Information Security Compliance Analyst

Firewood Marketing, Inc.

Kuala Lumpur

On-site

MYR 120,000 - 180,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Monks is seeking an Information Security Compliance Analyst to ensure adherence to regulatory standards and protect customer and company data. You will shape the security posture and collaborate with global Infosec teams across regions.

The role covers risk assessment, third-party risk, audit coordination, and development of awareness materials, with emphasis on ISO27001:2022, SOC2, and NIST-800 controls across APAC.

Qualifications

  • Bachelor's degree in Computer Science, Computer or Systems Engineering or equivalent.
  • Minimum of 5 years of experience in InfoSec related positions.
  • Solid knowledge of security on networking, cloud, infrastructure configuration, end-point protection and SDLC.
  • Knowledge of the standards ISO 27001/2, SOC2, NIST-800.
  • Professional working proficiency in written and spoken English.
  • Ability to confidently present findings to those with either a technical or non-technical background.
  • Self-directed, resourceful, and a critical thinker with attention-to-detail and proactive problem-solving skills.
  • Ability to self-organize and plan activities with commitment towards results.
  • Ready to learn new contents both from others or self-learned.
  • Looking forward to self-improvement and suggesting improvements to processes or activities.

Responsibilities

  • Lead the alignment to the global ISMS (based on ISO27001:2022) over the APAC region.
  • Integrate the compliance efforts in the region with the global roadmap.
  • Perform routine activities to evaluate compliance with security frameworks and legislation.
  • Report the compliance status of processes and technology in the region.
  • Identify risk related to information security in the technical environment, the relationships with third parties or any component of the company's operations.
  • Define security measures to lower the risks identified.
  • Understand about technical and administrative controls in the different areas: networking, operations, access management, SSDLC, cloud security, end-point protection, physical security, third party risk assessment, organization security and legal compliance.
  • Coordinate the information security assessments with 3rd parties (clients, suppliers).
  • Contribute in the development of awareness material and the process of delivery and measurement.
  • Coordinate and reply to internal and external audits related to information security.
  • Investigate on technologies that could improve the security baseline and the compliance (e.g. DLP, end-point protection, network security, security and vulnerabilities assessment).
  • Empower, assist, and mentor fellow members of the team to foster their professional growth and ensure collective success.

Skills

InfoSec expertise
Networking security
Cloud security
SDLC
Audits & compliance
Presentation skills
Risk assessment

Education

Bachelor's degree in Computer Science/Engineering or equivalent

Job description

Please note that we will never request payment or bank account information at any stage of the recruitment process. As we continue to grow our teams, we urge you to be cautious of fraudulent job postings or recruitment activities that misuse our company name and information. Please protect your personal information during any recruitment process. While Monks may contact potential candidates via LinkedIn, all applications must be submitted through our official website (monks.com/careers ).

As an Information Security Compliance Analyst, your core responsibility will be to ensure the organization's strict adherence to all pertinent regulations and standards. Your critical role will involve safeguarding customer and company data, protecting the company's reputation,and making vital decisions that are integral to shaping the state-of-the-art security posture for the business's future success.

This person should understand the risk assessment process to detect new threats, contribute in the action plan development and promote the progress of control implementation and evolution. The position will cover compliance activities, third parties risk assessments, management of clients requirements, internal awareness and technical controls evaluation.

As a valuable member of our Global Infosec Team, you will have the opportunity to collaborate with colleagues across the globe, fostering a dynamic and diverse work environment. Your role will involve working closely with stakeholders from various departments, forging strong partnerships to ensure the collective success of our information security initiatives.

Responsibilities:
  • Lead the alignment to the global ISMS (based on ISO27001:2022) over the APAC region.
  • Integrate the compliance efforts in the region with the global roadmap.
  • Perform routine activities to evaluate compliance with security frameworks and legislation.
  • Report the compliance status of processes and technology in the region.
  • Identify risk related to information security in the technical environment, the relationships with third parties or any component of the company's operations.
  • Define security measures to lower the risks identified.
  • Understand about technical and administrative controls in the different areas: networking, operations, access management, SSDLC, cloud security, end-point protection, physical security, third party risk assessment, organization security and legal compliance.
  • Coordinate the information security assessments with 3rd parties (clients, suppliers).
  • Contribute in the development of awareness material and the process of delivery and measurement.
  • Coordinate and reply to internal and external audits related to information security.
  • Investigate on technologies that could improve the security baseline and the compliance (e.g. DLP, end-point protection, network security, security and vulnerabilities assessment).
  • Empower, assist, and mentor fellow members of the team to foster their professional growth and ensure collective success.
About You
The essentials:
  • Bachelor's degree in Computer Science, Computer or Systems Engineering or equivalent.
  • Minimum of 5 years of experience in InfoSec related positions.
  • Solid knowledge of security on networking, cloud, infrastructure configuration, end-point protection and SDLC.
  • Knowledge of the standards ISO 27001/2, SOC2, NIST-800.
  • Professional working proficiency in written and spoken English
  • Ability to confidently present findings to those with either a technical or non-technical background.
  • Self-directed, resourceful, and a critical thinker with attention-to-detail and proactive problem-solving skills.
  • Ability to self-organize and plan activities with commitment towards results.
  • Ready to learn new contents both from others or self-learned.
  • Looking forward to self-improvement and suggesting improvements to processes or activities.
Not a must, but a plus:
  • +4 year of dedicated experience in any of the following areas:
  • Security Risk Management
  • Security Consultant
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Compliance Analyst
Information Security Compliance Analyst

Monks • Kuala Lumpur

On-site
MYR 120,000 - 180,000
ISMS & Compliance Lead — InfoSec (APAC)
ISMS & Compliance Lead — InfoSec (APAC)

Firewood Marketing, Inc. • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Information Security Analyst
Information Security Analyst

Media.Monks • Kuala Lumpur

On-site
MYR 90,000 - 150,000
Information Security Manager
Information Security Manager

FIRMUS • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Information Technology Security Analyst
Information Technology Security Analyst

Lotus's Malaysia • Kuala Lumpur

On-site
MYR 90,000 - 150,000
Information Security Manager
Information Security Manager

EPOS • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Security Engineer
Security Engineer

Mission Consultancy Services • Kuala Lumpur

On-site
MYR 80,000 - 120,000
Compliance & MIS Manager
Compliance & MIS Manager

CloudMile • Kuala Lumpur

On-site
MYR 60,000 - 90,000
Senior SOC Consultant
Senior SOC Consultant

S-RM • Kuala Lumpur

Hybrid
MYR 180,000 - 240,000
Hybrid work model
Global collaboration
Senior Cyber Security Consultant (SOC) Cyber security Kuala Lumpur
Senior Cyber Security Consultant (SOC) Cyber security Kuala Lumpur

S-RM Intelligence and Risk Consulting • Kuala Lumpur

Hybrid
MYR 120,000 - 180,000