IT Governance Analyst

Fusang

Kuala Lumpur

On-site

MYR 120,000 - 180,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Fusang, Asia’s first fully regulated digital securities exchange, seeks an IT Governance Analyst to own IT governance, compliance, and internal audits in Kuala Lumpur. You will maintain policy frameworks, monitor adherence, and respond to regulator inquiries, inspecting live configurations across cloud and SaaS to ensure regulatory readiness and robust controls.

This technical, non-cybersecurity-engineering role offers exposure to high‑impact audits and hands-on policy development with

Qualifications

  • Bachelor's degree in Information Technology, Computer Science, Business, or a related field.
  • Minimum 5 years of experience in IT governance, GRC, IT compliance, or technology risk roles.
  • Experience with AWS, Cloudflare, GPO and Active Directory settings and logs.
  • Hands-on experience with ISO 27001, SOC 2, MAS TRM, or equivalent.
  • Experience responding to regulatory inquiries or client security questionnaires and DDQs.
  • Demonstrated ability to manage a policy lifecycle—drafting, reviewing, approving, and enforcing IT policies.
  • Experience maintaining certificate inventories, software licence registers, or similar asset tracking.
  • Strong documentation skills — you write policies, procedures, and audit evidence packs.
  • Good English communication skills — written and verbal, including executive-level reporting.
  • AI-Assisted Productivity: Comfort using AI-assisted tools to improve documentation.

Responsibilities

  • Independent System Inspection: review live configurations and logs across systems.
  • Source-of-Truth Verification: validate controls beyond screenshots or attestations.
  • Internal Compliance Auditing: test live system parameters against requirements.
  • Control Drift & Gap Detection: spot-check access privileges and settings for deviations.
  • Audit Evidence Management: gather and maintain verifiable logs for audits.
  • Maintain IT policy library and SOPs for key IT processes.
  • Policy reviews against regulatory requirements and industry frameworks.
  • Respond to regulatory inquiries and client security questionnaires.
  • Track renewal dates and asset lifecycle (certificates, licenses, SaaS).
  • Coordinate with Legal, Finance, and Operations on regulatory obligations.

Skills

IT governance
GRC
Policy lifecycle
Audit evidence
Executive reporting

Education

Bachelor's degree in Information Technology, Computer Science, Business, or a related field

Tools

AWS
Cloudflare
Active Directory
GPO

Job description

About Fusang

Fusang is Asia’s first fully-regulated digital securities exchange, pioneering the convergence of traditional finance and blockchain technology.

Licensed by the Labuan Financial Services Authority, we created the world’s first institutional tokenised sukuk—recognised with the IFN Most Innovative Deal 2023 award. With over USD 410 million in tokenised instruments issued, we’re proving that regulated digital securities are the future of capital markets.

Our mission is to build the digital superhighway for traditional finance, making investment opportunities more accessible globally. Backed by 40 years of wealth management expertise through our relationship with Portcullis Group, we combine startup innovation with institutional credibility.

We’re looking for exceptional people who want to shape the future of finance.

Role Overview:

As a licensed digital securities exchange, Fusang operates under the scrutiny of regulators, institutional clients, and external auditors. Our clients run rigorous due diligence processes. Our regulators expect documented, enforceable policies. Our infrastructure must remain continuously monitored to prevent lapses in certificates, domain registrations, and compliance obligations.

We are seeking an IT Governance Analyst to own the operational backbone of our IT governance, compliance, and internal technical audit function. You will maintain the IT policy framework, monitor adherence to processes, respond to regulatory and client security inquiries, and ensure that nothing—a certificate expiry, a policy gap, or an unanswered audit request—falls through the cracks.

While this is not a cybersecurity engineering role, it requires strong technical acumen to act as an effective internal technical auditor. Rather than relying on self-reported evidence or screenshots provided by engineers, you will use your technical skills to establish the true "source of truth." You will independently log into various environments—including cloud systems, Web Application Firewalls (WAF), cybersecurity tools, corporate IT platforms, and SaaS applications to directly inspect live configurations, audit permissions, and review logs to ensure absolute compliance and regulatory readiness.

Key Responsibilities:
Technical Audit & Source-of-Truth Inspection
  • Independent System Inspection: Directly log into systems—including cloud environments, Web Application Firewalls (WAF), cybersecurity tools, corporate IT infrastructure, and SaaS platforms to review live configurations and system logs independently.
  • Source-of-Truth Verification: Validate security controls and policy compliance through direct system-level inspection, moving beyond reliance on engineer-provided screenshots or self-reported attestations.
  • Internal Compliance Auditing: Function as an internal technical auditor to continuously test live system parameters and access controls against regulatory requirements, industry benchmarks, and internal policies.
  • Control Drift & Gap Detection: Spot-check access privileges, security rules, and parameter settings to proactively detect configuration drift, unapproved changes, or policy deviations.
  • Audit Evidence Management: Gather and maintain verifiable, system-generated logs and evidentiary artifacts to ensure seamless readiness for regulatory inspections and external audits.
IT Policy & Process Governance
  • Maintain and update the IT policy library (acceptable use, access control, change management, incident response, data classification, vendor management, etc.)
  • Conduct scheduled policy reviews against regulatory requirements and industry frameworks
  • Track organisation-wide policy acknowledgement and follow up on non-compliance
  • Identify process gaps through internal reviews and work with teams to close them
  • Document and maintain standard operating procedures (SOPs) for key IT processes
Regulatory & Client Compliance
  • Respond to regulatory inquiries and information requests from MAS, SFC, Labuan FSA, and equivalent bodies
  • Complete client security questionnaires, due diligence questionnaires (DDQs), and third-party risk assessments
  • Prepare and maintain evidence packs and control documentation for audits (ISO 27001, SOC 2, internal and external audits)
  • Coordinate with Legal, Finance, and Operations to ensure alignment on regulatory obligations
  • Track regulatory changes and assess impact on existing policies and controls
Certificate & Asset Lifecycle Management
  • Maintain a centralised inventory of SSL/TLS certificates, domain registrations, software licences, and SaaS subscriptions
  • Track renewal dates and coordinate with IT, DevOps, and vendors to ensure no lapses or service disruptions
  • Document renewal processes and establish escalation procedures for time-sensitive renewals
  • Maintain an up-to-date IT asset register for hardware, software, and cloud resources
Risk & Vendor Governance
  • Maintain the IT risk register, track risks, mitigations, owners, and review cycles
  • Support third-party vendor assessments and due diligence reviews prior to onboarding
  • Monitor vendor compliance with contractual security obligations and SLAs
  • Assist in Business Continuity Planning (BCP) and Disaster Recovery (DR) documentation and testing
Security Awareness & Training
  • Coordinate IT security awareness programmes and phishing simulation exercises
  • Track completion of mandatory compliance training across the organisation
  • Maintain and update onboarding materials related to IT policies and acceptable use
Requirements:
Required
  • Bachelor's degree in Information Technology, Computer Science, Business, or a related field
  • Minimum 5 years of experience in IT governance, GRC (Governance, Risk & Compliance), IT compliance, or technology risk roles
  • Experience with AWS, Cloudflare, GPO and Active Directory settings and logs.
  • Hands-on experience with at least one compliance framework: ISO 27001, SOC 2, MAS TRM, or equivalent
  • Experience responding to regulatory inquiries or client security questionnaires and DDQs
  • Demonstrated ability to manage a policy lifecycle — drafting, reviewing, approving, and enforcing IT policies
  • Experience maintaining certificate inventories, software licence registers, or similar asset tracking
  • Strong documentation skills — you write policies, procedures, and audit evidence packs that hold up under scrutiny
  • Good English communication skills — written and verbal, including executive-level reporting
  • AI-Assisted Productivity: Comfort using AI-assisted tools such as Claude Code or similar to improve documentation efficiency and workflow automation
Preferred
  • Professional certification: CISA, CRISC, ISO 27001 Lead Implementer/Auditor, or CompTIA Security+
  • Experience in financial services, fintech, or a regulated industry (MAS, SFC, Labuan FSA)
  • Exposure to corporate secretary, trust administration, fund administration, and digital assets.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Corporate IT Associate
Corporate IT Associate

Fusang • Kuala Lumpur

On-site
MYR 48,000 - 72,000
Cybersecurity Engineer
Cybersecurity Engineer

Fusang • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Senior IT Governance & Compliance Architect
Senior IT Governance & Compliance Architect

Fusang • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Security Governance Assistant Manager
Security Governance Assistant Manager

Boost Holdings Sdn Bhd • Kuala Lumpur

On-site
MYR 150,000 - 210,000
Lead IT Security Policy | Up to RM14K
Lead IT Security Policy | Up to RM14K

Randstad Malaysia • Kuala Lumpur

On-site
MYR 180,000 - 240,000
IT Security Governance
IT Security Governance

GoKardz Technologies • Kuala Lumpur

On-site
MYR 90,000 - 120,000
IT Security Governance Manager
IT Security Governance Manager

HLB • Petaling Jaya

On-site
MYR 180,000 - 300,000
Senior Executive, IT Compliance & Monitoring
Senior Executive, IT Compliance & Monitoring

Takaful Malaysia • Kuala Lumpur

On-site
MYR 60,000 - 100,000
Senior Executive, IT Governance
Senior Executive, IT Governance

Takaful Malaysia • Kuala Lumpur

On-site
MYR 60,000 - 90,000
Senior Executive, IT Governance, Risk and Compliance
Senior Executive, IT Governance, Risk and Compliance

Revenue Group Berhad • Petaling Jaya

On-site
MYR 72,000 - 120,000