Skill: GRC
Role: Cybersecurity GRC Analyst / Specialist/ Consultants / Information Security / GRC Analyst
Location: KL, Malaysia
Work mode: Hybrid (Tuesday-Thursday in office)
About the Role
We are looking for an experienced Cybersecurity GRC Analyst to join a global cybersecurity team supporting Governance, Risk, and Compliance initiatives. The ideal candidate will possess a strong understanding of cybersecurity governance, risk management, compliance frameworks, and security policies, while being able to communicate cyber risks effectively to both technical and business stakeholders. The role also requires strong presentation skills to prepare executive-level reports and presentations.
Key Responsibilities
- Conduct cybersecurity risk assessments and control evaluations.
- Develop, review, and maintain cybersecurity policies, standards, and procedures.
- Support Governance, Risk & Compliance (GRC) initiatives across the organization.
- Perform gap assessments and recommend remediation plans.
- Ensure compliance with cybersecurity frameworks, standards, and regulatory requirements.
- Maintain risk registers, control documentation, and governance records.
- Prepare executive dashboards, reports, and PowerPoint presentations for senior leadership.
- Translate technical cybersecurity risks into business-friendly language.
- Present cybersecurity risks, compliance status, and recommendations to senior stakeholders.
- Collaborate with IT, Security, Risk, Audit, and Business teams to strengthen the organization's cybersecurity posture.
- Support internal and external audits and drive remediation activities.
- Monitor emerging cybersecurity risks and recommend governance improvements.
Required Skills
- Strong understanding of Cybersecurity Governance, Risk & Compliance (GRC)
- Cyber Risk Assessment
- Information Security Governance
- Security Controls
- Compliance Management
- Policy Development & Implementation
- Control Frameworks
- Risk Registers
- Gap Analysis
- Audit Management
- Stakeholder Management
- Excellent PowerPoint and presentation skills
- Strong written and verbal communication
- Ability to explain technical cybersecurity concepts in business language
Preferred Frameworks & Standards
- ISO 27001
- NIST Cybersecurity Framework (CSF)
- CIS Controls
- SOC 2
- COBIT
- ISO 31000
- IT Risk Management Frameworks
Preferred Experience
- 3+ years of experience in Cybersecurity, Information Security, IT Risk, or GRC.
- Experience working with enterprise cybersecurity governance programs.
- Experience presenting to senior management, executives, or leadership teams.
- Consulting or multinational company experience is an advantage.
Preferred Certifications
- CISA
- CRISC
- CGRC
- CISSP
- ISO 27001 Lead Implementer
- ISO 27001 Lead Auditor
- Security+
What We're Looking For
- Strong analytical and problem-solving skills
- Excellent stakeholder management
- Ability to influence business decisions through effective communication
- Comfortable working with cross-functional global teams
- Self-driven with strong organizational skills
Pay: RM3,087.95 - RM10,000.00 per month
Benefits:
- Flexible schedule
- Health insurance
- Opportunities for promotion
- Professional development
Application Question(s):
- Citizen of Malaysia
- Willing to apply for 1-year extended contract through agency payroll
- Budget for the given role would be RM 10k, please mention your current and expected salary
- Need to join immediately or within max of 30 days notice period
- How many years of experience do you have in Cybersecurity Governance, Risk & Compliance (GRC)?
Work Location: In person