Routiqo

Governance Risk and Compliance Senior

Hytech

  • Malaysia
  • Full-time

About Hytech

Hytech is a leading management consulting firm headquartered in Australia and Singapore, specialising in digital transformation for fintech and financial services organisations. We deliver end-to-end consulting services and provide robust middle- and back-office solutions that enable our clients to optimise operations, enhance efficiency, and stay ahead in a fast-evolving digital landscape.

With more than 2,000 professionals worldwide, Hytech has a strong and growing international presence, with offices across Australia, Singapore, Malaysia, Taiwan, the Philippines, Thailand, Morocco, Cyprus, Dubai, and beyond.

About Role

We are seeking a Cyber Security Governance Specialist to strengthen our group company’s cyber-security frameworks and risk posture. In this role, you will collaborate with internal teams and guide stakeholders on key security standards and frameworks, including:

  • ISO/IEC 27001
  • NIST Cybersecurity Framework (CSF) & NIST SP 800 series
  • PCI-DSS

Your work will ensure that governance, risk, and compliance (GRC) principles are embedded into business operations, enabling the company to maintain resilience, compliance, and trust.

Key Responsibilities

  1. Assess & Benchmark
  • Conduct cyber-risk and control-maturity assessments (NIST CSF, ISO 27001, Essential Eight, proprietary models).
  • Translate technical findings into executive-level insights and actionable roadmaps.
  1. Programme Design & Delivery
  • Build and embed cyber-risk programmes: risk registers, treatment plans, dashboards.
  • Develop policies, standards, and procedures that are both compliant and practical for engineers.
  1. Governance & Compliance
  • Own and maintain the GRC framework and policy stack; embed the three lines of defence.
  • Guide stakeholders through audits and regulatory reviews (e.g., APRA CPS 234, SOC 2).
  • Monitor regulatory changes and advise business stakeholders on impact within 30 days.
  1. Strategic Advisory
  • Develop multi-year cyber-security and risk strategies aligned to corporate OKRs.
  • Present risk posture, KPI/KRI trends, and investment options to boards and regulators.
  1. Leadership & Coaching
  • Mentor junior GRC analysts and upskill cross-functional teams on secure-by-design and offensive-security principles.
  • Foster a culture of continuous improvement and measurable risk reduction.

Qualifications & Experience

Essential

  • 3+ years in cyber-security, technology risk, or security consulting.
  • Hands-on delivery of ISO 27001 and PCI-DSS certification projects.
  • Experience guiding senior stakeholders through NIST CSF or equivalent reviews.
  • Working knowledge of offensive-security methodologies to inform strategic risk decisions.
  • Strong experience building risk registers, executive dashboards, and board reports.

Preferred / Nice-to-Have

  • Master’s degree in Cybersecurity, Risk, Business, or MBA.
  • Professional certifications: CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor.
  • Exposure to AI governance and data ethics (e.g., NIST AI RMF).
  • Prior line-management of GRC, security architecture, or penetration testing teams.

What We Offer

  • Easy access to public transportation (LRT & KTM).
  • Transportation allowance.
  • Corporate insurance coverage, including dental, optical, and outpatient claims.
  • Gym and fitness claims.
  • Ongoing training and development opportunities.
  • Exposure to exciting projects that support career growth and professional development.

Skills

  • Cybersecurity
  • Financial reporting
  • Risk assessment
  • Solution architecture