Stand out for this role — generate a tailored resume and cover letter in about a minute.
Mindteck, Inc. in Malaysia seeks an experienced senior professional to establish and maintain cybersecurity governance, risk management, and compliance across IT and OT environments.
You will lead enterprise-wide risk activities, develop policies, and coordinate audits and remediation with stakeholders. The role requires 7–10 years in cybersecurity governance, strong knowledge of ISO 27001, NIST CSF, and regulatory requirements, plus hands-on experience with RSA Archer, ServiceNow GRC, or
Find work that actually fits - with teams building things that matter
The role will be responsible for establishing and maintaining cybersecurity policies and standards, leading enterprise-wide risk management activities, ensuring compliance with international frameworks and regulatory requirements, and strengthening cybersecurity governance across IT and Operational Technology (OT) environments.
The successful candidate will work closely with business, IT, cybersecurity, risk, audit, and operational stakeholders to identify and manage cybersecurity risks and drive continuous improvements in the organization's security posture.
Lead enterprise-wide cybersecurity risk identification, assessment, mitigation, treatment, and monitoring activities.
Develop, implement, review, and maintain cybersecurity policies, standards, procedures, and guidelines.
Establish and maintain cybersecurity governance processes aligned with business and technology objectives.
Ensure alignment with recognized frameworks and regulatory requirements, including ISO 27001, NIST, GDPR, and applicable industry regulations.
Conduct cybersecurity risk assessments, gap analyses, control assessments, and compliance reviews across IT and OT environments.
Identify control gaps and develop risk treatment and remediation plans in collaboration with relevant stakeholders.
Lead and manage the organization's third-party and vendor cybersecurity risk management program.
Assess security risks associated with suppliers, service providers, technology partners, and other third parties.
Coordinate internal and external cybersecurity audits, regulatory assessments, and compliance reviews.
Track audit findings, control deficiencies, and remediation activities through to closure.
Provide executive-level reporting on cybersecurity risk posture, compliance status, key risks, policy adherence, and remediation progress.
Develop and maintain cybersecurity risk registers, dashboards, KPIs, and KRIs.
Lead cybersecurity policy awareness and security awareness/training initiatives across the organization.
Administer and continuously improve GRC platforms, including Archer, ServiceNow GRC, or equivalent solutions.
Monitor emerging cybersecurity threats, regulatory developments, vulnerabilities, and industry best practices and assess their potential impact.
Provide guidance to business and technology teams on cybersecurity risk, governance, policies, controls, and compliance requirements.
Drive continuous improvement of the organization's cybersecurity governance and risk management framework.
Bachelor’s Degree in Cybersecurity, Information Security, Information Technology, Computer Science, or a related discipline.
7–10 years of experience in cybersecurity governance, risk management, compliance, information security, or related areas.
Strong knowledge and practical experience with:
ISO 27001
NIST Cybersecurity Framework
Cybersecurity risk management methodologies
Security controls and compliance frameworks
Regulatory and industry requirements
Proven experience conducting risk assessments, gap analyses, control reviews, and compliance evaluations.
Experience managing cybersecurity risks across enterprise IT and/or OT environments.
Hands-on experience with GRC platforms such as:
RSA Archer
ServiceNow GRC
MetricStream or equivalent platforms
Strong experience managing third-party/vendor cybersecurity risk.
Experience coordinating internal and external security audits and remediation programs.
Strong analytical, communication, presentation, and stakeholder management skills.
Relevant certifications such as:
CISSP – Certified Information Systems Security Professional
CISM – Certified Information Security Manager
CISA – Certified Information Systems Auditor
CRISC – Certified in Risk and Information Systems Control
Other recognized cybersecurity GRC certifications