ISO 27001, ISO 42001, SOC 2, HIPAA, GDPR, PCI DSS, NIST, IRAP or similar.
  • Experience across multiple time zones and strong collaboration with cross-functional teams.

Responsibilities

  • Support governance and compliance programs aligned with ISO 27001, SOC 2, GDPR, and other standards.
  • Assist in maintaining and updating security policies, procedures, and controls.
  • Conduct compliance reviews, identify gaps, and define remediation actions.
  • Monitor regulatory changes and contribute to compliance strategy updates.
  • Support AI governance program to ensure responsible and compliant use of AI technologies.

Skills

GRC experience
Audit coordination
Regulatory compliance

Education

Bachelor's degree in information technology or cybersecurity

Tools

OneTrust
Drata
Vanta

Job description

About Us:

At Sitecore, our mission is to simplify how brands reach, engage, and serve people by delivering intelligent, personalised digital experiences that connect the world. We empower the world’s most iconic brands to build lifelong relationships with their customers—seamlessly, smartly, and at scale.

As the leading provider of agentic digital experience software, Sitecore brings together content, commerce, and data into one composable platform that enables brands to deliver millions of meaningful, adaptive experiences every day. Trusted by global leaders such as American Express, Porsche, Starbucks, and L’Oréal, Sitecore helps brands transform engagement through experiences that are not only personalised but predictive and dynamic.

Our foundation is our people—a diverse, passionate, and collaborative global team spanning over 25 countries. We believe that every experience matters, and that belief starts with how we work together. Our values—empathy, accountability, clarity, and growth—guide how we lead, innovate, and connect. They are the behaviors that bring our mission and vision to life, every day, in every interaction.

As we continue to evolve, we are actively cultivating AI skills across our teams to unlock new levels of creativity, efficiency, and insight. From engineering to customer experience, AI capabilities are becoming integral to how we design, build, and deliver the next generation of digital experiences.

Learn more at Sitecore.com

About the Role:

We are looking for a detail-oriented and proactive GRC (Governance, Risk, and Compliance) Analyst to join our team. This role will be based in Kuala Lumpur, Malaysia and will support operations aligned with U.S. Central (Eastern time zones)/Europe (GMT+1).

The GRC Analyst will report to the GRC Manager contributing to the day-to-day execution of compliance programs, audit preparation, risk assessments, and overall security governance efforts. This is a hands-on role, ideal for someone who thrives in a collaborative, fast-paced environment and is passionate about security, compliance, and risk management.

What You’ll Do:
Governance & Compliance
  • Support the implementation and maintenance of compliance programs aligned with frameworks such as ISO 27001, ISO 42001, SOC 2, HIPAA, PCI DSS, GDPR, TISAX, NIST, and IRAP.
  • Assist in maintaining and updating security policies, procedures, and controls to ensure alignment with regulatory requirements.
  • Conduct compliance reviews to identify gaps and assist in defining remediation actions.
  • Monitor changes in regulatory requirements and provide input into compliance strategy and updates.
  • Support the implementation and ongoing operation of the organization's AI Governance program, helping to ensure the responsible, ethical, and compliant use of AI technologies.
Audit Support
  • Collaborate with internal stakeholders to coordinate audit-related activities, including evidence collection, documentation preparation, and status reporting.
  • Maintain audit calendars, track deliverables, and ensure readiness for internal and external audits.
Risk Management
  • Support periodic risk assessments (Information Security,AI), helping to identify, document, and track technology and process risks.
  • Maintain the risk and findings register, ensuring items are regularly updated and monitored for progress.
Cross-Functional Collaboration
  • Work closely with teams across Engineering, Product, Legal, Procurement, and Information Technology to support compliance initiatives and ensure timely completion of action items.
  • Provide ongoing support and clarity to teams on compliance tasks and expectations.
Reporting & Documentation
  • Assist in preparing and delivering status reports, dashboards, and metrics on GRC activities for leadership and stakeholders.
  • Ensure that compliance documentation is consistently updated and centrally stored (e.g., SharePoint, Jira, Confluence).
What You Need to Succeed
  • Bachelor’s degree in information technology, cybersecurity, or a related field.
  • Familiarity with industry standards and frameworks such as ISO 27001, ISO 42001, SOC 2, HIPAA, GDPR, PCI DSS, NIST, and others.
  • Experience in AI Governance, ISO 42001, AI risk management, and knowledge of the EU AI Act, NIST AI RMF, or other emerging AI regulations is highly desirable.
  • 3 + years of experience in GRC, risk management, audit support, or compliance role.
  • Able to operate on own initiative, anticipating needs, identifying gaps, and proactively contributing to audit, risk, and compliance activities.
  • Personable and collaborative, with strong interpersonal skills and the ability to build effective working relationships across diverse teams.
  • Working towards being self-sufficient and proactive, able to take ownership of tasks and drive work forward with minimal supervision.
  • Comfortable working across multiple time zones, demonstrating flexibility and clear communication in a global environment.
Additional Skills That Could Set You Apart:
  • Experience working with GRC Tooling/ compliance management framework (e.g Vanta, Drata, OneTrust etc) is a plus.
  • Experience in AI Governance, ISO 42001, and knowledge of the EU AI Act is a plus.
  • This role requires full coverage of U.S. Central or Eastern time zone hours. (12-8pm MYT)
  • Occasional flexibility may be needed to support urgent compliance or audit activities.
  • Highly organized and detail-oriented, with the ability to manage multiple priorities and maintain structure in a fast-paced environment.

Sitecore is proud to be an equal opportunity workplace. We are committed to equal employment opportunity without unlawful regard to race, color, ancestry, religion, gender, national origin, sexual orientation, age, citizenship, marital status, disability, veteran status or any other local legally protected characteristic.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Analyst Kuala Lumpur, Malaysia GRC Analyst
GRC Analyst Kuala Lumpur, Malaysia GRC Analyst

Sitecore • Kuala Lumpur

On-site
MYR 60,000 - 90,000
GRC Analyst: AI Governance & Compliance
GRC Analyst: AI Governance & Compliance

Sitecore • Kuala Lumpur

On-site
MYR 60,000 - 100,000
Global GRC Analyst: Compliance, Risk & Audit (US Hours)
Global GRC Analyst: Compliance, Risk & Audit (US Hours)

Sitecore • Kuala Lumpur

On-site
MYR 60,000 - 90,000
DevSecOps Engineer (GRC)
DevSecOps Engineer (GRC)

Respond • Kuala Lumpur

On-site
MYR 120,000 - 240,000
Mental health allowance
Flexible working hours
Competitive compensation package
+2
Senior Manager, Governance, Risk and Compliance
Senior Manager, Governance, Risk and Compliance

Daythree Business Services • Shah Alam

On-site
MYR 180,000 - 260,000
GRC Consultant - Information Security - MY Based
GRC Consultant - Information Security - MY Based

Condition Zebra (M) Sdn. Bhd. • Selangor

On-site
MYR 120,000 - 180,000
Competitive salary
Professional growth support
Collaborative team
+1
GRC Consultant - Information Security - MY Based
GRC Consultant - Information Security - MY Based

Condition Zebra • Shah Alam

On-site
MYR 120,000 - 160,000
Competitive salary
Comprehensive benefits
Growth opportunities
+2
Cybersecurity GRC Analyst
Cybersecurity GRC Analyst

Niaga Prestasi • Kuala Lumpur

On-site
MYR 100,000 - 160,000
IT Governance, Risk & Compliance Manager
IT Governance, Risk & Compliance Manager

CapBay • Kuala Lumpur

Hybrid
MYR 90,000 - 150,000
Cybersecurity GRC Analyst
Cybersecurity GRC Analyst

Srpailabs.com • Kuala Lumpur

On-site
MYR 120,000 - 180,000