jobs in Johor Plantations Group Berhad

全职 Cyber Security GRC Analyst 工作, 薪水, Johor Plantations Group Berhad Johor 公司招聘中 - Ricebowl

Cyber Security GRC Analyst

Johor Plantations Group Berhad

Undisclosed
分享
保存

工作地点

  • Johor Bahru Johor Malaysia

职位描述

岗位职责

Requirements:


  1. Bachelor's degree in Information Systems, Cybersecurity, Computer Science, Information Technology, or a related discipline, with a CGPA of 3.00 and above and MUET Band 4 or equivalent.
  2. Up to 2 years of experience in GRC, IT audit, compliance, information security, or data protection; strong fresh graduates are encouraged to apply.
  3. Familiarity with ISO/IEC 27001, Malaysia's PDPA, and preferably exposure to NIST CSF 2.0 or related cybersecurity frameworks.
  4. Strong documentation, record-keeping, reporting, and Microsoft Office (Excel, Word, PowerPoint) skills; experience with GRC platforms is an added advantage.
  5. Methodical, detail-oriented, and process-driven, with the ability to coordinate across departments and drive tasks to completion.
  6. Strong communication, integrity, confidentiality, and professionalism, with a willingness to pursue relevant certifications and continuous development.


Job Responsibilities:


A. Governance & Documentation

  • Maintain cybersecurity policies, procedures, SOPs, and related documentation, including version control and annual review cycles.
  • Maintain the cybersecurity evidence repository.


B. Risk & Compliance

  • Maintain the information security risk register, including risk logging, score updates, and remediation follow-ups with treatment owners for Manager approval.
  • Conduct internal compliance checks against SOPs and document deviations as findings.
  • Coordinate VAPT and audit activities.
  • Maintain the open-items tracker and follow up on remediation activities, including the VAPT-before-go-live gate.


C. Security Operations Support

  • Maintain the incident register.
  • Perform first-line incident documentation and escalate decisions to the Cybersecurity Manager.
  • Support the CSIRP process and prepare post-incident reports.
  • Coordinate access reviews and asset register checks.
  • Operate the GRC platform for evidence management, control mapping, and status tracking.


D. Data Privacy (PDPA)

  • Maintain the Record of Processing Activities (ROPA).
  • Support Data Protection Impact Assessments (DPIAs).
  • Prepare consent forms, privacy notices, and data-handling documentation.
  • Log and track Data Subject Access Requests (DSARs) within statutory timelines.
  • Compile breach evidence for the Data Protection Officer (DPO).


E. Awareness & Reporting

  • Execute security awareness and phishing simulation campaigns.
  • Prepare compliance dashboards and reporting packs.
  • Coordinate governance meetings and record meeting minutes.
  • Track and follow up on action items arising from governance meetings.


Special Duties

  • Act as the operational focal point supporting the Data Protection Officer (DPO) function under the Personal Data Protection Act (PDPA) 2010, including the 2024 amendments.


重要安全守则

申请工作时,切勿提供您的银行或信用卡详细资料。不要转账或完成无关的在线调查问卷。如果您发现可疑内容,请举报此招聘广告。

了解更多