Job Search and Career Advice Platform

Enable job alerts via email!

Senior Risk Management Specialist (Cyber / IT Risk)

PowTech Solution (M) Sdn. Bhd

Selangor

On-site

MYR 100,000 - 150,000

Full time

Yesterday
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading technology solutions provider in Malaysia is seeking a Senior Risk Management Specialist to oversee the execution of IT and cyber risk management activities. This role involves performing risk assessments, maintaining risk registers, and preparing comprehensive risk reports. Candidates should possess 6 to 10 years of experience in IT Risk Management or Cyber Security, with relevant certifications being a significant advantage. Strong communication skills in English and the ability to work independently are essential. This position offers a dynamic environment for individuals passionate about technology risk management.

Qualifications

  • 6 to 10 years of hands-on experience in IT Risk Management, Cyber Security Risk, Application Risk Assessment, or IT Audit / Technology Controls.
  • Experience working in MNC or regional APAC environments is preferred.
  • Professional certifications such as CISA, CRISC, CISSP, ISO 27001 Lead Implementer, or Lead Auditor are beneficial.

Responsibilities

  • Perform IT, cyber, and application risk assessments.
  • Identify, assess, and document technology and security risks.
  • Maintain and update risk registers, risk ratings, and mitigation plans.
  • Support IT audit activities.
  • Prepare risk reports and management presentations.

Skills

IT Risk Management
Cyber Risk
Stakeholder management
Communication
Analytical skills

Education

Bachelor’s Degree in Information Technology, Cyber Security, Risk Management, Computer Science, Engineering, or related discipline

Tools

GRC tools
ISO 27001
NIST
COBIT frameworks
Job description
Role Overview

The Senior Risk Management Specialist is responsible for hands-on execution of IT and cyber risk activities. The role works closely with IT, Security, Audit, and business stakeholders to identify, assess, and manage technology risks in line with group standards. This is an individual contributor role. The position does not involve people management and requires strong independence and ownership.

Key Responsibilities
  • Perform IT, cyber, and application risk assessments
  • Identify, assess, and document technology and security risks
  • Maintain and update risk registers, risk ratings, and mitigation plans
  • Support IT audit activities, including audit preparation, response, and remediation tracking
  • Review effectiveness of IT and application controls
  • Coordinate with IT, Security, Internal Audit, and business stakeholders
  • Prepare risk reports, dashboards, and management presentations
  • Support risk reviews, workshops, and governance forums
  • Ensure alignment with group risk policies, standards, and frameworks
  • Participate in incident analysis and post-event reviews when required
  • Strong experience in IT Risk Management, Cyber Risk, or GRC
  • Hands-on exposure to application risk assessment and IT controls
  • Good understanding of IT audit processes
  • Strong stakeholder management, communication, and coordination skills
  • Able to translate technical risks into business-impact language
  • Comfortable working independently and managing multiple priorities
  • Structured, analytical, and detail-oriented
  • Able to work under pressure in a regional environment
Requirements
  • Bachelor’s Degree in Information Technology, Cyber Security, Risk Management, Computer Science, Engineering, or related discipline
  • 6 to 10 years of hands-on experience in IT Risk Management, Cyber Security Risk, Application Risk Assessment, or IT Audit / Technology Controls
  • Experience working in MNC or regional APAC environments is preferred
  • Familiarity with ISO 27001, ISO 31000, NIST, and COBIT frameworks
  • Exposure to GRC tools or structured risk platforms is an advantage
  • Professional certifications is a big plus, including CISA, CRISC, CISSP (risk or governance focus), ISO 27001 Lead Implementer or Lead Auditor, and CIA
  • Excellent communicator in English with strong interpersonal skills
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.