Role SummaryThe successful candidate will join the company IT Security & Governance team to lead a structured review of approximately 38 in-house applications against internal IT security and control standards, while coordinating remediation activities with application, IT, and business stakeholders.
Key Responsibilities
- Maintain a central tracker capturing compliance status of applications against internal IT security standards.
- Facilitate assessment workshops with business owners, system owners, IT leads, and the security review team.
- Document assessment findings, risk ratings, and agreed remediation plans in a clear and consistent manner.
- Track remediation actions to closure and manage exception processes where remediation is not feasible.
- Support reviews of user access administration for selected in-house applications and assist in transitioning them into a more structured governance model.
- Prepare regular progress reports, dashboards, and audit-ready documentation.
Mandatory Requirements
- Bachelor's Degree in Information Technology, Computer Science, Information Security, or equivalent.
- 3–6 years of experience in IT Governance, IT Audit, IT Risk, or IT Compliance.
- Good understanding of IT security control domains, including:
- User Access Management
- Privileged Access Management
- Multi-Factor Authentication (MFA)
- Encryption
- System Logging and Monitoring
- Vulnerability Management
- Data Protection
- Strong attention to detail and documentation skills.
- Excellent follow-up and stakeholder management capabilities.
- Ability to work independently and manage multiple workstreams effectively.
- Strong proficiency in Microsoft Excel, PowerPoint, and Word.
- Good written and verbal communication skills in English.
Preferred Qualifications
- Experience within the financial services, insurance, or takaful industry.
- Familiarity with Bank Negara Malaysia (BNM) regulations, PDPA, ISO 27001, and internal audit frameworks.
- Experience with Identity & Access Management (IAM), Privileged Access Management (PAM) solutions, and IT ticketing platforms such as Jira or Remedyforce.
- Professional certifications such as CISA, CRISC, CISM, or ISO 27001 Lead Auditor.
Pay: RM5,000.00 - RM9,000.00 per month
Education:
Experience:
- IT Governance, IT Audit, IT Risk, or IT Compliance: 3 years (Required)
- IT security control: 3 years (Preferred)
- financial services, insurance, or takaful industry: 2 years (Required)
- Bank Negara Malaysia Regulations: 1 year (Preferred)
Work Location: In person