Information Security Analyst 5, Governance, Risk & Compliance (GRC)
On-siteBatu Kawan, Penang, Malaysia
Job Summary
Implement and operate global, enterprise-wide information security risk management practices aligned with ISO 27001 and NIST standards. Serve as a primary security risk partner to manufacturing and operations teams, including acting as a liaison with teams in Penang to ensure cybersecurity requirements align with operational realities. Lead technical and business process risk assessments across systems, applications, and operational processes, identifying threats, vulnerabilities, and potential impacts to information and technology assets. Develop and drive the implementation of effective technical and non-technical risk treatment plans, balancing security, compliance, and business objectives. Collaborate with cross-functional stakeholders to embed risk management practices into projects, system implementations, and operational workflows. Analyze security and risk data to identify trends, systemic issues, and opportunities for control improvement. Partner with internal and external auditors to support security assessments, audits, and remediation efforts. Contribute to the development and maintenance of information security policies, standards, and procedures. Stay current on emerging threats, regulatory expectations, and best practices in information security and risk management.
Required Qualifications
- Bachelor's degree in Information Security, Computer Science, or equivalent practical experience
- 5+ years of progressive experience in information security, with demonstrated focus on risk management, security assessments, reporting, and metrics in an enterprise environment
- Hands-on experience in at least one technical security domain, such as security engineering, network security, identity and access management, security operations, or application security
- Proven ability to perform independent risk assessments across both technical and business processes
- Strong working knowledge of information security frameworks and standards, including ISO 27001 and NIST
Desired Qualifications
- Experience supporting manufacturing, operational technology (OT), or globally distributed environments
- Professional certifications such as CISSP, CISM, CRISC, GSNA, or equivalent
- Technical certifications such as GCIH, GPEN, CEH, OSCP, or equivalent
- Experience supporting compliance or audit activities in regulated or high-assurance environments
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.