Cybersecurity GRC Analyst
Location: Kuala Lumpur, Malaysia
Employment Type: Contract (12 Months, Renewable)
About the Role
We are seeking an experienced Cybersecurity Governance, Risk & Compliance (GRC) Analyst to strengthen the organization's cybersecurity governance framework, manage cyber risks, and ensure compliance with regulatory, contractual, and industry security standards.
The successful candidate will play a key role in cybersecurity governance, risk management, audit readiness, third-party risk assessments, and continuous improvement of the organization's security posture across cloud, on-premises, and enterprise environments.
Key Responsibilities
- Develop, review, and maintain cybersecurity policies, standards, procedures, and security baselines.
- Conduct enterprise and project-level cybersecurity risk assessments.
- Manage and maintain the organization's cyber risk register, including risk identification, assessment, treatment, and tracking.
- Support compliance initiatives aligned with ISO 27001, NIST CSF, SOC 2, and other applicable security frameworks.
- Coordinate internal and external security audits, including evidence collection, remediation tracking, and gap assessments.
- Perform third-party and vendor cybersecurity risk assessments.
- Define, monitor, and report cybersecurity KPIs and KRIs.
- Support governance reporting and communicate cybersecurity risks to stakeholders and management.
- Collaborate with Infrastructure, Cloud, Security Operations, and business teams to promote security-by-design.
- Monitor changes in regulatory requirements and cybersecurity threats and assess their impact on governance and compliance.
- Maintain comprehensive documentation, policies, and compliance evidence repositories.
Requirements
- Bachelor's Degree in Cybersecurity, Information Technology, Computer Science, Information Security, or a related discipline.
- 6–10 years of experience in Cybersecurity Governance, Risk & Compliance (GRC).
- Strong knowledge of cybersecurity governance, risk management, and compliance practices.
- Hands-on experience supporting enterprise cybersecurity audits and regulatory compliance.
- Excellent analytical, documentation, communication, and stakeholder management skills.
- Ability to work independently while managing multiple compliance and governance initiatives.
Technical Skills
- Cybersecurity Governance
- Enterprise Risk Assessments
- Risk Registers & Risk Treatment
- ISO 27001 / ISO 27002
- NIST Cybersecurity Framework (CSF)
- CIS Controls
- SOC 2
- Internal & External Audit Support
- Control Assessment & Gap Analysis
- Third-Party & Vendor Risk Management
- Cloud Security Governance (Azure & AWS)
- Security Policies & Standards
- KPI / KRI Reporting
- GRC Platforms & Documentation Management
Preferred Certifications
- CISSP
- CISM
- CRISC
- CGEIT
- ISO 27001 Lead Implementer
- ISO 27001 Lead Auditor
Why Join Us?
- Opportunity to contribute to enterprise cybersecurity governance initiatives.
- Work with industry-recognized cybersecurity frameworks and standards.
- Collaborative environment focused on security, compliance, and continuous improvement.
- Competitive remuneration with potential for contract renewal.
We thank all applicants for their interest. Only shortlisted candidates will be contacted.
Pay: RM5,000.00 - RM10,000.00 per month
Work Location: In person