IT Senior Executive (Cybersecurity Risk & Policy)
Location: Kuala Lumpur (Fully onsite)
Employment Type: Contract (1 year initially, renewable up to additional 2 years based on performance)
Working Hours: 8:30 AM – 5:30 PM
Salary: RM9,000 – RM12,000/month (depending on experience and skill set)
Project commencement target: Early September.
We are looking for a Cybersecurity Risk & Policy Senior Executive to support cybersecurity governance, risk management, compliance monitoring, and security policy initiatives. The ideal candidate has experience in cybersecurity risk assessments, GRC processes, vendor risk management, and regulatory compliance.
Key Responsibilities
- Support the development, implementation, and enforcement of cybersecurity policies and standards.
- Conduct cybersecurity risk assessments and compliance monitoring activities.
- Manage third-party/vendor cybersecurity risk assessments and reviews.
- Support governance, risk, and compliance (GRC) activities using relevant tools.
- Monitor emerging cybersecurity threats, industry standards, and regulatory requirements.
- Track security compliance gaps and support remediation activities.
- Assist in cybersecurity awareness programs and initiatives.
- Prepare risk reports, compliance documentation, and management updates.
- Collaborate with internal teams and stakeholders on cybersecurity governance matters.
Skills & Requirements
- Minimum 5–7 years of experience in cybersecurity risk, governance, compliance, or related fields.
- Strong understanding of cybersecurity policies, risk frameworks, and compliance requirements.
- Experience conducting security risk assessments and compliance reviews.
- Experience managing third-party/vendor cybersecurity risks.
- Familiarity with GRC tools and cybersecurity governance processes.
- Knowledge of security standards, regulations, and best practices.
- Strong documentation, communication, and stakeholder management skills.
- Good analytical and problem-solving abilities.
Pay: RM9,000.00 - RM12,000.00 per month
Benefits:
- Opportunities for promotion
- Professional development
Application Question(s):
- Please share your notice period/availability.
- How many years of hands-on experience in cybersecurity risk assessment, policy development, or GRC activities you have?
Work Location: In person