Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
Mindteck, Inc. in Malaysia seeks a Senior Executive – IT (Cybersecurity Risk & Policy) to lead governance, risk and compliance initiatives. You will develop policies, conduct risk assessments, and drive remediation with IT and business teams.
The role requires 5–7 years in cybersecurity risk, governance and compliance, familiarity with ISO 27001 and NIST CSF, and hands-on experience with GRC platforms such as RSA Archer or ServiceNow. This is a contract position based in Sepang.
Find work that actually fits - with teams building things that matter
We are seeking an experienced Senior Executive – IT (Cybersecurity Risk & Policy) to support the organization's cybersecurity Governance, Risk & Compliance (GRC) initiatives.
The role will be responsible for developing and maintaining cybersecurity policies and standards, conducting risk assessments and compliance reviews, managing cybersecurity risks, and supporting alignment with applicable regulatory requirements and industry frameworks.
The ideal candidate will have strong experience in cybersecurity governance, risk management, compliance, audit, and third-party risk, with the ability to work effectively across business, IT, and operational teams.
Develop, review, maintain, and implement cybersecurity policies, standards, procedures, and guidelines.
Conduct cybersecurity risk assessments, gap analyses, control assessments, and compliance reviews.
Identify, assess, document, and monitor cybersecurity risks and recommend appropriate mitigation measures.
Maintain risk registers, risk dashboards, compliance records, and audit documentation.
Support internal and external cybersecurity audits and assessments, including tracking findings and remediation activities.
Conduct third-party/vendor cybersecurity risk assessments and monitor associated risks.
Utilize GRC platforms to manage risk, compliance, controls, assessments, issues, and reporting.
Monitor changes in cybersecurity regulations, standards, regulatory requirements, and emerging threats and assess their potential impact on the organization.
Support the implementation and continuous improvement of cybersecurity governance and control frameworks.
Prepare management reports, risk dashboards, compliance reports, and cybersecurity metrics.
Assist in developing and conducting cybersecurity awareness and security culture programs.
Collaborate with business, IT, infrastructure, risk, audit, legal, and operational stakeholders to strengthen cybersecurity governance.
Support the tracking and closure of cybersecurity audit findings, control gaps, and risk remediation activities.
Provide guidance to stakeholders on cybersecurity policies, controls, risk requirements, and compliance expectations.
Bachelor’s Degree in Cybersecurity, Information Technology, Information Security, Computer Science, or a related discipline.
5–7 years of experience in cybersecurity risk, governance, compliance, information security, or related areas.
Strong understanding of cybersecurity risk management and governance principles.
Familiarity with ISO 27001, NIST Cybersecurity Framework, risk management frameworks, and audit processes.
Experience performing risk assessments, gap assessments, control assessments, and compliance reviews.
Experience managing cybersecurity risks, issues, audit findings, and remediation activities.
Experience in third-party/vendor risk management is preferred.
Hands-on experience with GRC platforms such as:
RSA Archer
ServiceNow GRC
MetricStream
Other equivalent GRC platforms
Relevant professional certifications such as:
CISA – Certified Information Systems Auditor
CISSP – Certified Information Systems Security Professional
CRISC – Certified in Risk and Information Systems Control
Certified GRC Professional or equivalent