Senior Consultant – Information Security Governance, Risk & Compliance (GRC)

EC-Council Group

Kuala Lumpur

On-site

MYR 180,000 - 240,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

EC-Council is the world's leading cybersecurity certification body and seeks a Senior Consultant – GRC to deliver governance, risk, compliance and advisory engagements across industries. You will manage assigned workstreams, conduct stakeholder interviews and workshops, assess controls, and develop high-quality client deliverables.

You will mentor junior consultants, support certification readiness, and help develop practical remediation roadmaps while upholding the highest standards of

Qualifications

  • Bachelor’s degree in cybersecurity, IT, or related field.
  • 4–7 years in Information Security GRC or related consulting roles.
  • Experience in client-facing engagements and producing risk-based deliverables.
  • Knowledge of ISO 27001, NIST, and other frameworks.
  • Familiarity with Malaysian regulations like BNM, MCMC is a plus.
  • Professional certifications such as CISA, CISM, or CISSP are advantageous.

Responsibilities

  • Lead GRC engagements from planning to reporting.
  • Perform governance, risk, compliance, and audit assessments.
  • Develop remediation roadmaps and management presentations.
  • Mentor junior consultants and review work.
  • Coordinate with clients and stakeholders to ensure timely delivery.

Skills

GRC consulting
Information Security
Regulatory compliance
Risk assessment
Audit

Education

Bachelor’s Degree in Cybersecurity, IT, or related field

Job description

Senior Consultant – Information Security Governance, Risk & Compliance (GRC)

5 Years

Full-Time

Job Title: Senior Consultant – Information Security Governance, Risk & Compliance (GRC)

#ECGS

EC-Council is the world's largest cyber security technical certification body. We operate in 170 countries globally and we are the owner and developer of various world-famous cyber security programs. We are proud to have trained and certified over 400,000 information security

professionals globally that have influenced the cyber security mindset of countless organizations worldwide.

We are looking for an experienced Senior Consultant – Information Security Governance, Risk & Compliance (GRC) to join our cybersecurity consulting team. The successful candidate will be responsible for delivering information security governance, risk management, compliance, audit, assurance, and advisory engagements for clients across various industries. This is a client-facing consulting role suited for someone who is comfortable independently managing assigned workstreams, conducting stakeholder interviews and workshops, assessing cybersecurity controls, reviewing evidence, identifying risks and gaps, and developing high-quality client deliverables. You will also provide guidance to junior consultants and support the successful delivery of multiple GRC engagements.

Key Responsibilities:

  • Deliver Information Security GRC consulting engagements from planning through reporting.
  • Conduct cybersecurity governance, risk, compliance, maturity, and control assessments.
  • Perform information security and cybersecurity risk assessments.
  • Conduct regulatory and standards-based gap assessments.
  • Perform cybersecurity audits, internal audits, and independent control assessments.
  • Assess the design adequacy and operating effectiveness of cybersecurity controls.
  • Conduct stakeholder interviews, walkthroughs, workshops, and evidence reviews.
  • Identify control gaps, risks, weaknesses, and areas for improvement.
  • Develop practical and risk-based recommendations for clients.
  • Prepare professional assessment reports, audit reports, risk registers, compliance reports, management presentations, and remediation roadmaps.
  • Develop and review information security policies, procedures, standards, and governance frameworks.
  • Conduct cybersecurity maturity assessments and develop improvement roadmaps.
  • Conduct third-party and supplier cybersecurity risk assessments.
  • Support certification and regulatory compliance readiness activities.
  • Track project activities, information requests, findings, risks, and deliverables.
  • Manage assigned engagement workstreams and ensure activities are completed within agreed timelines.
  • Present assessment findings and recommendations to client stakeholders and management.
  • Review work performed by Consultants and Junior Consultants.
  • Mentor and guide junior members of the GRC delivery team.
  • Maintain high standards of quality, confidentiality, professionalism, and integrity throughout all engagements.
  • To assist any other related duties as may be assigned from time to time by the company.
Required Skills and Qualifications:
  • Bachelor’s Degree in Cybersecurity, Information Technology, Information Systems, Computer Science, Risk Management, or related discipline.
  • Approximately 4–7 years of relevant experience in Information Security GRC, Cybersecurity Consulting, IT Risk, Technology Risk, Cybersecurity Audit, IT Audit, Regulatory Compliance, or Information Security Management Systems.
  • Experience in client-facing consulting or professional services is highly preferred.
  • Strong knowledge of information security governance, cybersecurity risk management, compliance, audit, and control assessment.
  • Hands-on experience conducting cybersecurity risk assessments, gap assessments, internal audits, maturity assessments, regulatory compliance reviews, or control effectiveness assessments.
  • Good working knowledge of recognised standards and frameworks such as ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, ISO/IEC 27701, ISO 22301, ISO/IEC 42001, NIST Cybersecurity Framework, CIS Controls, COBIT, and SOC 2 Trust Services Criteria.
  • Familiarity with Malaysian cybersecurity and technology regulatory requirements, including BNM Risk Management in Technology (RMiT), BNM Management of Customer Information and Permitted Disclosures (MCIPD), Cyber Security Act 2024, NACSA / NCII requirements, MCMC information and network security requirements, PDPA, Securities Commission Malaysia requirements, and Bursa Malaysia requirements will be an advantage.
  • Possession of one or more relevant professional certifications such as ISO/IEC 27001 Lead Auditor / Lead Implementer, CISA, CISM, CRISC, CISSP, CGEIT, ISO 22301 Lead Auditor / Lead Implementer, ISO/IEC 42001 Lead Auditor / Lead Implementer, COBIT, CCSP, CCSK, or relevant privacy certifications will be an advantage.
  • Strong ability to review policies, procedures, processes, systems, controls, and supporting evidence to determine design adequacy and operating effectiveness.
About Our Culture:

EC-Council is driven by a mission to strengthen global cybersecurity capability and advance the profession of ethical hacking and information security. Our teams operate across regions and cultures, united by integrity, professionalism, and a commitment to meaningful impact. Continuous learning and accountability are encouraged, empowering individuals to take ownership of their contributions. Respect, trust, and ethical conduct guide how we work with colleagues, partners, and the global cybersecurity community.

Additional Information:

EC-Council is an equal opportunity workplace and an affirmative action employer. We are committed to providing equal employment opportunities regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, or veteran status. We do not discriminate based on these or any other characteristics protected by applicable laws or regulations in the locations where we operate.

EC-Council is dedicated to working with and providing reasonable accommodations to individuals with disabilities. If you have a medical condition or disability that limits your ability to complete any part of the application process and require reasonable accommodation, please contact us at ecchr@eccouncil.org and let us know how we can assist. To be eligible for this position, candidates must be able to provide proof that they are either a citizen of the country or have legal authorization to work in the country where the position is posted and are currently residing there. EC-Council does not offer employment to ineligible candidates and reserves the right to revoke employment in case the candidate loses the authorization to work. If, as part of the recruitment process, you are required to complete or submit any form of work, project, case study, or assignment, please note that such material will be considered the exclusive property of EC-Council. By submitting such work, you acknowledge that EC-Council retains all rights, title, and interest in the submitted content, including any intellectual property contained therein. Candidates further waive any intellectual property or moral rights in such submissions, confirm that the work is original and free of third-party infringement, and acknowledge that it is provided solely for evaluation purposes, with no ownership or other rights retained.

Our Privacy Policy outlines how we collect, use, store, and protect your personal data during the recruitment process. This may include information such as your name, contact details, employment history, qualifications, and any other details you provide as part of your application. All data is handled in compliance with applicable data protection and privacy regulations.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Consultant - Tech Risk, Cyber & Privacy Advisory
Senior Consultant - Tech Risk, Cyber & Privacy Advisory

EC-Council Global Services • Kuala Lumpur

On-site
MYR 150,000 - 210,000
Senior Consultant - Tech Risk, Cyber & Privacy Advisory
Senior Consultant - Tech Risk, Cyber & Privacy Advisory

EC-Council Group • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Senior GRC Consultant - Cyber Risk & Compliance Advisory
Senior GRC Consultant - Cyber Risk & Compliance Advisory

EC-Council Global Services • Kuala Lumpur

On-site
MYR 150,000 - 210,000
Sr Director - Business Development
Sr Director - Business Development

EC-Council Group • Kuala Lumpur

On-site
MYR 400,000 - 800,000
Cyber Security Manager
Cyber Security Manager

EC-Council Group • Kuala Lumpur

On-site
MYR 90,000 - 150,000
Soc Manager
Soc Manager

EC-Council Global Services • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Senior GRC Consultant: Cybersecurity Governance & Risk
Senior GRC Consultant: Cybersecurity Governance & Risk

EC-Council Group • Kuala Lumpur

On-site
MYR 120,000 - 180,000
IT Governance, Risk & Compliance Analyst
IT Governance, Risk & Compliance Analyst

Petron group • Kuala Lumpur

On-site
MYR 75,000 - 120,000
Reporting Lead
Reporting Lead

EC-Council Global Services • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Senior GRC Security Consultant — Risk & Compliance
Senior GRC Security Consultant — Risk & Compliance

EC-Council Group • Kuala Lumpur

On-site
MYR 180,000 - 240,000