Manager – IT (Cybersecurity Risk & Policy)

Mindteck, Inc.

Sepang

On-site

MYR 180,000 - 280,000

Full time

6 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Mindteck, Inc. in Malaysia seeks an experienced senior professional to establish and maintain cybersecurity governance, risk management, and compliance across IT and OT environments.

You will lead enterprise-wide risk activities, develop policies, and coordinate audits and remediation with stakeholders. The role requires 7–10 years in cybersecurity governance, strong knowledge of ISO 27001, NIST CSF, and regulatory requirements, plus hands-on experience with RSA Archer, ServiceNow GRC, or

Qualifications

  • Bachelor’s degree in Cybersecurity, Information Security, IT, CS, or related discipline.
  • 7–10 years of experience in cybersecurity governance, risk management, compliance, information security, or related areas.
  • Strong knowledge of ISO 27001, NIST CSF, security controls, and regulatory requirements.
  • Experience with risk assessments, gap analyses, control reviews, and compliance evaluations.
  • Experience managing cybersecurity risks across enterprise IT and OT environments.
  • Hands-on experience with GRC platforms such as RSA Archer, ServiceNow GRC, and MetricStream.

Responsibilities

  • Lead enterprise-wide cybersecurity risk identification, assessment, mitigation, treatment, and monitoring activities.
  • Develop, implement, review, and maintain cybersecurity policies, standards, procedures, and guidelines.
  • Establish and maintain cybersecurity governance processes aligned with business and technology objectives.
  • Ensure alignment with ISO 27001, NIST CSF, GDPR, and applicable industry regulations.
  • Conduct risk assessments, gap analyses, control assessments, and compliance reviews across IT and OT environments.
  • Lead third-party and vendor cybersecurity risk management programs.

Skills

Cybersecurity governance
Risk management
Regulatory compliance
NIST CSF
ISO 27001
GRC methodologies

Education

Bachelor's degree in Cybersecurity or related field

Tools

RSA Archer
ServiceNow GRC
MetricStream

Job description

Find work that actually fits - with teams building things that matter

The role will be responsible for establishing and maintaining cybersecurity policies and standards, leading enterprise-wide risk management activities, ensuring compliance with international frameworks and regulatory requirements, and strengthening cybersecurity governance across IT and Operational Technology (OT) environments.

The successful candidate will work closely with business, IT, cybersecurity, risk, audit, and operational stakeholders to identify and manage cybersecurity risks and drive continuous improvements in the organization's security posture.

Key Responsibilities

Lead enterprise-wide cybersecurity risk identification, assessment, mitigation, treatment, and monitoring activities.

Develop, implement, review, and maintain cybersecurity policies, standards, procedures, and guidelines.

Establish and maintain cybersecurity governance processes aligned with business and technology objectives.

Ensure alignment with recognized frameworks and regulatory requirements, including ISO 27001, NIST, GDPR, and applicable industry regulations.

Conduct cybersecurity risk assessments, gap analyses, control assessments, and compliance reviews across IT and OT environments.

Identify control gaps and develop risk treatment and remediation plans in collaboration with relevant stakeholders.

Lead and manage the organization's third-party and vendor cybersecurity risk management program.

Assess security risks associated with suppliers, service providers, technology partners, and other third parties.

Coordinate internal and external cybersecurity audits, regulatory assessments, and compliance reviews.

Track audit findings, control deficiencies, and remediation activities through to closure.

Provide executive-level reporting on cybersecurity risk posture, compliance status, key risks, policy adherence, and remediation progress.

Develop and maintain cybersecurity risk registers, dashboards, KPIs, and KRIs.

Lead cybersecurity policy awareness and security awareness/training initiatives across the organization.

Administer and continuously improve GRC platforms, including Archer, ServiceNow GRC, or equivalent solutions.

Monitor emerging cybersecurity threats, regulatory developments, vulnerabilities, and industry best practices and assess their potential impact.

Provide guidance to business and technology teams on cybersecurity risk, governance, policies, controls, and compliance requirements.

Drive continuous improvement of the organization's cybersecurity governance and risk management framework.

Required Qualifications & Experience

Bachelor’s Degree in Cybersecurity, Information Security, Information Technology, Computer Science, or a related discipline.

7–10 years of experience in cybersecurity governance, risk management, compliance, information security, or related areas.

Strong knowledge and practical experience with:

ISO 27001

NIST Cybersecurity Framework

Cybersecurity risk management methodologies

Security controls and compliance frameworks

Regulatory and industry requirements

Proven experience conducting risk assessments, gap analyses, control reviews, and compliance evaluations.

Experience managing cybersecurity risks across enterprise IT and/or OT environments.

Hands-on experience with GRC platforms such as:

RSA Archer

ServiceNow GRC

MetricStream or equivalent platforms

Strong experience managing third-party/vendor cybersecurity risk.

Experience coordinating internal and external security audits and remediation programs.

Strong analytical, communication, presentation, and stakeholder management skills.

Preferred Certifications

Relevant certifications such as:

CISSP – Certified Information Systems Security Professional

CISM – Certified Information Security Manager

CISA – Certified Information Systems Auditor

CRISC – Certified in Risk and Information Systems Control

Other recognized cybersecurity GRC certifications

  • Job Location Sepang, Malaysia
  • Job Type: Contract
  • Experience 7 Years
  • Education Bachelor’s Degree in Cybersecurity, Information Security, Information Technology, Computer Science, or a related discipline.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Manager – IT (Security Operations Centre & Incident Response)
Manager – IT (Security Operations Centre & Incident Response)

Mindteck, Inc. • Sepang

On-site
MYR 180,000 - 240,000
Manager – IT (Cybersecurity Strategy & Architecture)
Manager – IT (Cybersecurity Strategy & Architecture)

Mindteck, Inc. • Sepang

On-site
MYR 167,000 - 312,000
Senior IT GRC & Cyber Policy Leader
Senior IT GRC & Cyber Policy Leader

Mindteck, Inc. • Sepang

On-site
MYR 120,000 - 180,000
Assistant Manager, Cybersecurity Architecture & Governance
Assistant Manager, Cybersecurity Architecture & Governance

SD Guthrie International • Petaling Jaya

On-site
MYR 100,000 - 140,000
Manager IT (Cybersecurity Risk & Policy)
Manager IT (Cybersecurity Risk & Policy)

MINDTECK SOFTWARE MALAYSIA SDN BHD • Sepang

On-site
MYR 180,000 - 340,000
Security Engineer
Security Engineer

Agensi Pekerjaan Penta Consultancy Sdn. Bhd • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Manager – ICT Governance & Compliance
Manager – ICT Governance & Compliance

Scicom MSC Berhad • Kampung Cendana

On-site
MYR 71,000 - 85,000
Salary up to RM7000
Medical insurance
Medical and hospitalization leaves
+1
Senior Consultant - Tech Risk, Cyber & Privacy Advisory
Senior Consultant - Tech Risk, Cyber & Privacy Advisory

EC-Council Global Services • Kuala Lumpur

On-site
MYR 150,000 - 210,000
6412 - IT Security Manager
6412 - IT Security Manager

Agensi Pekerjaan Minde Group Sdn Bhd • Penang

On-site
MYR 180,000 - 270,000
IT Governance, Risk & Compliance Analyst
IT Governance, Risk & Compliance Analyst

Petron group • Kuala Lumpur

On-site
MYR 75,000 - 120,000