Enable job alerts via email!

IT Governance, Risk & Compliance Analyst

Petron Malaysia Refining & Marketing Bhd

Kuala Lumpur

On-site

MYR 40,000 - 80,000

Full time

Yesterday
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a dedicated Information Security Manager to oversee the governance, risk management, and compliance programs. This role involves leading the development of security policies, facilitating audits, and ensuring compliance with regulatory standards. The ideal candidate will have a strong background in information security, risk management, and a solid understanding of IT security technologies. Join a dynamic team focused on safeguarding information assets while promoting a culture of security awareness across the organization. If you are passionate about information security and ready to take on new challenges, this opportunity is perfect for you.

Qualifications

  • 3-5 years of experience in information security roles.
  • Proven ability in risk management and monitoring.

Responsibilities

  • Lead and improve information security control policies and guidelines.
  • Manage change management processes and guidelines.
  • Oversee internal and external security audits.

Skills

Risk Management
Information Security Governance
Compliance
Communication Skills
Time Management

Education

Bachelor’s Degree in Computing
Diploma in Information Technology
ISO27001:2013/2022 Certification

Tools

GRC Platform
ISMS Framework

Job description

Job Overview

Responsible for developing, implementing, and managing the organization's Information Security Governance, Risk Management, and Compliance (GRC) programs. Ensure that information security controls, processes, and solutions are clearly defined and effectively implemented, aligning with current business needs and relevant regulatory standards, including NIST CSF, PCI DSS, BNM RMiT, and ISO/IEC 27001 Standards.

Responsibilities
  1. Lead and improve information security control policies, procedures, and guidelines in line with regulatory, ISMS requirements, and industry best practices
  2. Facilitate periodic reviews of security policies and procedures
  3. Promote awareness through IT security bulletins on cybersecurity topics
  4. Provide training on governance, compliance, risk management, and security matters
  5. Develop and implement security policies for all business units
  6. Maintain the risk register within the GRC platform
  7. Manage change management processes and guidelines
  8. Lead internal and external security audits and compliance reviews
  9. Oversee technology change lifecycle and third-party security assessments
  10. Evaluate third-party risks, generate compliance reports, and support budget planning
Qualifications
  1. Bachelor’s Degree or Diploma in Computing, Information Technology, or Computer Security
  2. 3-5 years of experience in a similar role
  3. ISO27001:2013/2022 certification
  4. Knowledge of ISMS framework, compliance, and risk assessment
  5. Understanding of IT security technologies and controls
  6. Familiarity with NIST, ISO 27001, PCI DSS standards
  7. Experience in developing IT policies and procedures
  8. Proven ability in risk management and monitoring
  9. Experience with IT project coordination
  10. Ability to investigate security incidents and document findings
  11. Strong communication skills
  12. Effective time management skills

Thank you for your interest in joining Petron Malaysia. We look forward to your application. Please note that only shortlisted candidates will be contacted.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.