AI-generated summary
This job is part of AIA Digital+ focusing on IT Risk Management & Governance Compliance. You might like this job because it offers opportunities for growth and involves ensuring information security in a dynamic environment.
Undisclosed
Kuala Lumpur, MY-AIA Malaysia, Kuala Lumpur
AIA Digital+ is a Technology, Digital and Analytics innovation hub dedicated to powering AIA to be more efficient, connected and innovative as it fulfils its Purpose to help millions of people across Asia-Pacific live Healthier, Longer, Better Lives.
If you are hungry and driven to play an active role in shaping a better tomorrow, we want to hear from you. Because the work we do at AIA Digital+ makes a difference in the lives of millions of people, every day. We will equip you with the critical skills, tools and technology, and endless opportunities to learn, contribute and thrive in a dynamic and exciting environment.
If you want to shape a brighter future at AIA Digital+, please read on.
About the Role
This position is require to provide consultation and professional advice on key technology and information security risk matters. Thereby making valuable contributions to building a strong information security risk culture centred on people, processes and technology. The role will also coordinate regular governance review engagements and being involved in technology-related audit engagements for the abovementioned geographical locations. The role requires professional judgment and assessments on material to be provided by the various process and control owners for the audits.IT Risk Management & Governance Compliance
Consolidate and tracking all submitted risk deviation registration are being valid and closed timely.
Provide a day-to-day support and guidance to all queries needed related to risk registration.
Conduct the Pentest schedule initiatives and arrangement with Pentest Vendor.
Provide monthly Internal Vulnerability Assessment (IVA) Report to Senior Leader of Technology stakeholders.
Support on the IT Risk Management and Governance Compliance process and follow up action – this includes reporting/reminders of outstanding or overdue action required from risk/deviation registration system, Penetration test schedule, vulnerability assessment, and technology & governance management action items.
May be assigned to drive or support other initiative like security assessment services.
Audit and Regulatory Management
Support and responding to audit queries and to be involved in control assessment related to Risk Mgmt.
This is an individual contributor role, with opportunities for lateral development within the function.
Education
University degree or equivalent experience in one of the following or related disciplines (Computer Science, Computer Engineering, Information Security, Information Systems)
Experience
At least 3 years of relevant work experience, including at least 1 years of experience in IT audit, risk management, compliance and/or governance roles, with particular expertise and knowledge of governance reporting of technology risk issues and cybersecurity.
Rich working experience from financial industry, big tech firms or established auditing firms will be considered favorably
Experience and exposure in information security standards such as ISO27001, SOC2 or PCIDSS will be an advantage
Certifications/licenses
Preferably a holder of one or more of the following entry-level information security and audit qualifications: Security+, CEH
Candidates with advanced level qualifications such as CISSP, CISA, CRISC, CCSP will have added advantage
Special skills:
Good Communication, Coordination and Interpersonal Skills.
Good experience working alongside and opposite external auditors as well as regulatory bodies
Meticulous and analytical traits
Strong programme/Project Management skills
High drive, energy and good attitude over teamwork
High levels of professional integrity
Eagerness to learn and develop one’s knowledge in information security and computing, especially on emerging computing fields such as cloud security, DevSecOps, etc.
Attractive benefits provided :-
Medical insurance
Work life balance
Hybrid working arrangement
Learning & development
Unleash your potential and join us now!
Build a career with us as we help our customers and the community live healthier, longer, better lives.
You must provide all requested information, including Personal Data, to be considered for this career opportunity. Failure to provide such information may influence the processing and outcome of your application. You are responsible for ensuring that the information you submit is accurate and up-to-date.
We offer a range of wellbeing tools and programmes to help you think well, feel well, plan well and live well.
With our diverse up-skilling, mentorship, job mobility and career experiences, we will help shape your career, your way.
It's our differences that make us better together. We empower you to be your best and make a difference in your own unique ways.
Last active - few hours ago
0 - 10 Years of Experience