It Security Compliance Analyst - Malaysia

Nintex Nintex · Enterprise · Kuala Lumpur, Malaysia · IT

This role is for an IT Security Compliance Analyst responsible for executing and sustaining a company's compliance program. The analyst will work with globally distributed departments to implement compliance requirements, enable audit readiness, coordinate compliance activities, and support audits. Key responsibilities include domain knowledge and documentation, global stakeholder management, adherence to standards, and risk management. The role requires at least 5 years of experience with common compliance frameworks like SOC 2, ISO 27001, GDPR, and HIPAA.

What you'd actually do

  1. Coordinate the full compliance lifecycle, including gap analysis, remediation planning, audit execution, and continuous compliance monitoring.
  2. Collaborate with globally distributed stakeholders across Engineering, IT, Product, HR, Legal, and other business functions to support consistent implementation of compliance requirements.
  3. Support adherence to Nintex governance, risk, and compliance standards by assisting with the creation, review and updates of information security policies and procedures.
  4. Support risk management activities by assisting with security reviews and compliance risk assessments for new initiatives, technologies, and vendors.

Skills

Required

  • Bachelor’s degree in Information Security, Information Technology, Risk Management, Business, or a related field, or equivalent practical experience.
  • Proven track of at least 5 years working experience with common compliance and assurance frameworks such as SOC 2, ISO/IEC 27001, GDPR, HIPAA, FedRAMP, or similar international regulatory standards.
  • Familiarity with common IT infrastructure, SaaS based cloud services, identity and access management concepts, and security tooling sufficient to assess control design and operational effectiveness

Nice to have

  • Relevant certifications are preferred but not required, including: CISA, CRISC, CISSP, CCSK, ISO 27001 Lead Implementer/Auditor, or related compliance or risk certifications.

What the JD emphasized

  • at least 5 years of experience
  • common compliance and assurance frameworks such as SOC 2, ISO/IEC 27001, GDPR, HIPAA, FedRAMP, or similar international regulatory standards