ROLE: IT Security Governance Specialist
Location: Bangi, Malaysia
Job Summary
We are looking for an experienced IT Security Governance Specialist to strengthen and support information security governance, risk and compliance activities within a large and complex organisation.
The successful candidate will be responsible for IT Security Governance, Risk & Compliance (GRC), ISO 27001:2022 implementation, regulatory compliance, risk assessments, audit coordination and remediation tracking. The role will involve working closely with internal stakeholders, auditors and business teams to ensure effective implementation and continuous improvement of the organisation's information security framework.
Key Responsibilities
- Manage and support IT Security Governance, Risk & Compliance (GRC) activities.
- Support the implementation, maintenance and continuous improvement of ISO 27001:2022 / ISMS.
- Conduct information security risk assessments and support risk treatment and remediation activities.
- Perform regulatory and compliance gap assessments against applicable requirements.
- Coordinate internal and external information security audits.
- Prepare and maintain security governance documentation, policies, standards, procedures and compliance evidence.
- Track security findings, risks, corrective actions and remediation activities until closure.
- Support management reporting on security risks, compliance status, audit findings and remediation progress.
- Coordinate with internal stakeholders to ensure security controls are implemented effectively.
- Support regulatory assessments and ensure identified gaps are appropriately addressed.
- Develop and deliver security awareness programmes and related security communications.
- Support cyber insurance renewal coordination, including gathering required security and risk information.
- Engage with auditors, business stakeholders and relevant security teams during assessments and reviews.
- Maintain appropriate documentation and evidence for audit and regulatory requirements.
- Provide recommendations for improving security governance, risk management and compliance processes.
Required Qualifications & Experience
- Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Security or a related field.
- Minimum 5 years of experience in IT Security Governance, Risk & Compliance (GRC).
- Strong experience in IT Security Governance and Information Security GRC.
- Hands-on experience with ISO 27001:2022 implementation, maintenance or recertification.
- Experience conducting regulatory compliance and gap assessments.
- Strong experience in security risk assessment and remediation tracking.
- Experience coordinating internal and external security audits.
- Strong understanding of information security policies, controls, standards and governance frameworks.
- Good experience in stakeholder management and cross-functional coordination.
- Strong documentation, analytical and reporting skills.
- Good communication skills in English.
Preferred Experience
- Experience in the Banking / Financial Services / BFSI sector.
- Experience working with financial-sector regulatory requirements.
- Experience supporting ISO 27001 certification or recertification.
- Experience with regulatory audits and compliance assessments.
- Experience coordinating cyber insurance renewal activities.
- Knowledge of information security risk management frameworks and industry best practices.
Key Skills
IT Security Governance | GRC | Information Security | ISO 27001:2022 | ISMS | Risk Assessment | Risk Management | Regulatory Compliance | Regulatory Gap Assessment | Audit Coordination | Security Compliance | Remediation Tracking | Security Awareness | Stakeholder Management | Cyber Insurance
Pay: RM4,200.00 - RM10,500.00 per month
Benefits:
- Additional leave
- Health insurance
- Opportunities for promotion
- Parental leave
- Professional development
Application Question(s):
- Citizen of Malaysia
- Willing to apply for 1 year extended contract through agency payroll
- Currently or able to commute or willing to relocate to BANGI location
- Budget for the given role would be RM 10,000 (Mention your current and expected slaary)
- Will be able to join immediately or in max 30 days notice
- How many years of experience do you have in IT Security Governance / GRC?
-
- Do you have hands-on experience with ISO 27001:2022 implementation or recertification?
- Do you have experience conducting regulatory compliance or regulatory gap assessments?
Work Location: In person