Information Security Analyst
ABA Bank · Phnom Penh, Cambodia
Apply & track with Apply EdgeJob PurposeThe Information Security Analyst supports the governance, risk, and compliance (GRC) aspects of information security, including risks associated with artificial intelligence (AI), ensuring alignment with regulatory requirements, internal policies, and established governance frameworks.The role contributes to the continuous improvement and operation of information security risk management, control assurance, and compliance processes, leveraging data analytics and AI‑enabled techniques where appropriate, and aligning with international best practices such as NIST and ISO standards, as well as national regulations and guidance including TCRMG.The position provides accurate risk analysis, compliance insights, and reporting to support effective oversight, assurance, and informed decision‑making by Information Security leadership and key internal stakeholders.LocationHead Office, Phnom Penh (03 Posts)Major Areas of ResponsibilitySupport the effective operation of the Bank’s information security governance, risk, and compliance (GRC) activities, including governance of artificial intelligence (AI) and data‑driven technologies, in line with approved frameworks and policies.Contribute to the ongoing enhancement and maintenance of information security and AI‑related GRC processes to ensure alignment with regulatory requirements, internal governance standards, and recognised international best practices (e.g. NIST, ISO).Perform and support assigned GRC activities, including reviews, assessments, and analysis of information security and AI‑related controls, and assist with the documentation, tracking, and follow‑up of identified issues.Maintain accurate, complete, and up‑to‑date information security and AI governance artefacts, including registers, assessments, policies, standards, and supporting documentation.Provide GRC input for projects, significant changes, new technologies, third‑party engagements, and AI initiatives to ensure governance, risk, and compliance considerations are addressed.Prepare clear, timely, and reliable information security and AI‑related GRC reporting and analysis to support management oversight and informed decision‑making.Qualifications & ExperienceBachelor’s or Master’s degree in Information Technology, Computer Science, Information Security, or a related technical or risk management discipline.One or more of CISSP, CISM, ISO27001, CRISC, CGRC, COBIT, COSO Minimum of 5 years’ professional experience in Information Technology, Information Security, or related fields, with demonstrable exposure to governance, risk, and compliance activities.Good working knowledge of information security and risk management frameworks and standards, such as NIST, ISO/IEC 27001/27005, COBIT, COSO, ISACA, and ISC².Hands‑on experience supporting the development, implementation, or maintenance of information security GRC processes, including risk assessments, compliance activities, policy management, or assurance support.Experience developing, reviewing, or maintaining information security documentation, such as policies, standards, procedures, risk registers, and assessment artefacts.Strong analytical skills with the ability to assess information, identify issues, and clearly summarise findings for reporting and follow‑up actions.Effective written and verbal communication skills, with the ability to engage constructively with technical and non‑technical stakeholders.High level of integrity, professionalism, and accountability, with a strong attention to accuracy and detail.Experience supporting audits, regulatory reviews, or internal assurance activities.Exposure to AI, data‑driven technologies, or technology risk governance is an advantage.