Implement and maintain cybersecurity compliance program to support the overall cybersecurity program.
Compliance Management & Governance
Responsibilities
- Maintain comprehensive documentation of compliance activities, including policies, procedures, audit results, and training records.
- Monitor relevant laws, regulations, and standards (e.g., DPA2012, GDPR, ISO27001, NIST CSF) to ensure the organization complies with cybersecurity requirements.
- Implement compliance review to organization’s security policies, procedures, industry best practices, relevant laws, regulations, and standards.
- Maintain records of compliance activities, audits, and assessments.
- Ensure that compliance metrics and reports meet regulatory requirements and are submitted to relevant authorities as needed.
- Monitor compliance with established security policies, procedures, industry best practices, relevant laws, regulations, and standards, and report findings to management.
- Monitor and track corrective actions for non-compliance issues, including risk acceptance and risk exceptions.
- Ensure that remediation efforts are completed effectively and verify that vulnerabilities have been addressed.
- Develop key performance indicators (KPIs) and metrics that align with the organization’s compliance objectives and regulatory requirements.
- Identify specific metrics to measure compliance with laws, regulations, and internal policies related to cybersecurity.
- Integrate compliance metrics into the organization and cybersecurity’s risk assessment processes to provide a comprehensive view of compliance-related risks.
- Use metrics to inform risk management decisions and prioritize compliance initiatives.
- Stay informed about emerging trends, threats, and changes in regulations to continuously improve the organization’s compliance posture.
Compliance Review, Audit and Reporting
- Conduct regular risk assessments to identify compliance gaps and vulnerabilities within the organization’s cybersecurity framework.
- Conduct internal review and assessments to evaluate the effectiveness of compliance controls and identify areas for improvement.
- Provide support to cybersecurity risk management activities. Provide critical insights to identify compliance gaps and facilitating the development of effective risk mitigation strategies.
- Collaborate with Internal Audit to support audit and compliance activities including external audits and regulatory compliance activities.
- Prepare and present compliance reports to senior management and regulatory bodies as required.
- Generate reports, track and document compliance violations and remediation actions.
- Continuously monitor compliance metrics and key performance indicators (KPIs) and to assess the effectiveness of compliance programs and identify trends or areas of concern.
- Establish benchmarks for compliance performance and compare the organization’s metrics against industry standards or best practices.
Policy Development
- Develop, implement, and maintain cybersecurity policies and procedures that align with regulatory requirements and industry best practices.
- Provide training and awareness programs for employees on compliance requirements, policies, and best practices related to cybersecurity.
- Promote awareness of compliance metrics and their importance in achieving organizational goals.
- Collaborate with incident response teams to ensure that compliance considerations are integrated into incident management processes.
- Ensure that maintenance of documentation and reports for regulatory reporting for incident response activities.
- Coordinate with Legal Team on regulatory compliance, disclosures and potential fines and impact.
- Act as a liaison between cybersecurity teams and business units to ensure that compliance to cybersecurity requirements.
- Communicate compliance cybersecurity risks and mitigation strategies.
- Work with IT, Legal, HR, DPO, Enterprise Risk Officer and compliance teams on cybersecurity initiatives.
- Support other cybersecurity activities.
Qualifications
- With Bachelor’s Degree on Information Technology, Computer Engineering, or any equivalent IT course.
- With at least 3 years’ experience on cybersecurity compliance related position/functions.
- Strong foundation on cybersecurity fundamentals and its framework, and cybersecurity standards and regulations e.g., ISO27001, NIST CSF, GDPR, and DPA2012.
- Highly knowledgeable of relevant laws, regulations, and standards related to cybersecurity and data protection.
- Highly knowledgeable of cybersecurity technologies, tools, and practices, as well as an understanding of IT infrastructure.
- Strong analytical and problem-solving skills to assess compliance risks and develop effective mitigation strategies.
- Attention to details to identify potential security threats and vulnerabilities.
- Excellent verbal and written communication skills to convey complex security concepts to non-technical stakeholders.
- Ability to work collaboratively with cross-functional teams to achieve cybersecurity goals.
- Entry level cyber security certifications such as CompTIA Security+, Certified Information Systems Auditor (CISA) or other related certifications (e.g., Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Certified in Risk and Information Systems Control (CRISC).
- Ability to manage multiple projects and priorities effectively to achieve targets within deadline.