GRC Consultant - Information Security - MY Based

Condition Zebra

Shah Alam

On-site

MYR 120,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive salary
Comprehensive benefits
Growth opportunities
Collaborative team
Impact resilience of regional orgs

Job summary

Condition Zebra is seeking a results-oriented GRC & IT Security Audit Consultant in Malaysia to manage client engagements with autonomy. The role focuses on compliance, framework, and process controls across IT security, risk strategies, and governance.

The successful candidate will lead IT security audits, manage evidence, guide ISO 27001 ISMS implementation, assess maturity against NIST CSF and CIS Controls, and advise on PDPA data privacy, vendor risk, and business continuity planning.

Qualifications

  • Bachelor's degree in Computer Science, IT, Cybersecurity, or related field.
  • 3–5+ years in IT security auditing, GRC consulting, or info security risk management.
  • Deep knowledge of ISO 27001, NIST CSF, CIS Controls, and PDPA.
  • Hold at least one certification: CISSP, CISM, CISA, CRISC, CCSP, or ISO 27001 Lead Auditor.
  • Strong audit cycles understanding and evidence gathering.
  • Excellent communication and project management skills.

Responsibilities

  • Plan, scope, and execute IT security audits aligning with governance standards.
  • Manage client evidence requests ensuring audit trail integrity.
  • Guide ISO 27001 ISMS implementation and maintenance.
  • Benchmark maturity against NIST CSF and CIS Controls.
  • Advise on PDPA data privacy; perform DPIAs and risk assessments.
  • Conduct vendor security risk assessments and review SOC 2.
  • Assist in designing BC/DR plans and deliver security awareness training.

Skills

IT Security Auditing
GRC Consulting
ISO 27001
NIST CSF
CIS Controls

Education

Bachelor's degree in Computer Science / IT / Cybersecurity

Job description

Jora Malaysia will close on 9th September 2026. Thank you for being with us, we are cheering you on as you continue your career journey.

GRC Consultant - Information Security - MY Based

We are seeking a results-oriented GRC & IT Security Audit Consultant to join our team. This role focuses entirely on the compliance, framework, and process controls side of IT Security. If you excel at designing risk strategies, leading compliance frameworks, and conducting comprehensive IT security audits, this position offers an excellent opportunity to manage client engagements with a high degree of autonomy.

Key Responsibilities
  • Lead IT Security Audits: oPlan, scope, and execute comprehensive IT compliance and control audits. Develop audit checklists, test internal controls, and verify that processes align with governance standards.
  • Audit Evidence Management: oManage and review client evidence request lists, ensuring that documentation, logs, and process artifacts meet strict compliance and audit trail integrity standards.
  • ISO 27001 Implementation: oGuide clients through the end-to-end implementation and maintenance of robust Information Security Management Systems (ISMS), helping them close gaps and prepare for formal ISO 27001 certification.
  • Cyber Maturity Assessments: oEvaluate and benchmark client security maturity levels against internationally recognized frameworks such as the NIST Cybersecurity Framework (CSF) and CIS Critical Security Controls.
  • Data Privacy & Compliance (PDPA): oFunction as the primary advisor on data protection regulations, specifically the Malaysian Personal Data Protection Act (PDPA), leading data mapping exercises and Data Protection Impact Assessments (DPIAs). oConduct process-driven risk assessments to identify operational liabilities and policy gaps, maintain enterprise Risk Registers, and establish formal mitigation workflows.
  • Third-Party Risk Management (TPRM): oExecute vendor security risk assessments, evaluating third-party compliance profiles, reviewing security questionnaires, and analyzing SOC 2 reports. oDevelop, review, and refine formal information security policies. Translate complex audit findings into clear, structured executive reports and actionable remediation roadmaps.
  • Resilience & Awareness: oAssist clients in designing and auditing Business Continuity (BCP) and Disaster Recovery (DR) plans, and deliver professional security awareness training to client staff.
Qualifications
  • Education: Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Business IT, or a related field.
  • Experience: 3 to 5+ years of hands-on experience strictly within IT Security Auditing, GRC consulting, or Information Security risk management roles. Proven track record of managing client-facing projects autonomously.
  • Framework & Regulatory Knowledge: Deep understanding of ISO 27001, NIST CSF, CIS Controls, and local regulations including the Malaysian PDPA.
  • Possess at least one of the following industry-recognized certifications: CISSP, CISM, CISA, CRISC, CCSP, ISO 27001 Lead Auditor.
  • Audit & Control Mastery: Strong foundational understanding of audit cycles, internal control concepts, segregation of duties, and systematic evidence gathering.
  • Professional Communication: Excellent written and verbal communication skills. Ability to clearly articulate complex risk and compliance exposure to both technical administrators and non-technical business leaders.
  • Project Management & Autonomy: Proven ability to effectively manage multiple auditing and consulting projects simultaneously, prioritize tasks dynamically, and consistently meet rigid deadlines.
  • Quality & Detail Focus: Uncompromising focus on accuracy, audit trail integrity, and delivering highly polished executive deliverables.
  • Competitive salary and comprehensive benefits package.
  • Structured opportunities for professional growth, including financial support for advanced cybersecurity certifications and continuous education.
  • Work within a dynamic, supportive, and highly collaborative team of cybersecurity and infrastructure specialists.
  • A challenging and rewarding advisory environment with the opportunity to directly impact the resilience of prominent regional organizations.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity GRC Analyst
Cybersecurity GRC Analyst

Srpailabs.com • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Senior Manager, Governance, Risk and Compliance
Senior Manager, Governance, Risk and Compliance

Daythree Business Services • Shah Alam

On-site
MYR 180,000 - 260,000
Executive, IT Risk - Security (GRC)
Executive, IT Risk - Security (GRC)

Zetrix AI • Selangor

Hybrid
MYR 51,000 - 61,000
Health insurance
Opportunities for promotion
IT Governance, Risk & Compliance Manager
IT Governance, Risk & Compliance Manager

CapBay • Kuala Lumpur

Hybrid
MYR 90,000 - 150,000
IT GRC Manager
IT GRC Manager

Michael Page • Kuala Lumpur

On-site
MYR 135,000 - 165,000
Competitive salary
Good work culture
GRC & InfoSec Consultant - ISO27001/PDPA
GRC & InfoSec Consultant - ISO27001/PDPA

Condition Zebra • Shah Alam

On-site
MYR 120,000 - 160,000
Competitive salary
Comprehensive benefits
Growth opportunities
+2
Senior IT Risk & Compliance Specialist
Senior IT Risk & Compliance Specialist

MOL AccessPortal • Kuala Lumpur

On-site
MYR 120,000 - 180,000
IT Project Manager (GRC / Technology Risk)
IT Project Manager (GRC / Technology Risk)

Tentacle Technologies • Kuala Lumpur

On-site
MYR 180,000 - 280,000
High visibility project
Mentorship and guidance
Training & development
+1
GRC Analyst Kuala Lumpur, Malaysia GRC Analyst
GRC Analyst Kuala Lumpur, Malaysia GRC Analyst

Sitecore • Kuala Lumpur

On-site
MYR 60,000 - 90,000
Manager – ICT Governance - Compliance
Manager – ICT Governance - Compliance

Scicom (MSC) Berhad • Kuala Lumpur

On-site
MYR 67,000 - 78,000
Salary up to RM7000
Performance related allowance forStaff