Information Security Compliance Analyst

MEDIAMONKS MALAYSIA SDN. BHD.

Kuala Lumpur

On-site

MYR 90,000 - 150,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

MEDIAMONKS MALAYSIA SDN. BHD.

is seeking an Information Security Compliance Analyst to safeguard data, enforce regulations, and strengthen our security posture across APAC in collaboration with the Global Infosec Team. You will conduct risk assessments, manage client requirements, and ensure compliance with ISO27001:2022, SOC2, and NIST-800 while coordinating with vendors and internal stakeholders to implement effective controls.

Qualifications

  • Bachelor's degree in Computer Science, Computer or Systems Engineering or equivalent.
  • Minimum of 5 years of experience in InfoSec related positions.
  • Solid knowledge of security on networking, cloud, infrastructure configuration, end‑point protection and SDLC.
  • Knowledge of ISO 27001/2, SOC2, NIST-800.
  • Professional working proficiency in written and spoken English.
  • Ability to confidently present findings to those with either a technical or non-technical background.
  • Self-directed, resourceful, and a critical thinker with attention‑to‑detail and proactive problem‑solving skills.
  • Ability to self-organize and plan activities with commitment towards results.
  • Ready to learn new contents both from others or self‑learned.
  • Looking forward to self-improvement and suggesting improvements to processes or activities.

Responsibilities

  • Lead the alignment to the global ISMS (based on ISO27001:2022) over the APAC region.
  • Integrate the compliance efforts in the region with the global roadmap.
  • Perform routine activities to evaluate compliance with security frameworks and legislation.
  • Report the compliance status of processes and technology in the region.
  • Identify risk related to information security in the technical environment, the relationships with third parties or any component of the company's operations.
  • Define security measures to lower the risks identified.
  • Understand about technical and administrative controls in the different areas: networking, operations, access management, SSDLC, cloud security, end‑point protection, physical security, third party risk assessment, organization security and legal compliance.
  • Coordinate the information security assessments with 3rd parties (clients, suppliers).
  • Contribute in the development of awareness material and the process of delivery and measurement.
  • Coordinate and reply to internal and external audits related to information security.
  • Investigate on technologies that could improve the security baseline and the compliance (e.g. DLP, end‑point protection, network security, security and vulnerabilities assessment).
  • Empower, assist, and mentor fellow members of the team to foster their professional growth and ensure collective success.

Education

Bachelor's degree in Computer Science, Computer or Systems Engineering or equivalent

Job description

As an Information Security Compliance Analyst, your core responsibility will be to ensure the organization's strict adherence to all pertinent regulations and standards. Your critical role will involve safeguarding customer and company data, protecting the company's reputation,and making vital decisions that are integral to shaping the state‑of‑the‑art security posture for the business's future success.

This person should understand the risk assessment process to detect new threats, contribute in the action plan development and promote the progress of control implementation and evolution. The position will cover compliance activities, third parties risk assessments, management of clients requirements, internal awareness and technical controls evaluation.

As a valuable member of our Global Infosec Team, you will have the opportunity to collaborate with colleagues across the globe, fostering a dynamic and diverse work environment. Your role will involve working closely with stakeholders from various departments, forging strong partnerships to ensure the collective success of our information security initiatives.

Responsibilities:

Lead the alignment to the global ISMS (based on ISO27001:2022) over the APAC region.

Integrate the compliance efforts in the region with the global roadmap.

Perform routine activities to evaluate compliance with security frameworks and legislation.

Report the compliance status of processes and technology in the region.

Identify risk related to information security in the technical environment, the relationships with third parties or any component of the company's operations.

Define security measures to lower the risks identified.

Understand about technical and administrative controls in the different areas: networking, operations, access management, SSDLC, cloud security, end‑point protection, physical security, third party risk assessment, organization security and legal compliance.

Coordinate the information security assessments with 3rd parties (clients, suppliers).

Contribute in the development of awareness material and the process of delivery and measurement.

Coordinate and reply to internal and external audits related to information security.

Investigate on technologies that could improve the security baseline and the compliance (e.g. DLP, end‑point protection, network security, security and vulnerabilities assessment).

Empower, assist, and mentor fellow members of the team to foster their professional growth and ensure collective success.

About You
The essentials:

Bachelor's degree in Computer Science, Computer or Systems Engineering or equivalent.

Minimum of 5 years of experience in InfoSec related positions.

Solid knowledge of security on networking, cloud, infrastructure configuration, end‑point protection and SDLC.

Knowledge of the standards ISO 27001/2, SOC2, NIST-800.

Professional working proficiency in written and spoken English

Ability to confidently present findings to those with either a technical or non-technical background.

Self‑directed, resourceful, and a critical thinker with attention‑to‑detail and proactive problem‑solving skills.

Ability to self‑organize and plan activities with commitment towards results.

Ready to learn new contents both from others or self‑learned.

Looking forward to self‑improvement and suggesting improvements to processes or activities.

Not a must, but a plus:

+4 year of dedicated experience in any of the following areas:

Security Risk Management

Security Consultant

Security/IT ISO implementer

Information Security Certification (e.g. CISSP, CCSP, CISM, AWS Security Specialist, etc)

Unlock job insights

Hirer responsiveness Salary match Number of applicants

Advertising, Marketing & Communications Services 1,001-5,000 employees

Monks is the global digital brand of S4Capital, combining marketing, tech services, and AI‑powered data science to help businesses accelerate and innovate. We deliver scalable content, enterprise‑grade technology, and integrated workflows, powered by top digital talent. Monks was named a Contender in The Forrester Wave™: Global Marketing Services.

We are an equal‑opportunity employer, committed to fostering a diverse, inclusive work environment where everyone can thrive and contribute unique perspectives. Please be aware of fraudulent job postings and always apply via our website career page. We never ask for payment or bank details.

Monks is the global digital brand of S4Capital, combining marketing, tech services, and AI‑powered data science to help businesses accelerate and innovate. We deliver scalable content, enterprise‑grade technology, and integrated workflows, powered by top digital talent. Monks was named a Contender in The Forrester Wave™: Global Marketing Services.

We are an equal‑opportunity employer, committed to fostering a diverse, inclusive work environment where everyone can thrive and contribute unique perspectives. Please be aware of fraudulent job postings and always apply via our website career page. We never ask for payment or bank details.

To help fast track investigation, please include here any other relevant details that prompted you to report this job ad as fraudulent / misleading / discriminatory / salary below minimum wage.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Compliance Analyst
Information Security Compliance Analyst

InfoSec • Kuala Lumpur

On-site
MYR 100,000 - 167,000
Global ISMS Compliance Lead – APAC
Global ISMS Compliance Lead – APAC

InfoSec • Kuala Lumpur

On-site
MYR 100,000 - 167,000
APAC IT Manager (Cybersecurity)
APAC IT Manager (Cybersecurity)

The Hoffman Agency • Kuala Lumpur

On-site
MYR 180,000 - 320,000
APAC IT Manager (Cybersecurity)
APAC IT Manager (Cybersecurity)

hoffmanagency • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Competitive salary
Four‑week sabbatical after four years
Career advancement opportunities
[Hybrid] Local Security Officer (LSO)
[Hybrid] Local Security Officer (LSO)

TMF Administrative Services Malaysia Sdn. Bhd. • Kuala Lumpur

On-site
MYR 120,000 - 170,000
IT Administrator (SysOps)
IT Administrator (SysOps)

Corp iT • Kuala Lumpur

Hybrid
MYR 100,000 - 145,000
Hybrid work model
Growth Marketing Specialist
Growth Marketing Specialist

MEDIAMONKS MALAYSIA SDN. BHD. • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Security Consultant
Security Consultant

NTT DATA • Kuala Selangor

On-site
MYR 120,000 - 180,000
APAC ISMS & Compliance Lead (ISO 27001)
APAC ISMS & Compliance Lead (ISO 27001)

MEDIAMONKS MALAYSIA SDN. BHD. • Kuala Lumpur

On-site
MYR 90,000 - 150,000
IT Administrator (SysOps)
IT Administrator (SysOps)

Monks • Kuala Lumpur

Hybrid
MYR 54,000 - 96,000