Compliance and ISMS Support
- Maintain and help reconcile core ISMS documentation, including the Statement of Applicability (SoA), ISMS Manuals, and supporting SOPs, ensuring version control and consistency across documents.
- Maintain, and monitor compliance with ISO27001:2022 Clauses 4–10 and applicable Annex A controls across ICT operations.
- Track applicable legal and regulatory requirements (e.g., Personal Data Protection Act, Cybersecurity Act 854, Electronic Commerce Act 2006, Computer Crimes Act 1997) and support periodic compliance reviews.
- Deliver periodic security awareness training to staff as part of the ISMS awareness and training requirement.
IT Risk Management
- Maintain and update the organizational Risk Register in line with the Risk Management Procedure, including at least annual review and event-triggered updates following incidents or significant changes.
- Conduct risk assessments for new systems, projects, vendors, and significant changes to existing infrastructure.
- Support risk treatment planning, tracking mitigation actions through closure, and escalating overdue or high-severity risks to the ISMS Owner.
Incident & Control Monitoring
- Support incident response activities involving information security events, ensuring appropriate escalation to IT/Security in line with policy.
- Monitor evidence of operating controls (access reviews, backup testing, vulnerability scans, security awareness training records) and flag gaps proactively.
- Contribute technical input on data loss prevention, access control, and related technological
Audit Support
- Assist in planning and executing internal audits, including preparing evidence, coordinating with auditees, and maintaining the audit schedule.
- Support external certification and surveillance audits by certification bodies, including evidence gathering and auditor liaison.
- Log audit findings (nonconformities, observations, opportunities for improvement) into the CAPA Log and track corrective actions to closure within defined deadlines.
- Audit support excludes leading or independently verifying controls directly owned or operated by the ICT department; such audits shall be assigned to an independent auditor per the ISMS independence requirements.
Reporting & Continuous Improvement
- Prepare risk and compliance status reports for Management Review meetings.
- Recommend improvements to policies, procedures, and controls based on audit findings, incident trends, and risk assessment outcomes.
- Support the ISMS Owner in maintaining a rotational internal audit programme across departments.
Information Security Roles & Responsibilities
- To guard against abuse that disrupts or threatens the viability of all ICT systems.
- To understand the consequences of their actions regarding computing security practices and act accordingly. Embrace the “Security is everyone’s responsibility” philosophy to assist ENV in meeting its business goals.
- To read the Enviros Information Security Policy and acknowledge the same at least once annually.
- To comply with all applicable information security, data protection, and privacy laws, regulations, contractual obligations, and regulatory requirements in the jurisdictions where ENV operates, including ISO/IEC 27001:2022 and other applicable international, regional, and local legal requirements.
Pay: Up to RM6,000.00 per month
Benefits:
- Additional leave
- Dental insurance
- Health insurance
- Maternity leave
- Opportunities for promotion
- Parental leave
- Professional development
Work Location: In person