Overview
GRC Consultant – Information Security Jobs in Selangor, Malaysia at Condition Zebra (M) Sdn. Bhd.
Title: GRC Consultant – Information Security
Company: Condition Zebra (M) Sdn. Bhd.
Location: Selangor, Malaysia
About the Role:
We are seeking a results-oriented GRC & IT Security Audit Consultant to join our team. This role focuses entirely on the compliance, framework, and process controls side of IT Security. If you excel at designing risk strategies, leading compliance frameworks, and conducting comprehensive IT security audits, this position offers an excellent opportunity to manage client engagements with a high degree of autonomy.
Key Responsibilities:
● Lead IT Security Audits:
o Plan, scope, and execute comprehensive IT compliance and control audits. Develop audit checklists, test internal controls, and verify that processes align with governance standards.
● Audit Evidence Management:
o Manage and review client evidence request lists, ensuring that documentation, logs, and process artifacts meet strict compliance and audit trail integrity standards.
● ISO 27001 Implementation:
o Guide clients through the end-to-end implementation and maintenance of robust Information Security Management Systems (ISMS), helping them close gaps and prepare for formal ISO 27001 certification.
● Cyber Maturity Assessments:
o Evaluate and benchmark client security maturity levels against internationally recognized frameworks such as the NIST Cybersecurity Framework (CSF) and CIS Critical Security Controls.
● Data Privacy & Compliance (PDPA):
o Function as the primary advisor on data protection regulations, specifically the Malaysian Personal Data Protection Act (PDPA), leading data mapping exercises and Data Protection Impact Assessments (DPIAs).
● Risk Management & Governance:
o Conduct process-driven risk assessments to identify operational liabilities and policy gaps, maintain enterprise Risk Registers, and establish formal mitigation workflows.
● Third-Party Risk Management (TPRM):
o Execute vendor security risk assessments, evaluating third-party compliance profiles, reviewing security questionnaires, and analyzing SOC 2 reports.
● Policy Architecture & Reporting:
o Develop, review, and refine formal information security policies. Translate complex audit findings into clear, structured executive reports and actionable remediation roadmaps.
● Resilience & Awareness:
o Assist clients in designing and auditing Business Continuity (BCP) and Disaster Recovery (DR) plans, and deliver professional security awareness training to client staff.
Qualifications:
· Education: Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Business IT, or a related field.
· Experience: 3 to 5+ years of hands-on experience strictly within IT Security Auditing, GRC consulting, or Information Security risk management roles. Proven track record of managing client-facing projects autonomously.
· Framework & Regulatory Knowledge: Deep understanding of ISO 27001, NIST CSF, CIS Controls, and local regulations including the Malaysian PDPA.
· Possess at least one of the following industry-recognized certifications: CISSP, CISM, CISA, CRISC, CCSP, ISO 27001 Lead Auditor.
Skills & Competencies
● Audit & Control Mastery:
o Strong foundational understanding of audit cycles, internal control concepts, segregation of duties, and systematic evidence gathering.
● Professional Communication:
o Excellent written and verbal communication skills. Ability to clearly articulate complex risk and compliance exposure to both technical administrators and non-technical business leaders.
● Project Management & Autonomy:
o Proven ability to effectively manage multiple auditing and consulting projects simultaneously, prioritize tasks dynamically, and consistently meet rigid deadlines.
● Quality & Detail Focus:
o Uncompromising focus on accuracy, audit trail integrity, and delivering highly polished executive deliverables.
Benefits
- Competitive salary and comprehensive benefits package.
- Structured opportunities for professional growth, including financial support for advanced cybersecurity certifications and continuous education.
- Work within a dynamic, supportive, and highly collaborative team of cybersecurity and infrastructure specialists.
- A challenging and rewarding advisory environment with the opportunity to directly impact the resilience of prominent regional organizations.