Role PurposeTo support IMU’s Technology Governance function across IT Services, covering technology governance, risk and compliance, audit coordination, vendor governance, policy framework, disaster recovery and business continuity governance, reporting, and follow-up on control gaps.
This is a governance and assurance role, with close coordination across the Network and Infrastructure and Cybersecurity Operations and Assurance functions where required.
Job Responsibilities- Maintain the Technology Governance Framework, policies, standards, procedures, control checklists, evidence requirements and review cycles.
- Coordinate IT governance activities covering change, incident, service, monitoring and operational control reviews.
- Maintain the Technology Risk Register and track mitigation actions, control gaps, owners and closure dates.
- Coordinate internal/external audits, audit readiness, evidence collection, walkthroughs, responses and finding closure.
- Support compliance for ISO27001, PDPA, AI governance, internal controls, institutional policies and contractual requirements.
- Coordinate vendor governance including vendor risk review, SLA tracking, compliance evidence and periodic vendor review.
- Support DR/BCP governance and prepare monthly governance reporting on risk, audit, compliance, vendor issues and remediation status.
Job Requirement- Bachelor’s degree in Information Technology, Computer Science, Information Systems, Cybersecurity, Risk Management, or a related field.
- 3 to 6 years of relevant experience in technology governance, risk and compliance, audit, information security, IT service management, or vendor governance.
- Good understanding of ISO/IEC 27001, COBIT, ITIL, NIST, PDPA, vendor governance, service level agreement tracking, and disaster recovery governance.
- Experience in audit coordination, evidence collection, control testing, remediation tracking, and closure of audit findings.
- Good documentation, reporting, evidence management, and stakeholder coordination skills.
- Analytical, organised, proactive, and able to track remediation actions to closure while maintaining confidentiality and integrity.
- Professional certifications such as CISA, CRISC, ISO 27001 Lead Auditor/Lead Implementer, ITIL, COBIT, or equivalent would be an added advantage.