Grc Analyst
1 week ago
**Job Title**: GRC Analyst (U.S. Time Zone Support)
**Location**: Based in KL
**Time Zone**: U.S. Central or Eastern Time Zone (Full Coverage Required)
**About Us**:
At Sitecore, our mission is to simplify how brands reach, engage, and serve people by delivering intelligent, personalised digital experiences that connect the world. We empower the world’s most iconic brands to build lifelong relationships with their customers—seamlessly, smartly, and at scale.
As the leading provider of agentic digital experience software, Sitecore brings together content, commerce, and data into one composable platform that enables brands to deliver millions of meaningful, adaptive experiences every day. Trusted by global leaders such as American Express, Porsche, Starbucks, and L’Oréal, Sitecore helps brands transform engagement through experiences that are not only personalised but predictive and dynamic.
Our foundation is our people—a diverse, passionate, and collaborative global team spanning over 25 countries. We believe that every experience matters, and that belief starts with how we work together. Our values—empathy, accountability, clarity, and growth—guide how we lead, innovate, and connect. They are the behavior's that bring our mission and vision to life, every day, in every interaction.
**About the Role/ The Opportunity**:
We are looking for a detail-oriented and proactive GRC (Governance, Risk, and Compliance) Analyst to join our team. This role will be based in Kuala Lumpur and will support operations aligned with U.S. Central or Eastern time zones. The GRC Analyst will work closely with and support GRC Manager and the CISO, contributing to the day-to-day execution of compliance programs, audit preparation, risk assessments, and overall security governance efforts. This is a hands-on role, ideal for someone who thrives in a collaborative, fast-paced environment and is passionate about security, compliance, and risk management.
**What You’ll Do**:
**Governance & Compliance**
- Support the implementation and maintenance of compliance programs aligned with frameworks such as ISO 27001, SOC 2, HIPAA, PCI DSS, GDPR, TISAX, NIST, and IRAP.
- Assist in maintaining and updating security policies, procedures, and controls to ensure alignment with regulatory requirements.
- Conduct compliance reviews to identify gaps and assist in defining remediation actions.
- Monitor changes in regulatory requirements and provide input into compliance strategy and updates.
**Audit Support**
- Collaborate with internal stakeholders to coordinate audit-related activities, including evidence collection, documentation preparation, and status reporting.
- Maintain audit calendars, track deliverables, and ensure readiness for internal and external audits.
**Risk Management**
- Support periodic risk assessments, helping to identify, document, and track technology and process risks.
- Maintain the risk and findings register, ensuring items are regularly updated and monitored for progress.
**Cross-Functional Collaboration**
- Work closely with teams across Engineering, Product, Legal, Procurement, and Enterprise Technology to support compliance initiatives and ensure timely completion of action items.
- Provide ongoing support and clarity to teams on compliance tasks and expectations.
**Reporting & Documentation**
- Assist in preparing and delivering status reports, dashboards, and metrics on GRC activities for leadership and stakeholders.
- Ensure that compliance documentation is consistently updated and centrally stored (e.g., SharePoint, Confluence).
**What You Need to Succeed**
- Bachelor’s degree in information technology, Cybersecurity, or a related field.
- Familiarity with industry standards and frameworks such as ISO 27001, SOC 2, HIPAA, GDPR, PCI DSS, NIST, and others.
- 3-5 years of experience in a GRC, risk management, audit support, or compliance role in a technology-driven environment.
- Strong attention to detail, organizational skills, and ability to manage multiple tasks.
**What You Need to Succeed**
- Experience working across global teams and time zones is a plus.
- Certifications such as CISA, CRISC, or ISO 27001 Lead Implementer/Auditor are a plus.
- Comfortable using Microsoft 365 tools (e.g., Outlook, Teams, Excel, SharePoint) and collaboration platforms.
Sitecore is proud to be an equal opportunity workplace. We are committed to equal employment opportunity without unlawful regard to race, color, ancestry, religion, gender, national origin, sexual orientation, age, citizenship, marital status, disability, veteran status or any other local legally protected characteristic.
**How we hire**
At Sitecore, we put a lot of care and time into who we hire. We believe that in order to build the best products, we need to build high impact teams. Our recruitment process centers around what we call the Life Story interview, a conversational-style interview where we get to learn more about you.
-
Business Controls Analyst
2 weeks ago
Kuala Lumpur, Malaysia British American Tobacco Full time**BAT is evolving at pace - truly like no other organisation.** **To achieve the ambition, we have set for ourselves, we are looking for colleagues who are ready to live our ethos every day. Come be a part of this journey!** **BAT DIGITAL BUSINESS SOLUTION** **IS LOOKING FOR BUSINESS CONTROLS ANALYST** **SENIORITY LEVEL**:Non Management **FUNCTION**: Digital...
-
T&T Consultant
3 days ago
Kuala Lumpur, Kuala Lumpur, Malaysia Deloitte Full time 60,000 - 120,000 per yearDate: 23 Nov 2025Service Line / Portfolios: Enterprise Technology & PerformanceLocation:Kuala Lumpur, MYAre you ready to unleash your potential?At Deloitte, our purpose is to make an impact that matters for our clients, our people, and the communities we serve.We believe we have a responsibility to be a force for good, and WorldImpact is our portfolio of...
-
Team Lead, IT Security
1 day ago
Kuala Lumpur, Kuala Lumpur, Malaysia iForte Group Full timeContract duration: 12 months (Convertible to permanent)Job OverviewThe Supervisor, IT Security & GRC, will lead the organization's cybersecurity and governance team, ensuring that both technical defences and compliance frameworks are effectively implemented, monitored, and continuously improved. This role provides leadership across IT Security Operations and...
-
Security Analyst
2 weeks ago
Kuala Lumpur, Kuala Lumpur, Malaysia CARSOME Full time 60,000 - 120,000 per yearAbout YouThe Security Analyst II is responsible for day-to-day cybersecurity operations, including monitoring alerts, investigating incidents, validating endpoint hygiene, and ensuring timely execution of remediation plans. The role serves as a tactical executor under the direction of the Senior Manager, Cybersecurity and in coordination with the SOC and...
-
Security Specialist 9204
1 week ago
Kuala Lumpur, Malaysia AMK Technology Sdn Bhd Full time**Role Title** **Security Specialist** **Experience Requirement** **Minimum: 3 years** **Core Security Skills** - Threat Detection & Incident Response - Vulnerability Management - Identity & Access Management (IAM) - Security Operations (SecOps) - Governance, Risk & Compliance (GRC) - Cloud Security - Data Protection & Data Loss Prevention (DLP) -...
-
IT Governance, Risk
1 week ago
Kuala Lumpur, Malaysia Petron Malaysia Full time"At Petron, we are not just in the business of oil, we are also in the business of fueling lives."_ Petron Malaysia is an emerging and rapidly evolving Asian oil company. It is part of Petron Corporation which is the leading oil company in the Philippines. Our integrated refining, distribution, and retailing of world-class petroleum products help meet the...
-
Information Technology Security Analyst
2 weeks ago
Kuala Lumpur, Malaysia Agensi Pekerjaan Language Talent Solutions Sdn. Bhd. Full time**Purpose of Role** **Key Duties and Responsibilities** - The Security Analyst will work professionally under the general guidance of the System Engineer as part of a cross-functional team to undertake the following general activities. - Oversee the implementation and maintenance of GRC frameworks and standards. - Conduct regular risk assessments and audits...
-
Cybersecurity Governance
1 week ago
Kuala Lumpur, Malaysia Nexperia Germany GmbH Full timeAbout the role The Cybersecurity Governance & Process Analyst is a key role responsible for establishing, maintaining, and overseeing the cybersecurity governance framework and operational processes across the organization. This position ensures that cybersecurity risks are properly identified, assessed, and managed in alignment with business objectives...
-
Regional Compliance Manager
1 week ago
Kuala Lumpur, Malaysia British American Tobacco Full time**BAT is evolving at pace into a global multi-category business. With products like VELO, VUSE and GLO we are on a mission to decrease the health impact of our industry** **To achieve our ambition, we are looking for colleagues who are ready to Be The Change. Come, join us on this journey!** **British American Malaysia exciting opportunity for a Regional...
-
Prism Support Lead
1 week ago
Kuala Lumpur, Malaysia Prudential plc Full timePrudential’s purpose is to be partners for every life and protectors for every future. Our purpose encourages everything we do by creating a culture in which diversity is celebrated and inclusion assured, for our people, customers, and partners. We provide a platform for our people to do their best work and make an impact to the business, and we support...