أبلاي إيدج ابدأ البحث عن عمل

Auditor | Cyber Security & Regulatory

EPF Malaysia · Kota Damansara, Selangor, Malaysia

قدّم وتابع مع أبلاي إيدج
JOB SUMMARYSupport the Manager and Head of Unit, Cyber Security & Regulatory (HOU) in executing risk-based audit engagements by delivering assigned audit assignments, assessing cybersecurity and regulatory controls, and delivering data-driven assurance across digital technology environments, while supporting the development of audit methodologies, analytics-enabled audit practices, AI-driven initiatives and real-time continuous auditing to strengthen governance, risk management, and compliance.JOB RESPONSIBILITIESSupport the Manager and HOU in developing and executing risk-based annual audit plans, ensuring coverage of cybersecurity, regulatory compliance, and emerging technology risks aligned with organisational prioritiesExecute risk-based audit assignments across cybersecurity and regulatory domains in accordance with the Global Internal Audit Standards (GIAS) and EPF audit methodology.Support audit planning and execute audit fieldwork activities, including walkthroughs, control testing, and the documentation of audit evidence.Execute complex audit testing activities, including risk assessments, and the identification and evaluation of key technology risks and process controls.Evaluate the adequacy and effectiveness of cybersecurity and regulatory controls, including compliance with relevant laws, regulations, standards, and practices covering the Cyber Security Act, PDPA, ISO ISMS, network security, security monitoring, incident management, vulnerability management, cloud security, encryption, and vendor management.Apply risk-based audit testing procedures and document findings, control gaps, and root causes.Perform risk-based control testing and evaluate audit evidence to determine compliance with policies, procedures, standards and regulatory requirements, control gaps and root causes.Identify control deficiencies pertaining to cybersecurity and regulatory requirements, emerging risks and improvement opportunities through systematic analysis of processes, systems and supporting documentation.Execute audit across complex IT and hybrid environments.Assess the potential business impact of control weaknesses and support the development of practical and risk-based recommendationsPrepare and maintain audit working papers, document audit procedures, testing results, supporting evidence, and conclusions in accordance with audit quality and documentation standards.Prepare audit observations, reports, and management communications to communicate key findings, risks, and recommendations, and support informed decision-making.Coordinate audit issue validation sessions with auditees to ensure factual accuracy and root cause identificationPerform follow-up reviews to assess the adequacy and effectiveness of corrective actions implemented by management for closure tracking.Identify emerging cyber risks, regulatory changes, and technology threats for incorporation into audit execution activities.Ensure quality and accuracy of audit deliverables under supervision.Deliver assigned audit assignments within timelines and quality standards.Provide support in stakeholder engagement during audit engagements.Leverage data analytics and technology-enabled audit techniques to improve audit effectiveness, efficiency and coverage with insights generation.Support continuous auditing, automation, and AI-enabled audit initiatives.Support the enhancement of audit methodologies, audit programmes, testing techniques, and digital audit initiatives.Maintain current knowledge of technology risks, cybersecurity threats, industry developments, audit practices, and regulatory expectations relevant to technology assurance.Support continuous learning through structured training programmes, knowledge sharing and professional development certifications.Share knowledge, insights and best practices with team members to strengthen audit capability and technical competency.JOB COMPETENCIES & SKILLSStrong understanding of cybersecurity governance, IT audit, and risk assurance practices.Good knowledge in risk-based audit approach, execution, and emerging technology risk assessmentFamiliarity with industry frameworks, standards, and regulations, including GIAS, COBIT, ITIL, ISO 27001, NIST, CIS, the Cyber Security Act, PDPA, and BNM guidelines.Experience in network security, vulnerability management, incident management or cloud security audit review.Execute audits over security operations, monitoring, and incident management, aligned to defined assurance standards and maturity models.Support the application of continuous monitoring techniques and AI analyst over SIEM, SOAR, threat intelligence.Ability to analyse Vulnerability Assessment (VA) and Penetration Testing (PT) results, including evaluation of control effectiveness, KRIs, and residual risks.Good knowledge of network infrastructure, security configurations, security posture assessment, control effectiveness, and risk exposure analysis to support audit reviews and management decision-making.Experience in executing audit reviews on network security architecture, defence mechanisms, and third- party monitoring controls, considering emerging threats.Performed audit review in-line with regulatory and compliance requirements (GIAS, Cyber Security Act, PDPA, BNM RMiT, ISO ISMS/ITSM).Performed audit review on vendor risk management, control effectiveness, and performance monitoring practices.Knowledge on data analytics tools, digital audit techniques and AI tools.Utilize data analytics and technology-enabled audit techniques to support audit activities.Strong written and verbal communication skills, including audit documentation and report writing.Knowledge of cloud technologies, digital platforms and emerging technology risks is an advantageJOB REQUIREMENTSMalaysian citizenPass in Bahasa Melayu, including oral test in Sijil Pelajaran Malaysia (SPM) level or equivalent qualification recognised by the Government.Possess a Bachelor’s Degree in Information Technology, Cyber Security, Computer Science, Accounting, or an equivalent field recognized by the Government, from an accredited higher learning institution.Minimum 4 – 7 years of relevant experience in IT audit, Cybersecurity, Technology Risk Management, IT operations or related technology assurance functions.Possess professional certifications such as: a) CISA, CISSP, CISM, or CRISC (required). b) Additional cloud or cybersecurity certifications (e.g., CCSP, CEH) would be an added advantage.JOB STATUSPermanentAll applications are strictly CONFIDENTIAL, and only shortlisted candidates will be called in for interview. Applications are deemed UNSUCCESSFUL if there is no feedback from the EPF 2 MONTHS after the closing date of advertisement.