Enable job alerts via email!

IT Security Governance and Risk Management Analyst

gradmalaysia.com

Kuala Lumpur

On-site

MYR 80,000 - 110,000

Full time

Yesterday
Be an early applicant

Job summary

A leading cybersecurity firm based in Kuala Lumpur is seeking an IT Security Governance and Risk Management Analyst to support cybersecurity governance and compliance efforts. You will provide advisory services, assess security risks, and contribute to IT security governance frameworks. The ideal candidate has a degree in IT or Cybersecurity and significant experience in security risk management. Professional certifications such as CISM or CISSP are highly desirable.

Qualifications

  • 4 – 7 years of experience in IT security, risk management, or cybersecurity advisory roles.
  • Strong understanding of information security principles and risk assessment methodologies.
  • Experience with regulatory frameworks (e.g., ISO 27001, NIST, CIS).

Responsibilities

  • Provide IT security advisory for business initiatives and systems implementations.
  • Review and assess IT change requests and vendor solutions.
  • Support execution of cybersecurity simulation exercises.
  • Monitor the implementation of risk mitigation plans.

Skills

Analytical thinking
Stakeholder engagement
Communication

Education

Bachelor's Degree in Computer Science/Information Technology/Cybersecurity
Job description
IT Security Governance and Risk Management Analyst

Job Summary

  • This position will be reporting to the Head of Security Governance & Risk Management Section and will function under the Advisory & Governance Unit.
  • Support and strengthen cybersecurity governance through comprehensive risk assessments, in-depth advisory services, and proactive engagement with key stakeholders to ensure compliance with internal policies and regulatory standards.

Job Responsibilities

  • Provide IT security advisory for business initiatives, systems implementations, and operational processes to ensure alignment with security policies and risk appetite.
  • Review and assess IT change requests, vendor solutions, technology initiatives and third-party controls for security risks and recommend mitigation strategies.
  • Support the execution, and analyse cybersecurity simulation exercises (e.g., phishing, smishing) to test and enhance organizational readiness.
  • Monitor the implementation of risk mitigation plans and follow up with relevant departments to ensure timely closure of issues.
  • Participate in governance forums on matters relating to IT risk and security governance.
  • Prepare reports, presentations, and dashboards on cybersecurity risk posture, incidents, and remediation progress for internal stakeholders and management.
  • Contribute to the development and refinement of IT security governance frameworks, policies, and procedures.
  • Ensure security assessment exercise is conducted and remediated in a timely manner.

Job Requirements

  • Possess a Bachelor's Degree in Computer Science/ Information Technology, Cybersecurity or equivalent qualification from accredited higher learning institutions.
  • Minimum 4 – 7 years of experience in IT security, risk management, or cybersecurity advisory roles.
  • Strong understanding of information security principles, risk assessment methodologies, and regulatory frameworks (e.g., ISO 27001, NIST, CIS).
  • Excellent analytical thinking, communication, and stakeholder engagement skills.
  • Experience coordinating with cross-functional teams on security governance and compliance efforts.
  • Professional certifications such as CISM, CISSP, CRISC, or equivalent are highly desirable.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.