Information Security & Compliance
Empresaria Group PLC ·www.empresaria.com
Apply directMonroe Consulting Group, an Executive Recruitment firm, is partnering with a leading organisation in the Information Technology sector to hire an Information Security & Compliance Manager. This opportunity is based in Kuala Lumpur, Malaysia.
Position Overview
Lead the design, implementation, and governance of the organisation's information security and compliance framework across multiple business operations.
Drive security maturity, regulatory compliance, risk management, and certification readiness while embedding security best practices across the organisation.
Key Responsibilities
Certification & Standards Readiness
- Lead end-to-end preparation for ISO 27001 (ISMS), PCI-DSS, and other relevant certifications, including gap analysis, control implementation, documentation, internal audits, and coordination with external certification bodies.
- Ensure ongoing compliance with recognised security and governance standards.
Policy & Process Standardisation
- Design, document, and implement information security policies, procedures, and controls.
- Establish practical and effective governance frameworks that support business and technology operations.
Risk Management
- Conduct periodic risk assessments across technology and operational environments.
- Maintain risk registers and drive remediation activities with relevant stakeholders.
- Monitor security risks and recommend appropriate mitigation strategies.
IT Compliance & Audit
- Support IT compliance initiatives, including vendor risk assessments, access control reviews, data governance audits, and regulatory compliance requirements.
- Coordinate audit activities and ensure readiness for external reviews and assessments.
Data Protection & Governance
- Develop and manage data classification, retention, handling, and disposal policies.
- Oversee data governance practices, third-party data processing controls, and cross-border data management requirements.
- Ensure compliance with applicable data privacy and protection regulations.
Stakeholder & Cross-Functional Collaboration
- Partner closely with Engineering, IT, Legal, HR, and business stakeholders to embed security and compliance requirements into business operations.
- Drive consistency and standardisation of security practices across multiple business units and locations.
- Serve as the primary liaison for external auditors, certification bodies, and customer security assessments.
Security Awareness & Incident Readiness
- Develop and deliver security awareness and compliance training programmes.
- Establish incident response processes, governance frameworks, and operational playbooks.
- Support organisational readiness for security incidents and compliance requirements.
Key Requirements
Qualifications & Experience
- 5-8+ years of experience in Information Security, IT Compliance, Governance, Risk & Compliance (GRC), or related disciplines.
- Proven hands-on experience leading organisations through ISO 27001, PCI-DSS, or equivalent certification programmes.
- Experience building, implementing, or standardising security and compliance frameworks across multiple entities or locations.
- Experience working within technology, software, digital services, fintech, or similarly regulated environments.
- Relevant certifications such as CISSP, CISM, CISA, ISO 27001 Lead Implementer/Auditor, or PCI-DSS ISA/QSA are advantageous.
Technical / Functional Expertise
- Strong expertise in ISO 27001, PCI-DSS, and information security governance frameworks.
- Experience in risk management, audit management, compliance monitoring, and control implementation.
- Solid understanding of IT systems, cloud infrastructure, and application security principles.
- Experience with data protection, data governance, data classification, retention policies, and privacy regulations.
- Knowledge of vendor risk management, access control reviews, and third-party security governance.
- Experience developing incident response processes, security policies, and operational standards.
- Familiarity with regional and international data protection regulations, including PDPA, GDPR, and related compliance frameworks.
Soft Skills & Leadership Competencies
- Strong stakeholder management and cross-functional collaboration abilities.
- Excellent communication and presentation skills.
- Strong analytical thinking and problem-solving capabilities.
- Ability to influence and drive compliance initiatives across technical and non-technical teams.
- High attention to detail and strong governance mindset.
- Self-driven with the ability to operate independently and manage multiple priorities.
- Strong organisational and project management skills.
- Fluency in English; additional language capabilities are advantageous.
Frequently asked questions
Who is hiring for the Information Security & Compliance role?
Empresaria Group PLC is hiring for the Information Security & Compliance position, a Shazamme client. Apply directly on the employer's career site.
Where is the Information Security & Compliance job located?
The Information Security & Compliance role with Empresaria Group PLC is based in Kuala Lumpur, MY.
Is the Information Security & Compliance role full-time or contract?
This is a full time position at Empresaria Group PLC.
What experience level is the Information Security & Compliance role?
The Information Security & Compliance position is aimed at mid-level candidates.
How do I apply for the Information Security & Compliance role at Empresaria Group PLC?
Apply directly on Empresaria Group PLC's career page via the Apply button on this listing. ZammeJobs links straight through to the employer's ATS — no third-party form, no resume database.