Assistant Manager - IT (Compliance)
genting energy- Posted 21 days ago
- Be among the first 10 applicants
Job Description
The Assistant Manager – IT (Compliance) is responsible for establishing and maintaining the organization's IT governance, risk management, compliance, and assurance framework to ensure that all technology systems, processes, and services operate in accordance with corporate policies, regulatory requirements, cybersecurity standards, and audit expectations.
Job Responsibilities:
1. IT Governance & Policy Ownership
- Develop, maintain, and enforce IT policies, standards, and procedures.
- Ensure alignment with corporate governance frameworks.
- Define control requirements applicable to infrastructure, systems, and data.
- Explore IT General Controls (ITGC) and ISO 27001.
2. IT Risk & Compliance Management
- Own IT risk identification, assessment, and treatment tracking.
- Maintain IT risk registers, control matrices, and compliance dashboards.
- Interpret regulatory and statutory IT requirements and translate them into control obligations.
3. Audit & Assurance (Primary Ownership)
- Act as primary IT liaison for internal and external audits.
- Coordinate audit walkthroughs, evidence collection, and control testing.
- Track audit findings, corrective action plans, and closure.
4. Cybersecurity Governance
- Own cybersecurity policies, access governance frameworks, and awareness programmes.
- Monitor security compliance posture and report to management.
- Ensure incident reporting, regulatory notifications, and postincident reviews are completed.
5. Access & Data Governance
- Define access control governance, approval workflows, and review cycles.
- Own periodic access reviews and privileged access governance.
- Oversee data classification, protection, and retention compliance.
6. Management & Operation Reporting
- Prepare IT compliance, risk, and audit status reports.
- Provide executivelevel summaries to management and operation team.
7. Change Management Governance
- Own and govern the IT Change Management framework, policies, and procedures.
- Ensure all IT changes (infrastructure, applications, security, configurations) comply with:
- Approved change approval workflows
- Segregation of duties requirements
- Documentation and impact assessment standards
- Review and validate:
- Change risk assessments
- Emergency and retrospective changes
- Change success and failure analysis
- Monitor adherence to change controls and report exceptions, trends, and risks to management.
- Ensure change records and evidence are auditready and retained in accordance with policy.
8. Contract & Vendor Compliance Management
- Govern ITrelated contracts from a compliance, risk, and control perspective.
- Review IT contracts to ensure inclusion of required clauses, including:
- Information security and data protection
- Regulatory and statutory compliance
- Righttoaudit and incident notification
- Business continuity and exit provisions
- Oversee vendor compliance obligations (security, audit, SLA, regulatory).
- Coordinate thirdparty IT risk assessments and ensure remediation of identified gaps.
- Track contract compliance milestones and escalate noncompliance issues.
Job Requirement:
- Bachelor's degree in information technology, Computer Science, Information Systems, Cyber Security, Business Information Systems, or related discipline.
- Professional certification (Microsoft, Security and Networking, Cloud)
- A strategic and analytical mindset.
- Dynamic thinking and problem-solving abilities.
- Knowledge of operating systems, current equipment and technologies, enterprise backup and recovery procedures, and system performance monitoring tools
- Knowledge of IT infrastructure, network and systems to effectively manage and troubleshoot issues.
- Excellent interpersonal skills.
- Minimum 8–12 years of IT experience, with at least 5 years in IT Governance, Risk, Compliance (GRC), Information Security, Internal Controls, or IT Audit.
- Proven experience managing IT compliance programs, risk management frameworks, and audit engagements.
- Experience supporting multi-site, multi-country operations within a corporate or group environment.
- Experience in managing external auditors, internal auditors, regulators, and third-party assessments.
- Hands-on experience in IT policy development, control frameworks, and compliance monitoring.
- Experience in vendor governance, contract management, and third-party risk management.
- Familiarity with ITIL-based service management and change management processes.
- Exposure to multi-entity, multi-country, or regulated environments is preferred.
- Willingness to work outside of normal business hours.
- Willingness to travel.
More Info
Key Skills
Control Frameworks
IT Policy Development
Vendor Governance
Change Management Governance
ITIL-based Service Management
Third-Party Risk Management
IT General Controls (ITGC)
System Performance Monitoring Tools
Enterprise Backup and Recovery Procedures
Audit Assurance
Contract Vendor Compliance Management
Microsoft Security and Networking Cloud
Cybersecurity Governance
Access Control Governance
Change Management Processes
