Summary
Responsible for conducting technology assurance reviews, managing audit processes, and ensuring compliance with internal policies and regulatory requirements. This role supports governance risk reporting, audit coordination, and continuous improvement of IT processes.
- This is a 6-months renewable contract
Key Responsibilities :
conduct detailed technology governance and assurance reviewsproduce good quality technology assurance review reportwork on requirements of governance risk reportingprepare and submit regulatory reportingliaison between Internal & External Auditors and Regulatory Bodies and IT Supporting Unitsensure accurate request for information (RFI) provided by IT Supporting Unitsreview and provide feedback on new updates arising from policies, framework, guidelinesstrategize the review of IT processes and operations to assess the effectiveness and efficiencyconduct Key Risk and Control Self-AssessmentKey Requirements :
Bachelor's Degree in Computer Science, Engineering, Information Systems or its equivalent.Minimum 8 to 10 years of related working experience. Knowledge of Cyber Security and IT security is essential. Industry certifications will be a plus e.g. CISA, CISM, CRISC, CISSP, CCSP etc.Highly result oriented and can work independently.Ability to build relationship and interact effectively with internal and external parties. Strong engagement skills with various stakeholders from business and technology units will be a plus.Good analytical, technical, written and verbal communication skills.At least 5 years or more hands-on experience on IT Audit, Technology Governance Assurance Reviews are required.Practical knowledge of security concepts, goals, technologies; security vulnerabilities, mitigation and remediation.Familiar with security standards and best practice; regulatory requirements such as BNM RMiT, MAS TRM, PCI-DSS, PayNet Guidelines on Cyber Resilience, Malaysia Cyber Security Act, PDPA etc; architecture and security of operating system; logging or auditing systems, including those on Operating System, databases and network device; Systems Development Life Cycle.