JOB SUMMARY
Serve as the primary liaison between Technology and internal/external auditors, regulators, risk, and compliance stakeholders. Coordinate and manage information requests, facilitate discussions with relevant technology teams, and ensure the timely delivery of accurate, complete, and high-quality audit and compliance submissions. Maintain proper documentation of audit evidence, perform quality assurance reviews on audit-related matters, and escalate non-compliance findings to Technology leadership.
JOB RESPONSIBILITIES
- Audit & Compliance
- Attend to all matters related to internal/external auditors, regulators, risk and compliance.
- Negotiate with auditors and internal stakeholders as to audit scope, delivery timeline, audit findings and remediation.
- Work closely with various technical and business teams to collect, compile, evaluate and assess information for audit submission.
- Perform quality control on all audit and compliance matters.
- Systematically record all evidences/supporting documents submitted to audits.
- Cascade audit requests to auditees and manages discussion and clarification session.
- Work closely with business units and auditors to close audit issues in a timely manner.
- Conduct periodic review on activities performed by various teams against the company policies and procedures.
- Report any non-compliance findings to superiors
- Policy Management
- Creating, maintaining, and enforcing IT policies, procedures, and standards to ensure compliance with laws, regulations (BNM RMIT, SC GTRM, Bursa ITSS) and industry standards.
- Process Improvement
- Identify gaps in IT processes and lead improvement initiatives
- Performing gap analysis against industry or regulatory standards
JOB REQUIREMENT
- Bachelor’s degree with related field
- Certifications such as CISM, CISA, CISSP or CRISC
- Proven experience in managing audit and compliance processes
- At least 5 years’ experience in IT Governance, Cybersecurity, Risk, Compliance or Audit related domain
- Expertise in risk assessment methodologies, cybersecurity frameworks (NIST CSF), and regulatory environments (RMIT, GTRM, ITSS).
- Technical knowledge of IT infrastructure, cybersecurity, and data management domains.
- Excellent verbal and written communication skills in English with good negotiation skills
- Ability to take ownership of matters through to a logical conclusion
- Meticulous in record keeping and documentation
- Ability to work well under pressure.