GRC Analyst

MA COMPLIANCE PTE. LTD.

Singapore

On-site

SGD 60,000 - 90,000

Full time

9 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

MA Compliance PTE. LTD. in Singapore seeks a GRC Analyst to work directly on client engagements, helping SME and start-up clients build, run and evidence their risk management and compliance programmes.

You will typically manage two to four concurrent engagements, conducting risk assessments, policy reviews and remediation tracking, and will be the primary GRC contact for clients. Experience with ISO 27001, PDPA, GDPR is a plus.

Qualifications

  • Degree or equivalent qualification in Information Technology, Cybersecurity, Risk Management, Business or a related discipline.
  • Professional

Responsibilities

  • Plan and run risk assessments for client organisations—asset and process scoping, threat and vulnerability identification, likelihood and impact rating, and treatment planning.
  • Facilitate Risk & Control Self-Assessment (RCSA) workshops with client business owners, and challenge risk ratings and control descriptions where the evidence does not support them.
  • Build and maintain client risk registers, and track risks, issues, incidents and remediation actions through to closure.
  • Define and monitor Key Risk Indicators (KRIs) for early visibility of exposures.
  • Support clients on third‑party and vendor risk assessments, including due diligence questionnaires and contractual security requirements.
  • Conduct gap assessments against ISO 27001, SOC 1/2/3,PDPA, GDPR and other standards, and translate findings into remediation roadmaps.
  • Prepare clients for certification, surveillance and audits—evidence collection, control walkthroughs, internal audit support.
  • Act as liaison with external auditors and coordinate management responses to findings.
  • Perform internal audits of client ISMS and report results to management.
  • Support PDPA obligations, including data inventories, DPIAs, consent and retention practices, and breach-notification readiness.
  • Draft, tailor and review information security policies and supporting records.
  • Establish governance routines for clients and maintain engagement documentation.

Skills

GRC
Risk management
Policy drafting

Education

Degree in IT/Cybersecurity/Risk Management

Tools

Power BI
JIRA
Excel

Job description

ABOUT MA COMPLIANCE

MA Compliance is a Singapore-headquartered IT and cybersecurity firm that helps small and medium enterprises and fast-growing start-ups become - and stay - audit-ready. With more than two decades of delivery experience across IT infrastructure, information security and compliance, we treat cyber risk management as a business enabler rather than a paperwork exercise.

Our compliance practice covers security consultation, compliance assessment, policy creation and review, security awareness training, IT asset classification, and incident and risk management, against frameworks including ISO 27001, SOC 1/2/3, GDPR, PDPA, CCPA and DPDP. We serve clients across Singapore, Indonesia, Vietnam, the Philippines and India, in industries ranging from manufacturing and logistics to healthcare, technology and financial services.

THE ROLE

The GRC Analyst is a client‑facing consulting role. You will work directly on client engagements - helping SME and start‑up clients build, run and evidence their risk management and compliance programmes.

Day to day, that means running risk assessments and gap analyses, writing and reviewing policies, preparing clients for certification and surveillance audits, tracking remediation to closure, and reporting risk clearly enough that a client’s management team can act on it. You will typically carry two to four concurrent engagements and will be the client’s main point of contact for GRC matters on those projects.

KEY RESPONSIBILITIES
Client Risk Management
  • Plan and run risk assessments for client organisations- asset and process scoping, threat and vulnerability identification, likelihood and impact rating, and treatment planning.
  • Facilitate Risk & Control Self-Assessment (RCSA)workshops with client business owners, and challenge risk ratings and control descriptions where the evidence does not support them.
  • Build and maintain client risk registers, and track risks, issues, incidents and remediation actions through to closure.
  • Define and monitor Key Risk Indicators (KRIs) so clients have early visibility of exposures rather than after-the-fact surprises.
  • Support clients on third‑party and vendor risk assessments, including due diligence questionnaires and contractual security requirements.
Compliance Assessment& Audit Readiness
  • Conduct gap assessments against ISO 27001, SOC 1/2/3,PDPA, GDPR and other applicable standards, and translate findings into a prioritised, costed remediation roadmap.
  • Prepare clients for certification, surveillance and customer audits - evidence collection, control walkthroughs, internal audit support and mock audits.
  • Act as the client’s liaison with external auditors and certification bodies during fieldwork, and coordinate management responses to findings.
  • Perform internal audits of client Information Security Management Systems (ISMS) and report results to client management.
  • Support clients’ PDPA obligations, including data inventories, DPIAs, consent and retention practices, and breach-notification readiness.
Governance, Policy &Documentation
  • Draft, tailor and review information security policies, standards, procedures and supporting records so they fit the client’s actual size, risk profile and operating model.
  • Carry out IT and information asset classification exercises to underpin clients’ data‑protection objectives.
  • Establish practical governance routines for clients -management review meetings, risk committee packs, exception and waiver handling, and document control.
  • Maintain complete, well‑organised engagement documentation and evidence so client programmes withstand audit scrutiny.
Reporting & Analytics
  • Produce risk dashboards, assessment reports and management reporting packs that are clear to non‑technical business owners.
  • Analyse risk and control data to surface trends, recurring control weaknesses and areas needing management attention.
  • Use reporting and GRC tooling (for example Power BI,JIRA, Excel, and GRC platforms) to improve the accuracy, consistency and turnaround of engagement reporting.
  • Contribute to internal delivery quality - reusable templates, assessment checklists and methodology improvements.
Client Engagement &Advisory
  • Serve as the day‑to‑day GRC contact on assigned engagements, managing scope, timelines and deliverables alongside the engagement lead.
  • Explain risk and compliance requirements to client stakeholders - from IT administrators to founders and board members - in language they can act on.
  • Deliver security awareness and risk training sessions to client teams.
  • Support pre‑sales and scoping conversations with prospective clients, including proposal input and effort estimation.
  • Identify opportunities to extend the value MA Compliance delivers to existing clients.
QUALIFICATIONS
  • Degree or equivalent qualification in Information Technology, Cybersecurity, Risk Management, Business or a related discipline.
  • Professional
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Analyst: Risk, Compliance & Audit Readiness
GRC Analyst: Risk, Compliance & Audit Readiness

MA COMPLIANCE PTE. LTD. • Singapore

On-site
SGD 60,000 - 90,000
Cyber Risk / GRC Consultant
Cyber Risk / GRC Consultant

RECRUIT123 PTE. LTD. • Singapore

On-site
SGD 61,000 - 100,000
Sponsorship for security certs
Career development toward Senior GRC /
CISO-track opportunities
GRC Application Security Specialist (Contract)
GRC Application Security Specialist (Contract)

Public Service Division • Singapore

On-site
SGD 90,000 - 130,000
Cybersecurity GRC Consultant (Full-Time) #IAC
Cybersecurity GRC Consultant (Full-Time) #IAC

RECRUIT EXPRESS PTE LTD • Singapore

On-site
SGD 120,000 - 180,000
Manager, Compliance
Manager, Compliance

SMRT Corporation, Ltd. • Singapore

On-site
SGD 120,000 - 180,000
Senior Information Security Manager | GRC
Senior Information Security Manager | GRC

Randstad Singapore • Singapore

On-site
SGD 150,000 - 210,000
GRC Application Security Specialist (Contract)
GRC Application Security Specialist (Contract)

Monetary Authority of Singapore (MAS) • Singapore

On-site
SGD 120,000 - 170,000
Senior Manager, Governance, Risk & Compliance
Senior Manager, Governance, Risk & Compliance

National Trades Union Congress (NTUC) • Singapore

On-site
SGD 140,000 - 210,000
Cyber Risk & GRC Consultant - Impact & Compliance
Cyber Risk & GRC Consultant - Impact & Compliance

RECRUIT EXPRESS PTE LTD • Singapore

On-site
SGD 120,000 - 180,000
Governance, Risk & Compliance Analyst
Governance, Risk & Compliance Analyst

KWE-APLL Technology Services Pte Ltd • Singapore

On-site
SGD 120,000 - 190,000