Назад
Company hidden
11 часов назад

Information Security Analyst 5, Governance, Risk & Compliance (GRC) (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Malaysia
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Information Security Analyst 5, Governance, Risk & Compliance (GRC) (Cybersecurity): Operating Sandisk’s enterprise information security risk management framework across corporate and manufacturing environments with an accent on risk assessments, ISO 27001 and NIST alignment, and regulatory readiness. Focus on identifying threats and vulnerabilities, driving risk treatment plans, improving security controls, and supporting audits across global operations.

Location: Batu Kawan, Penang, Malaysia; onsite at the Penang SDSM Office

Company

hirify.global develops Flash memory and advanced storage technologies for people, businesses, and global manufacturing supply chains.

What you will do

  • Implement and operate enterprise information security risk management practices aligned with ISO 27001 and NIST.
  • Partner with manufacturing and operations teams in Penang to align cybersecurity requirements with operational realities.
  • Lead technical and business process risk assessments across systems, applications, and operational processes.
  • Develop and drive technical and non-technical risk treatment plans balancing security, compliance, and business objectives.
  • Analyze security and risk data to identify trends, systemic issues, and opportunities for control improvement.
  • Support internal and external audits, remediation activities, and the maintenance of security policies, standards, and procedures.

Requirements

  • Bachelor’s degree in Information Security, Computer Science, or equivalent practical experience.
  • 5+ years of progressive information security experience focused on risk management, security assessments, reporting, and metrics in an enterprise environment.
  • Hands-on experience in at least one security domain, such as security engineering, network security, identity and access management, security operations, or application security.
  • Ability to independently perform risk assessments across technical and business processes.
  • Working knowledge of information security frameworks and standards, including ISO 27001 and NIST.
  • Strong communication, stakeholder engagement, analytical, and risk-prioritization skills.

Nice to have

  • Experience supporting manufacturing, operational technology, or globally distributed environments.
  • Professional certifications such as CISSP, CISM, CRISC, GSNA, or equivalent.
  • Technical certifications such as GCIH, GPEN, CEH, OSCP, or equivalent.
  • Experience supporting compliance or audit activities in regulated or high-assurance environments.

Culture & Benefits

  • Full-time exempt employment.
  • Inclusive environment focused on diversity, belonging, respect, and contribution.
  • Support is available for applicants with disabilities throughout the application and hiring process.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →