jobs in Johor Plantations Group Berhad

Johor Plantations Group Berhad Hiring! Full Time Cyber Security GRC Analyst in Johor - Ricebowl

Cyber Security GRC Analyst

Johor Plantations Group Berhad

Share
Save

Working Location

  • Johor Bahru Johor Malaysia

Job Description

Responsibilities

Requirements:


  1. Bachelor's degree in Information Systems, Cybersecurity, Computer Science, Information Technology, or a related discipline, with a CGPA of 3.00 and above and MUET Band 4 or equivalent.
  2. Up to 2 years of experience in GRC, IT audit, compliance, information security, or data protection; strong fresh graduates are encouraged to apply.
  3. Familiarity with ISO/IEC 27001, Malaysia's PDPA, and preferably exposure to NIST CSF 2.0 or related cybersecurity frameworks.
  4. Strong documentation, record-keeping, reporting, and Microsoft Office (Excel, Word, PowerPoint) skills; experience with GRC platforms is an added advantage.
  5. Methodical, detail-oriented, and process-driven, with the ability to coordinate across departments and drive tasks to completion.
  6. Strong communication, integrity, confidentiality, and professionalism, with a willingness to pursue relevant certifications and continuous development.


Job Responsibilities:


A. Governance & Documentation

  • Maintain cybersecurity policies, procedures, SOPs, and related documentation, including version control and annual review cycles.
  • Maintain the cybersecurity evidence repository.


B. Risk & Compliance

  • Maintain the information security risk register, including risk logging, score updates, and remediation follow-ups with treatment owners for Manager approval.
  • Conduct internal compliance checks against SOPs and document deviations as findings.
  • Coordinate VAPT and audit activities.
  • Maintain the open-items tracker and follow up on remediation activities, including the VAPT-before-go-live gate.


C. Security Operations Support

  • Maintain the incident register.
  • Perform first-line incident documentation and escalate decisions to the Cybersecurity Manager.
  • Support the CSIRP process and prepare post-incident reports.
  • Coordinate access reviews and asset register checks.
  • Operate the GRC platform for evidence management, control mapping, and status tracking.


D. Data Privacy (PDPA)

  • Maintain the Record of Processing Activities (ROPA).
  • Support Data Protection Impact Assessments (DPIAs).
  • Prepare consent forms, privacy notices, and data-handling documentation.
  • Log and track Data Subject Access Requests (DSARs) within statutory timelines.
  • Compile breach evidence for the Data Protection Officer (DPO).


E. Awareness & Reporting

  • Execute security awareness and phishing simulation campaigns.
  • Prepare compliance dashboards and reporting packs.
  • Coordinate governance meetings and record meeting minutes.
  • Track and follow up on action items arising from governance meetings.


Special Duties

  • Act as the operational focal point supporting the Data Protection Officer (DPO) function under the Personal Data Protection Act (PDPA) 2010, including the 2024 amendments.


Important Information

Never provide your bank or credit card details when applying for jobs. Do not transfer any money or complete unrelated online surveys. If you see something suspicious, Report this Job ad.

Learn More