Description
We are seeking a detail-oriented Cyber Security Compliance & Risk Analyst to join our Cyber Security department (CyberStation), supporting information security governance, compliance, and risk management for enterprise clients across our international operating regions, including Southeast Asia.
In this role, you will support the implementation and maintenance of information security governance, compliance, risk, and control frameworks for regulated enterprise environments. You will work closely with the Security Governance Lead, client business units, technology teams, auditors, and regional stakeholders to drive governance initiatives, compliance activities, risk assessments, audits, and the continuous improvement of security controls.
This position requires strong analytical and documentation skills, working knowledge of international security and regulatory frameworks such as ISO/IEC 27001, PCI DSS and the ability to coordinate confidently with cross-functional and cross-border teams in a client-facing setting.
Job Responsibilities
1. Security Governance & Compliance
- Support the development, maintenance, review, and communication of information security policies, standards, procedures, and guidelines.
- Assist in monitoring compliance with applicable regulatory requirements, industry standards, and internal security policies.
- Support compliance activities relating to PCI DSS, RMiT, ISO/IEC 27001, and other applicable regulatory and security frameworks.
- Track regulatory updates across client operating jurisdictions and identify potential impacts on existing security controls and processes.
2. Risk & Control Management
- Assist in conducting security risk assessments, control reviews, and gap assessments.
- Support the identification, documentation, and tracking of security risks, control deficiencies, and remediation activities.
- Maintain risk registers, compliance trackers, control inventories, and governance documentation.
- Monitor and follow up on remediation plans to ensure timely closure of identified issues.
3. Audit & Assessment Support
- Coordinate and support internal audits, external audits, regulatory assessments, and certification activities.
- Prepare and maintain audit evidence, documentation, and supporting records.
- Track audit findings, recommendations, and corrective action plans through to closure.
- Liaise with internal and client stakeholders to obtain information required for audit and compliance reviews.
4. Governance Reporting & Documentation
- Prepare governance reports, compliance dashboards, metrics, and management updates.
- Maintain security governance documentation, including policies, standards, exceptions, and control records.
- Support the preparation of reports and presentations for management, audit, and compliance committees.
5. Awareness & Continuous Improvement
- Support security awareness and compliance training initiatives.
- Assist in reviewing security incidents, policy exceptions, and control deviations from a governance and compliance perspective.
- Recommend process improvements to strengthen governance, compliance monitoring, and control effectiveness.
- Perform other duties as assigned by the immediate supervisor.
Requirements
- Bachelor's Degree in Information Technology, Cybersecurity, Information Security, Risk Management, Computer Science, or a related discipline.
- Minimum 3 years of relevant experience in Information Security Governance, IT Compliance, IT Risk Management, IT Audit, or Cybersecurity.
- Working knowledge of PCI DSS, ISO/IEC 27001, NIST Cybersecurity Framework, COBIT, or equivalent standards.
- Hands-on experience supporting audits, compliance reviews, risk assessments, and remediation tracking.
- Familiarity with governance processes, policy management, and control monitoring activities.
- Strong analytical, documentation, coordination, and communication skills.
- Ability to work independently while collaborating effectively with regional and cross-functional teams.
- Excellent command of written and spoken English, suitable for direct engagement with international clients, auditors, and regulators.
Nice to Have
- Exposure to regulatory and compliance requirements within Malaysia, Thailand, and/or the Philippines.
- Professional certifications such as CISA, ISO/IEC 27001 Lead Auditor or Lead Implementer, CRISC, CISM, or PCI-related credentials (achieved or in progress).
- Experience working in or supporting regulated industries such as banking, financial services, fintech, or payments.
- Experience serving international clients from an offshore or distributed delivery model.
- Familiarity with GRC platforms and compliance management tools.
- Exposure to Bangladesh Bank Cybersecurity Framework, SOC 2, GDPR, or data protection regulations.