Information Security Compliance Analyst

🗓️ Posted 2026-08-31 Kuala Lumpur, Federal Territory of Kuala Lumpur, Malaysia Full-time Hybrid ICT

Company shared salary

NA

Market rate

RM4,500–RM8,000/mo (RM54,000–RM96,000/yr)

Based on similar roles (title + domain + location).

About the Company

Please note that we will never request payment or bank account information at any stage of the recruitment process. As we continue to grow our teams, we urge you to be cautious of fraudulent job postings or recruitment activities that misuse our company name and information. Please protect your personal information during any recruitment process. While Monks may contact potential candidates via LinkedIn, all applications must be submitted through our official website (monks.com/careers). As an Information Security Compliance Analyst, your core responsibility will be to ensure the organization's strict adherence to all pertinent regulations and standards. Your critical role will involve safeguarding customer and company data, protecting the company's reputation,and making vital decisions that are integral to shaping the state-of-the-art security posture for the business's future success. This person should understand the risk assessment process to detect new threats, contribute in the action plan development and promote the progress of control implementation and evolution. The position will cover compliance activities, third parties risk assessments, management of clients requirements, internal awareness and technical controls evaluation. As a valuable member of our Global Infosec Team, you will have the opportunity to collaborate with colleagues across the globe, fostering a dynamic and diverse work environment. Your role will involve working closely with stakeholders from various departments, forging strong partnerships to ensure the collective success of our information security initiatives.

Responsibilities

  • Lead the alignment to the global ISMS (based on ISO27001:2022) over the APAC region.
  • Integrate the compliance efforts in the region with the global roadmap.
  • Perform routine activities to evaluate compliance with security frameworks and legislation.
  • Report the compliance status of processes and technology in the region.
  • Identify risk related to information security in the technical environment, the relationships with third parties or any component of the company's operations.
  • Define security measures to lower the risks identified.
  • Understand about technical and administrative controls in the different areas: networking, operations, access management, SSDLC, cloud security, end-point protection, physical security, third party risk assessment, organization security and legal compliance.
  • Coordinate the information security assessments with 3rd parties (clients, suppliers).
  • Contribute in the development of awareness material and the process of delivery and measurement.
  • Coordinate and reply to internal and external audits related to information security.
  • Investigate on technologies that could improve the security baseline and the compliance (e.g. DLP, end-point protection, network security, security and vulnerabilities assessment).
  • Empower, assist, and mentor fellow members of the team to foster their professional growth and ensure collective success.

Requirements

  • Bachelor's degree in Computer Science, Computer or Systems Engineering or equivalent.
  • Minimum of 5 years of experience in InfoSec related positions.
  • Solid knowledge of security on networking, cloud, infrastructure configuration, end-point protection and SDLC.
  • Knowledge of the standards ISO 27001/2, SOC2, NIST-800.
  • Professional working proficiency in written and spoken English
  • Ability to confidently present findings to those with either a technical or non-technical background.
  • Self-directed, resourceful, and a critical thinker with attention-to-detail and proactive problem-solving skills.
  • Ability to self-organize and plan activities with commitment towards results.
  • Ready to learn new contents both from others or self-learned.
  • Looking forward to self-improvement and suggesting improvements to processes or activities.
  • +4 year of dedicated experience in any of the following areas:
  • Security Risk Management
  • Security Consultant
  • Security/IT ISO implementer
  • Information Security Certification (e.g. CISSP, CCSP, CISM, AWS Security Specialist, etc)