Security GRC Analyst: Lead IT Compliance & Risk

Petron Malaysia Refining & Marketing Bhd

Kuala Lumpur

On-site

MYR 120,000 - 180,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Petron Malaysia Refining & Marketing Bhd is seeking an information security professional to develop, implement, and manage the organization's GRC programs. You will align controls with NIST CSF, PCI DSS, BNM RMiT, and ISO/IEC 27001, leading policies and audits across the business.

The role requires 3–5 years in a similar capacity, strong communication, and risk management skills. You will work with a cross‑functional team to protect information assets and support regulatory compliance in a

Qualifications

  • Bachelor’s Degree in Computing/Information Technology/Computer Security required.
  • 3-5 years’ experience in a similar role.
  • Certified ISO27001:2013/2022.
  • Knowledge of ISMS framework, compliance and risk assessment.
  • Knowledge of IT security technologies and controls.
  • Familiar with NIST, ISO 27001, PCI DSS.
  • Experience in developing or implementing IT policies, standards, and procedures.
  • Experience in identification, evaluation, management, and monitoring of risk.
  • Experience in project coordination for IT projects.
  • Ability to conduct investigations on security incidents and document findings.

Responsibilities

  • Lead and improve information security control policies and guidelines.
  • Review information security control policies and procedures regularly.
  • Publish IT security bulletins on cybersecurity topics.
  • Provide training on governance, compliance, risk management and security matters.
  • Develop and implement security policies for all entities and users.
  • Maintain risk register in GRC platform.
  • Maintain change management processes and guidelines.
  • Lead internal and external audits and compliance reviews.
  • Oversee lifecycle of technology changes and third‑party security assessments.
  • Evaluate third‑party risks and assist with budget planning and expenditure compliance.

Skills

Communication skills
Time management
Investigative skills
Policy implementation
Audit coordination
Budget awareness

Education

Bachelor’s Degree in Computing/Information Technology/Computer Security

Job description

Petron Malaysia Refining & Marketing Bhd is seeking an information security professional to develop, implement, and manage the organization's GRC programs. You will align controls with NIST CSF, PCI DSS, BNM RMiT, and ISO/IEC 27001, leading policies and audits across the business.

The role requires 3–5 years in a similar capacity, strong communication, and risk management skills. You will work with a cross‑functional team to protect information assets and support regulatory compliance in a

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC & InfoSec Analyst: Risk, Compliance & Policy
GRC & InfoSec Analyst: Risk, Compliance & Policy

Petron group • Kuala Lumpur

On-site
MYR 75,000 - 120,000
IT Governance, Risk & Compliance Analyst
IT Governance, Risk & Compliance Analyst

Petron group • Kuala Lumpur

On-site
MYR 75,000 - 120,000
IT Governance, Risk & Compliance Analyst
IT Governance, Risk & Compliance Analyst

Petron Malaysia Refining & Marketing Bhd • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Senior InfoSec GRC Analyst: Risk, Compliance & ISO/NIST
Senior InfoSec GRC Analyst: Risk, Compliance & ISO/NIST

Sandisk • Batu Kawan

On-site
MYR 90,000 - 120,000
Senior IT GRC Lead
Senior IT GRC Lead

Revenue Group Berhad • Petaling Jaya

On-site
MYR 72,000 - 120,000
GRC & PCI DSS Compliance Engineer
GRC & PCI DSS Compliance Engineer

SNSoft Sdn Bhd • Kuala Lumpur

On-site
MYR 70,000 - 120,000
Competitive salary
Project incentive
Sports activities
+2
IT GRC Leader: Risk, Compliance & Controls
IT GRC Leader: Risk, Compliance & Controls

Michael Page • Kuala Lumpur

On-site
MYR 135,000 - 165,000
Competitive salary
Good work culture
GRC Consultant - Information Security - MY Based
GRC Consultant - Information Security - MY Based

Condition Zebra • Shah Alam

On-site
MYR 120,000 - 160,000
Competitive salary
Comprehensive benefits
Growth opportunities
+2
GRC & InfoSec Consultant - ISO27001/PDPA
GRC & InfoSec Consultant - ISO27001/PDPA

Condition Zebra • Shah Alam

On-site
MYR 120,000 - 160,000
Competitive salary
Comprehensive benefits
Growth opportunities
+2
Senior Information Security Leader: Risk & Resilience
Senior Information Security Leader: Risk & Resilience

Prudential Assurance Malaysia Berhad • Kuala Lumpur

On-site
MYR 180,000 - 320,000