IT Governance, Risk & Compliance Analyst

Petron Malaysia Refining & Marketing Bhd

Kuala Lumpur

On-site

MYR 120,000 - 180,000

Full time

12 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Petron Malaysia Refining & Marketing Bhd is seeking an information security professional to develop, implement, and manage the organization's GRC programs. You will align controls with NIST CSF, PCI DSS, BNM RMiT, and ISO/IEC 27001, leading policies and audits across the business.

The role requires 3–5 years in a similar capacity, strong communication, and risk management skills. You will work with a cross‑functional team to protect information assets and support regulatory compliance in a

Qualifications

  • Bachelor’s Degree in Computing/Information Technology/Computer Security required.
  • 3-5 years’ experience in a similar role.
  • Certified ISO27001:2013/2022.
  • Knowledge of ISMS framework, compliance and risk assessment.
  • Knowledge of IT security technologies and controls.
  • Familiar with NIST, ISO 27001, PCI DSS.
  • Experience in developing or implementing IT policies, standards, and procedures.
  • Experience in identification, evaluation, management, and monitoring of risk.
  • Experience in project coordination for IT projects.
  • Ability to conduct investigations on security incidents and document findings.

Responsibilities

  • Lead and improve information security control policies and guidelines.
  • Review information security control policies and procedures regularly.
  • Publish IT security bulletins on cybersecurity topics.
  • Provide training on governance, compliance, risk management and security matters.
  • Develop and implement security policies for all entities and users.
  • Maintain risk register in GRC platform.
  • Maintain change management processes and guidelines.
  • Lead internal and external audits and compliance reviews.
  • Oversee lifecycle of technology changes and third‑party security assessments.
  • Evaluate third‑party risks and assist with budget planning and expenditure compliance.

Skills

Communication skills
Time management
Investigative skills
Policy implementation
Audit coordination
Budget awareness

Education

Bachelor’s Degree in Computing/Information Technology/Computer Security

Job description

\"At Petron, we are not just in the business of oil, we are also in the business of fueling lives.\"


Petron Malaysia is an emerging and rapidly evolving Asian oil company. It is part of Petron Corporation which is the leading oil company in the Philippines. Our integrated refining, distribution, and retailing of world-class petroleum products help meet the country’s growing energy needs and contributes to a more progressive nation. We are dedicated and passionate about our vision - to be the leading provider of total customer solutions in the oil sector and its allied businesses.


Job Overview

Responsible for developing, implementing, and managing the organization's Information Security Governance, Risk Management, and Compliance (GRC) programs. Ensure that information security controls, processes, and solutions are clearly defined and effectively implemented, aligning with current business needs and relevant regulatory standards, including NIST CSF, PCI DSS, BNM RMiT, and ISO/IEC 27001 Standards.


Responsibilities


  • Lead and continuously improve information security control policies, procedures, and guidelines in line with regulatory, ISMS requirements, and industry best practices

  • Facilitate periodic reviews of information security control policies, procedures, and guidelines

  • Promote awareness and publish IT security bulletins on cybersecurity topics

  • Provide and facilitate training on governance, compliance, risk management, and security-related matters

  • Develop and implement security policies, procedures, and guidelines for all business entities and users

  • Regularly update and maintain the risk register within the GRC platform

  • Develop and maintain change management processes, procedures, and guidelines

  • Lead and manage internal and external audits, and compliance reviews related to information security

  • Oversee the lifecycle of all technology changes and manage third-party security assessments

  • Evaluate and manage third-party risks, generate compliance reports, and assist with budget planning and expenditure compliance


Qualifications


  • Bachelor’s Degree in Computing/Information Technology/Computer Security

  • Minimum 3-5 years’ experience in similar role

  • Certified ISO27001:2013/2022

  • Knowledge in Information Security Management System (ISMS) framework, Compliance and Risk Assessment

  • Knowledge of IT security technologies and controls

  • Familiar with NIST, IS0 27001, PCI DSS

  • Experience in developing or implementing IT policies, standards, and procedures

  • Experience in identification, evaluation, management, and monitoring of risk

  • Experience in project coordination for IT projects

  • Ability to carry out investigations on security incidences as well as document findings; hence it is essential that they can define problems, collect data, establish facts, and draw valid conclusions.

  • Strong written and verbal communication skills

  • Good time management


Thank you for your application! We’re delighted by your interest in joining Petron Malaysia and are truly excited about your enthusiasm for the position!


Please note that due to the volume of applications, only shortlisted candidates will be contacted.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Governance, Risk & Compliance Analyst
IT Governance, Risk & Compliance Analyst

Petron group • Kuala Lumpur

On-site
MYR 75,000 - 120,000
Security GRC Analyst: Lead IT Compliance & Risk
Security GRC Analyst: Lead IT Compliance & Risk

Petron Malaysia Refining & Marketing Bhd • Kuala Lumpur

On-site
MYR 120,000 - 180,000
GRC & InfoSec Analyst: Risk, Compliance & Policy
GRC & InfoSec Analyst: Risk, Compliance & Policy

Petron group • Kuala Lumpur

On-site
MYR 75,000 - 120,000
DCS & Process Control Engineer – Refinery IT/OT
DCS & Process Control Engineer – Refinery IT/OT

Petron Malaysia Refining & Marketing Bhd • Port Dickson

On-site
MYR 80,000 - 100,000
Organizational Management & Compensation Specialist
Organizational Management & Compensation Specialist

Petron group • Kuala Lumpur

On-site
MYR 80,000 - 100,000
Head of Information Technology
Head of Information Technology

Talenta Consultants • Kuala Lumpur

On-site
MYR 240,000 - 420,000
Operations Coordinator (Contract)
Operations Coordinator (Contract)

Petron Malaysia Refining & Marketing Bhd • Kuala Lumpur

On-site
MYR 60,000 - 90,000
Facilities Operations Lead: Maintenance, Safety & SAP
Facilities Operations Lead: Maintenance, Safety & SAP

Petron Malaysia Refining & Marketing Bhd • Port Dickson

On-site
MYR 120,000 - 180,000
Tax Analyst
Tax Analyst

Petron Malaysia Refining & Marketing Bhd • Kuala Lumpur

On-site
MYR 90,000 - 120,000
Facilities Lead (Contract)
Facilities Lead (Contract)

Petron Malaysia • Port Dickson

On-site
MYR 90,000 - 130,000