Information Security Governance, Risk and Compliance Specialist

🗓️ Posted 2026-09-08 Cyberjaya, Selangor, Malaysia Full-time Hybrid ICT

Company shared salary

NA

Market rate

RM6,000–RM10,000/mo (RM72,000–RM120,000/yr)

Based on similar roles (title + domain + location).

About the Company

Make an impact with NTT DATA Join a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion - it's a place where you can grow, belong and thrive. Your day at NTT DATA The Information Security Governance, Risk and Compliance (GRC) Specialist is a seasoned subject matter expert, responsible for supporting the organization's information security program by assessing risks, implementing security controls, ensuring compliance, managing security awareness initiatives, and contributing to policy development. This role collaborates with internal teams to enhance security practices and maintain a strong security posture.

Responsibilities

  • Implement, and maintain security compliance frameworks (e.g., Data Protection Trustmark, Cyber Trust Mark, ISO/IEC 27001, GDPR, PDPA) in accordance with company policies
  • Monitor adherence to internal security policies and procedures.
  • Collaborates with internal stakeholders to ensure compliance with industry standards and regulations
  • Conduct regular audits and assessments to identify gaps and recommend corrective actions
  • Review client contracts and vendor agreements to ensure cybersecurity and risk-related clauses are appropriately addressed
  • Participates in security awareness and training initiatives
  • Supports incident response activities and investigations as required
  • Ensure timely reporting of security incidents to regulators and clients as required
  • Monitors and reports on security compliance metrics
  • Assists in the implementation of security controls and best practices.
  • Stays updated with emerging security threats and trends
  • Performs any other related task as required
  • Seasoned familiarity with information security frameworks and standards in Singapore.
  • Seasoned understanding of risk assessment methodologies, compliance, and policy development.
  • Strong communication and interpersonal skills for effective collaboration.
  • Strong attention to detail and ability to follow established processes.
  • Seasoned project management skills for coordinating and implementing security initiatives.
  • Bachelor's degree or equivalent in Information Technology, Computer Science, Information Security, Risk Management or related field.
  • Prior experience in regulated industries (e.g. financial services, technology, healthcare, telecommunications) is highly desirable.
  • Seasoned experience (5 to 8 years) in information security or related roles.
  • Seasoned exposure to risk assessment, compliance, security awareness, or policy development is beneficial.