IT Governance, Risk & Compliance Analyst

Petron group

Kuala Lumpur

On-site

MYR 75,000 - 120,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Petron group is seeking a responsible individual for developing, implementing, and managing their Information Security Governance and Compliance programs in Kuala Lumpur, Malaysia. This role encompasses leading security policies, facilitating audits, and promoting cybersecurity awareness.

The ideal candidate will possess a Bachelor's degree in IT or related fields with 3-5 years of experience and relevant certifications such as ISO27001. Strong communication skills and knowledge of ISMS frameworks are essential.

Qualifications

  • Minimum 3-5 years’ experience in a similar role.
  • Certified ISO27001:2013/2022.
  • Familiar with NIST, ISO 27001, PCI DSS.
  • Experience in developing or implementing IT policies, standards, and procedures.

Responsibilities

  • Lead and improve information security control policies and procedures.
  • Facilitate reviews of security control policies.
  • Provide training on governance and compliance.
  • Manage internal and external audits related to information security.

Skills

Information Security Management System (ISMS)
Compliance and Risk Assessment
IT security technologies and controls
Strong written and verbal communication skills
Good time management

Education

Bachelor’s Degree in Computing/Information Technology/Computer Security

Job description

Overview

Job Overview: Responsible for developing, implementing, and managing the organization's Information Security Governance, Risk Management, and Compliance (GRC) programs. Ensure that information security controls, processes, and solutions are clearly defined and effectively implemented, aligning with current business needs and relevant regulatory standards, including NIST CSF, PCI DSS, BNM RMiT, and ISO/IEC 27001 Standards.

Responsibilities
  • Lead and continuously improve information security control policies, procedures, and guidelines in line with regulatory, ISMS requirements, and industry best practices.
  • Facilitate periodic reviews of information security control policies, procedures, and guidelines.
  • Promote awareness and publish IT security bulletins on cybersecurity topics.
  • Provide and facilitate training on governance, compliance, risk management, and security-related matters.
  • Develop and implement security policies, procedures, and guidelines for all business entities and users.
  • Regularly update and maintain the risk register within the GRC platform.
  • Develop and maintain change management processes, procedures, and guidelines.
  • Lead and manage internal and external audits, and compliance reviews related to information security.
  • Oversee the lifecycle of all technology changes and manage third-party security assessments.
  • Evaluate and manage third-party risks, generate compliance reports, and assist with budget planning and expenditure compliance.
Qualifications
  • Bachelor’s Degree in Computing/Information Technology/Computer Security.
  • Minimum 3-5 years’ experience in similar role.
  • Certified ISO27001:2013/2022.
  • Knowledge in Information Security Management System (ISMS) framework, Compliance and Risk Assessment.
  • Knowledge of IT security technologies and controls.
  • Familiar with NIST, ISO 27001, PCI DSS.
  • Experience in developing or implementing IT policies, standards, and procedures.
  • Experience in identification, evaluation, management, and monitoring of risk.
  • Experience in project coordination for IT projects.
  • Ability to carry out investigations on security incidences as well as document findings; it is essential to define problems, collect data, establish facts, and draw valid conclusions.
  • Strong written and verbal communication skills.
  • Good time management.

Thank you for your application. We’re delighted by your interest in joining Petron Malaysia and are truly excited about your enthusiasm for the position. Please note that due to the volume of applications, only shortlisted candidates will be contacted.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Governance, Risk & Compliance Analyst
IT Governance, Risk & Compliance Analyst

Petron Malaysia Refining & Marketing Bhd • Kuala Lumpur

On-site
MYR 120,000 - 180,000
GRC & InfoSec Analyst: Risk, Compliance & Policy
GRC & InfoSec Analyst: Risk, Compliance & Policy

Petron group • Kuala Lumpur

On-site
MYR 75,000 - 120,000
Security GRC Analyst: Lead IT Compliance & Risk
Security GRC Analyst: Lead IT Compliance & Risk

Petron Malaysia Refining & Marketing Bhd • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Senior Consultant - Tech Risk, Cyber & Privacy Advisory
Senior Consultant - Tech Risk, Cyber & Privacy Advisory

EC-Council Global Services • Kuala Lumpur

On-site
MYR 150,000 - 210,000
Senior Executive, Cybersecurity & IT Governance
Senior Executive, Cybersecurity & IT Governance

Asia Recruit (Permanent, Contract, & Executive Recruitment) • Shah Alam

On-site
MYR 80,000 - 120,000
Manager – ICT Governance & Compliance
Manager – ICT Governance & Compliance

Scicom MSC Berhad • Kampung Cendana

On-site
MYR 71,000 - 85,000
Salary up to RM7000
Medical insurance
Medical and hospitalization leaves
+1
Cybersecurity GRC Analyst
Cybersecurity GRC Analyst

Srpailabs.com • Kuala Lumpur

On-site
MYR 120,000 - 180,000
IT Governance, Risk & Compliance Manager
IT Governance, Risk & Compliance Manager

CapBay • Kuala Lumpur

Hybrid
MYR 90,000 - 150,000
Senior Executive, IT Governance, Risk and Compliance
Senior Executive, IT Governance, Risk and Compliance

Revenue Group • Selangor

On-site
MYR 90,000 - 130,000
IT Information Security Management (ISM) / CyberSecurity Officer
IT Information Security Management (ISM) / CyberSecurity Officer

Nationgate Solution (M) Sdn Bhd • Seberang Perai

On-site
MYR 90,000 - 150,000