11 часов назад
Information Security Analyst 5, Governance, Risk & Compliance (GRC) (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Information Security Analyst 5, Governance, Risk & Compliance (GRC) (Cybersecurity): Operating Sandisk’s enterprise information security risk management framework across corporate and manufacturing environments with an accent on risk assessments, ISO 27001 and NIST alignment, and regulatory readiness. Focus on identifying threats and vulnerabilities, driving risk treatment plans, improving security controls, and supporting audits across global operations.
Location: Batu Kawan, Penang, Malaysia; onsite at the Penang SDSM Office
Company
develops Flash memory and advanced storage technologies for people, businesses, and global manufacturing supply chains.
What you will do
- Implement and operate enterprise information security risk management practices aligned with ISO 27001 and NIST.
- Partner with manufacturing and operations teams in Penang to align cybersecurity requirements with operational realities.
- Lead technical and business process risk assessments across systems, applications, and operational processes.
- Develop and drive technical and non-technical risk treatment plans balancing security, compliance, and business objectives.
- Analyze security and risk data to identify trends, systemic issues, and opportunities for control improvement.
- Support internal and external audits, remediation activities, and the maintenance of security policies, standards, and procedures.
Requirements
- Bachelor’s degree in Information Security, Computer Science, or equivalent practical experience.
- 5+ years of progressive information security experience focused on risk management, security assessments, reporting, and metrics in an enterprise environment.
- Hands-on experience in at least one security domain, such as security engineering, network security, identity and access management, security operations, or application security.
- Ability to independently perform risk assessments across technical and business processes.
- Working knowledge of information security frameworks and standards, including ISO 27001 and NIST.
- Strong communication, stakeholder engagement, analytical, and risk-prioritization skills.
Nice to have
- Experience supporting manufacturing, operational technology, or globally distributed environments.
- Professional certifications such as CISSP, CISM, CRISC, GSNA, or equivalent.
- Technical certifications such as GCIH, GPEN, CEH, OSCP, or equivalent.
- Experience supporting compliance or audit activities in regulated or high-assurance environments.
Culture & Benefits
- Full-time exempt employment.
- Inclusive environment focused on diversity, belonging, respect, and contribution.
- Support is available for applicants with disabilities throughout the application and hiring process.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →