Enable job alerts via email!

IT Security Governance and Risk Management Senior Analyst

EPF Malaysia

Petaling Jaya

On-site

MYR 80,000 - 120,000

Full time

3 days ago
Be an early applicant

Job summary

A government agency in Malaysia is seeking a professional for a Security Governance role to enhance cybersecurity governance through risk assessments and advisory services. Candidates must have a Bachelor's degree in relevant fields and 6–9 years of experience in IT security or risk management. The position demands strong analytical skills and professional certifications like CISM or CISSP are advantageous.

Qualifications

  • Minimum 6–9 years of experience in IT security, risk management, or cybersecurity advisory roles.
  • Strong understanding of information security principles and risk assessment methodologies.
  • Professional certifications like CISM, CISSP, or CRISC are desirable.

Responsibilities

  • Provide expert-level IT security advisory for business initiatives.
  • Review and assess IT change requests and vendor solutions for security risks.
  • Lead planning and execution of cybersecurity simulation exercises.
  • Monitor risk mitigation plans and ensure issue closures.

Skills

Analytical thinking
Communication skills
Stakeholder engagement

Education

Bachelor's Degree in Computer Science/IT/Cybersecurity

Tools

ISO 27001
NIST
CIS
Job description
JOB SUMMARY

This position will be reporting to the Head of Security Governance & Risk Management Section and will function under the Advisory & Governance Unit.

Support and strengthen cybersecurity governance through comprehensive risk assessments, in-depth advisory services, and proactive engagement with key stakeholders to ensure compliance with internal policies and regulatory standards.

JOB RESPONSIBILITIES
  • Provide expert-level IT security advisory for business initiatives, systems implementations, and operational processes to ensure alignment with security policies and risk appetite.
  • Review and assess IT change requests, vendor solutions, technology initiatives and third-party controls for security risks and recommend mitigation strategies.
  • Lead the planning, execution, and analyse cybersecurity simulation exercises (e.g., phishing, smishing) to test and enhance organizational readiness.
  • Monitor the implementation of risk mitigation plans and follow up with relevant departments to ensure timely closure of issues.
  • Participate in governance forums and act as a liaison to internal committees (e.g., Risk Management Department, Data Governance Office, etc) on matters relating to IT risk and security governance.
  • Prepare reports, presentations, and dashboards on cybersecurity risk posture, incidents, and remediation progress for internal stakeholders and management.
  • Contribute to the development and refinement of IT security governance frameworks, policies, and procedures.
  • Mentor and support junior analysts in risk assessment and advisory functions.
JOB REQUIREMENTS
  • Malaysian citizen.
  • Pass Malay Language including oral test at Sijil Pelajaran Malaysia (SPM) level.
  • Possess a Bachelor\'s Degree in Computer Science/ Information Technology, Cybersecurity or equivalent qualification from accredited higher learning institutions.
  • Minimum 6–9 years of experience in IT security, risk management, or cybersecurity advisory roles.
  • Strong understanding of information security principles, risk assessment methodologies, and regulatory frameworks (e.g., ISO 27001, NIST, CIS).
  • Excellent analytical thinking, communication, and stakeholder engagement skills.
  • Experience coordinating with cross-functional teams on security governance and compliance efforts.
  • Professional certifications such as CISM, CISSP, CRISC, or equivalent are highly desirable.
JOB STATUS

Permanent

All applications are strictly CONFIDENTIAL and only shortlisted candidates will be called in for interview. Applications are deemed UNSUCCESSFUL if there is no feedback from the EPF 2 MONTHS after the closing date of advertisement.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.