CrawlJobs Logo

Assistant Manager - Risk, Control & Compliance (Security)

https://www.ikea.com Logo

IKEA

Location Icon

Location:
Malaysia , Kuala Lumpur

Category Icon

Job Type Icon

Contract Type:
Not provided

Salary Icon

Salary:

Not provided

Job Description:

Assistant Manager - Risk, Control & Compliance (Security) position at MyTOWN Shopping Centre in Kuala Lumpur, Malaysia. The role involves leading the Security department, ensuring compliance with safety and security procedures, managing emergency response, conducting risk assessments, and overseeing security systems and personnel.

Job Responsibility:

  • Develop a close working relationship with local government official i.e Police Force Department, Fire & Rescue Department and Special Service Department
  • Coordinate with other Department in handling emergency situations and to ensure the security of visitors, co-workers and contractors in the mall and developing leadership with a conscious approach to identifying and implementing systems to detect, analyse, and reduce business loss, and financial impact, and prevent incidents and accidents
  • Risk assessment to be conducted for all business functions
  • Manage and provide monthly reporting on the performance of the outsourced security guards and auxiliary police unit
  • To lead Security department in all aspects of security controls and system in compliance to MyTOWN’s safety & security procedures
  • Manage and monitor the functionality of the Fire Control Room and all the system in place i.e. Fire Protection System, PA System, Fire-Man Intercom, CCTV, Lift & Elevator controls and etc
  • Ensure all servicing, checklist reports, follow up and closure are compiled accordingly
  • Enforce all safety and fire rules in the mall i.e. Sec-Check inspection and audit
  • Develop and implement strategy for continuous security improvement in the mall
  • Responsible for the overall CAPEX and OPEX Budget planning for security department
  • Handling, investigating and preparing timely reports of any safety & security incidents in the mall
  • Reviewing Loss and Found reports and takes follow-up action when necessary
  • Ensures high security are maintained in all areas under surveillance and to drive risk topics regarding potential operational challenges in the units including implementation of the crowd management plan, traffic plan, process gaps, and risk exposure
  • To ensure the unit is meeting compliance requirements by achieving positive results for all internal and external audits such as Sec Check, insurance , process audit and authorities’ inspections and coordinate with the unit Emergency Response Team and management for the handling of any emergency cases and provide appropriate actions according to the unit Emergency Management Plan
  • Ensure that all the Auxiliary Police unit and Security Personnel are trained and familiar with firefighting procedures, theft handling procedures, bomb threat, incident threat etc. in accordance to MyTOWN’s Safety & Security procedures and government rules and regulations
  • Educate and ensure all co-workers and external service providers on all aspects of the MyTOWN’s Code of Conduct, Anti-corruption & Bribery Policy, operational procedures, and local legislation relating but not limited to health, safety and security, and the environment, cultivating a culture of transparency and ethical conduct

Requirements:

  • Minimum bachelor’s degree in occupational health/safety, Environmental Engineering or a related field
  • 10+ years of experience in a similar or compliance role in retail or related industries (minimum with 5+ years in managerial level)
  • Ability to communicate confidently and clearly in English and Malay (written and verbally)
  • Familiar and understand the Auxiliary Police Force Act and Police Act 1967
  • Experience with incident reporting and claims handling process with insurance company
  • Experience in managing FCC and security guards and able to influence and develop people and act as a role model and coach
  • Self-reliant and motivated with proven ability to work as part of a team as well as independently
  • Experience dealing with fire drills, system testing, crisis management, investigating fraud and unethical behaviours
  • Strong management, and leadership experience and a self-starter with a positive mindset
  • Experience in setting and implementing long-term strategic plans, setting budgets, and following up goals
  • Ability to read and understand legal and technical documents with strong technical knowledge of security and safety systems
  • Experienced in investigating fraud and unethical behaviours
  • Working knowledge of MS Office computer programs (PowerPoint, Word, and Excel)

Nice to have:

A background as a police or military officer is highly valued

Additional Information:

Job Posted:
January 18, 2026

Employment Type:
Fulltime
Work Type:
On-site work
Job Link Share:

Looking for more opportunities? Search for other job offers that match your skills and interests.

Briefcase Icon

Similar Jobs for Assistant Manager - Risk, Control & Compliance (Security)

Security Governance Risk & Compliance (GRC) Analyst

Here at Virtru you’ll help build a cutting edge security compliance program alig...
Location
Location
United States , Washington, DC
Salary
Salary:
130000.00 - 180000.00 USD / Year
virtru.com Logo
Virtru
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Minimum of 5+ years of information security, IT audit and/or IT Risk Management, or GRC Analyst/Engineer experience
  • Deep understanding of at least few of the following: CMMC, NIST 800-53 & 800-171, FedRAMP, SOC 2, PCI, and/or other global privacy compliance frameworks
  • Technical acumen. Strong understanding of modern cloud technologies (AWS, GCP, Azure, etc.) and familiarity with GRC tools (Hyperproof, Vanta, Drata, etc) and SIEM tools (Datadog, Splunk)
  • You’re a relationship builder and have worked with both business and technical risk and understand how to translate risk to various levels of the organization
  • Have experience training and coaching teams to become better security and privacy practitioners
  • Like working on an autonomous agile team
  • Ability to resolve conflicts and drive issues to completion
  • Work independently with little or no supervision while maintaining a high level of efficiency
  • Hands on experience deploying and managing vulnerability scanning/cloud security posture management tools (Wiz, Prismacloud, etc.) to meet security compliance requirements
  • Real-world IR experience participating on security On-Call teams
Job Responsibility
Job Responsibility
  • Manage and implement complex controls frameworks for large systems, consisting of Cloud infrastructure and Software as a Service (SaaS) services (GCP, AWS, GitHub, Okta, etc)
  • Design and develop automation solutions for evidence collection across Cloud infrastructure, endpoints, and SaaS services
  • Conduct risk assessments across business units and processes. Identify risk findings and recommend remediation and risk mitigation strategies
  • Assist or implement automated controls to support risk mitigation efforts across various business units with stakeholders
  • Incorporate CMMC certification into Virtru’s slate of compliance assessments and ongoing monitoring activities (FedRAMP, SOC 2, PCI)
  • Facilitate the third-party vendor on-boarding and annual review process by evaluating the security of current and prospective partners
  • Participate in incident response (IR) activities, providing risk analysis and remediation support as needed
  • Enhance the team with your individualism, spirit, and love of learning
What we offer
What we offer
  • A Flexible PTO policy
  • A $1,500 annual Learning & Development Stipend
  • Frequent company-sponsored team celebrations
  • Access to an Employee Assistance Program
  • Access to Headspace, a mental health app
  • A flat 3% contribution to your retirement account
  • A high degree of flexibility
  • Competitive compensation
  • Generous parental, medical, and bereavement policies
  • 401K contribution and stock options
  • Fulltime
Read More
Arrow Right

Risk & Controls Manager

FloQast is looking for a Risk & Controls Manager to join our growing InfoSec & C...
Location
Location
India , Pune
Salary
Salary:
Not provided
floqast.com Logo
FloQast
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Bachelor’s degree
  • 6+ years of experience in compliance, risk management, information security, or a related field, with SaaS industry experience preferred
  • Strong general compliance expertise, including areas such as privacy, security, and IT general controls
  • Familiarity with compliance frameworks such as ISO, SOC, and SOX standards
  • Strong communication and interpersonal skills, with the ability to collaborate effectively across global teams and time zones
  • Highly organized, detail-oriented, and proactive in identifying and addressing compliance risks
  • Flexible and adaptable in a high-growth, fast-paced environment
Job Responsibility
Job Responsibility
  • Serve as a risk and controls advisor for FloQast’s India operations, acting as an internal resource for compliance-related questions and initiatives
  • Support FloQast’s security and compliance programs by ensuring adherence to applicable ISO, SOC, and SOX standards
  • Collaborate with internal stakeholders to review, maintain, and align documentation, policies, and procedures with audit and regulatory expectations
  • Conduct and document compliance impact assessments, covering risk, privacy, and AI considerations to support organizational decision-making
  • Assist with the intake and evaluation of product roadmap changes, customer success initiatives, and consulting partner engagements to identify potential compliance risks and propose mitigations
  • Coordinate vendor reviews and assist with procurement needs in support of third-party risk management activities
  • Evaluate and track control objectives specific to India operations, ensuring alignment with enterprise compliance frameworks
  • Respond to compliance-related inquiries from internal teams with clear, actionable guidance
  • Oversee resiliency risk for FloQast’s India operations, ensuring readiness for potential business disruptions and alignment with enterprise business continuity practices
  • Assist with business continuity planning activities, including maintaining documentation and supporting periodic plan reviews
  • Fulltime
Read More
Arrow Right

Assistant Vice President, JANA & Asia South Securities Settlement In-Business Risk & Control

Assistant Vice President role in JANA & Asia South Securities Settlement In-Busi...
Location
Location
Hong Kong , Kowloon
Salary
Salary:
Not provided
https://www.citi.com/ Logo
Citi
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Minimum of 5-8 years of experience in operational risk management, compliance, audit, or other control-related functions in the financial services industry
  • Ability to identify, measure, and manage key risks and controls within Securities Settlement Lifecycle
  • Strong problem-solving, decision-making skills, verbal and written communication skills, with a demonstrated ability to engage at the senior management level
  • Ability to manage multiple tasks and priorities
  • Bachelor's/University degree or equivalent experience
Job Responsibility
Job Responsibility
  • Execute comprehensive risk assessments, including the analysis of Operational and Compliance risks in alignment with the firm's appetite, evaluating control efficacy, and producing management metrics and presentations
  • Manage the end-to-end lifecycle of control issues, from identification and root cause analysis to designing strategic risk mitigation solutions, overseeing remediation, and validating their effectiveness to prevent recurrence
  • Conduct in-depth analysis of escalated operational risk events, as required, and propose effective remediation strategies, including process optimization, client service enhancements, or technology infrastructure upgrades
  • Advise management on the application of existing and new firm wide policies and standards and ensure management are aware of procedural changes and that these changes are implemented correctly within defined timelines
  • Interact with Markets 1LOD teams, Operational Risk Management, Compliance, Internal Audit and other functions to provide deliverables and business insight
  • Be involved in operations of governance meetings, including coordinating meetings, managing agendas, and ensuring follow-up on action items
What we offer
What we offer
  • Access to telehealth options, health advocates, confidential counseling
  • Expanded Paid Parental Leave Policy
  • Programs to help employees balance their work and life, including generous paid time off packages
  • Resources and tools to volunteer in the communities
  • Access to an array of learning and development resources
  • Programs and services for physical and mental well-being
  • Fulltime
Read More
Arrow Right

Legal Third-Party Management and Information Security Risk Lead

As part of the Legal Outside Counsel, Third Party Management and Operations team...
Location
Location
United Kingdom , Belfast
Salary
Salary:
Not provided
https://www.citi.com/ Logo
Citi
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Ability to assess residual risk in complex vendor environments and make sound defensible recommendations
  • Experience applying risk-based frameworks to prioritize issues and mitigation efforts
  • Strong interpersonal skills for engaging legal, compliance, technology, procurement and senior risk stakeholders
  • Proficiency in creating clear and concise reports dashboards and governance experience
  • Leading or supporting cross functional projects, ability to support risk transformation initiatives, and integrate evolving legal tech and regulatory guidance into assessment methodologies
  • Bachelor’s degree or equivalent
Job Responsibility
Job Responsibility
  • Manage and oversee a set of complex initiatives that span multiple lines of business in the Cyber Security (CS), Information Security (IS) and Third-Party Risk Management (TPRM) space for Global Legal Solutions
  • Assess the risks and effectiveness of Third Party IS processes and controls based on enterprise requirements ensuring the IS risk is within tolerance
  • Evaluate the design and execution of the Legal IS Program, identifies potential enhancements and drives implementation of governance, methodologies and tools required for the effective oversight of Third-Party Management IS risk to continually strengthen the Program
  • Assist the day-to-day activities within the TPM Risk and Info Sec group
  • Monitor, track and control outcomes to resolve issues, conflicts, dependencies and critical path deliverables related to issues and gaps found in the TPISA process
  • Drive implementation of enterprise Third Party Management controls required to be assessed as part of the Managers Control Assessment, reviews results, and determines if remediation actions are appropriate
  • Document control design, testing methodology, and evidence for effectiveness reviews in compliance with Citi's Risk and Control Standards
  • Contribute to quarterly control certifications, issue management processes and audit engagements
What we offer
What we offer
  • Generous holiday allowance starting at 27 days plus bank holidays
  • increasing with tenure
  • A discretional annual performance related bonus
  • Employee Assistance Program
  • Pension Plan
  • Paid Parental Leave
  • Special discounts for employees, family, and friends
  • Access to an array of learning and development resources
  • Private medical insurance packages to suit your personal circumstances
  • Fulltime
Read More
Arrow Right

Risk and Compliance Manager

The Program Manager position will report to the Head of Risk for the India team ...
Location
Location
India , Bengaluru
Salary
Salary:
Not provided
https://www.atlassian.com Logo
Atlassian
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Minimum 5 years of experience in IT audit, compliance, control monitoring or a related field
  • Experience with SOC 2, ISO 27001/27018, HIPAA, PCI, C5 and GDPR frameworks and requirements
  • Familiarity with compliance frameworks and standards such as NIST 800-53
  • Experience with the software development business for cloud service providers
  • Experience with Technology Risk Management, Compliance and Information Security
  • Experience with control and risk frameworks, performing compliance and risk assessments, creating controls and overseeing mitigation projects
  • Experience with translating compliance requirements to engineering and product teams
  • Experience with determining scope, timeline creation, complex project tracking, risk management, and process improvement
  • Familiarity with Jira and Confluence
  • Relevant certifications such as CISA, CISSP, or ISO 27001 Lead Auditor are highly desirable
Job Responsibility
Job Responsibility
  • Perform design and operating effectiveness testing on controls to ensure compliance with SOC 2, ISO 27001/27018, C5, HIPAA and other compliance obligations
  • Collaborate with control owners to review the design and effectiveness of controls, ensuring they meet certification requirements
  • Identify any gaps in compliance and work with relevant teams to remediate findings before the external audit
  • Drive control automation & control monitoring efforts
  • Maintain comprehensive documentation of controls, testing procedures, and evidence to support compliance efforts
  • Work closely with internal stakeholders, including product and functional teams, to address architectural, infrastructure, or new services that impact compliance
  • Assist in preparing for external audits by ensuring all necessary documentation and evidence are in place and up to date
  • Assess and document the impact of control gaps in SOC reports of critical third party suppliers
  • Identify compensating controls and follow up with business owners
  • Perform design and operating effectiveness testing on predefined Privacy controls to ensure compliance with GDPR
What we offer
What we offer
  • health coverage
  • paid volunteer days
  • wellness resources
  • Fulltime
Read More
Arrow Right

Operational Risk Management Officer

Allianz Technology is a global leader in driving technological innovation and op...
Location
Location
Spain , Barcelona
Salary
Salary:
Not provided
https://www.allianz.com Logo
Allianz
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Strong background in IT risk management, IT audit or IT security
  • Experience in Non-Financial Risk Management (NFRM) processes, including scoping, risk & control assessment, control documentation, quality assurance, control testing and assurance reporting
  • Proficiency in Excel and other relevant risk management tools
  • Familiarity with enterprise risk frameworks and methodologies
  • Ability to provide functional support to Functional/Entity Risk Officers
  • Strong knowledge-sharing capabilities, including creating guidance documents and delivering training sessions
  • Effective stakeholder collaboration skills
  • Strong communication and interpersonal skills
  • Preferred qualifications include prior experience in IT governance, compliance, or regulatory risk management
  • Exposure to risk reporting and assurance practices
Job Responsibility
Job Responsibility
  • Support activities related to the Non-Financial Risk Management (NFRM) lifecycle
  • Provide functional support to Functional/Entity Risk Officers on risk-related topics
  • Assist the Risk Management function in providing guidance and sharing best practices
  • Establish and maintain strong relationships with stakeholders in business IT functions, Risk Officers, and other safeguarding functions
What we offer
What we offer
  • Hybrid work model
  • Up to 25 days per year working from abroad
  • Company bonus scheme
  • Pension
  • Employee shares program
  • Multiple employee discounts
  • Career development and digital learning programs
  • International career mobility
  • Flexible working
  • Health and wellbeing offers
  • Fulltime
Read More
Arrow Right

Process Improvement, Knowledge, & Enterprise Risk Management Task Lead

Implement and execute a process improvement program that continuously identifies...
Location
Location
United States , Washington, DC
Salary
Salary:
Not provided
talentacquisitionconcepts.com Logo
Talent Acquisition Concepts
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • A current, active SECRET Clearance
  • A bachelor's degree in computer science or a related field
  • 5+ years of total work experience in IT governance, risk management, audit, compliance, business continuity plan management, or other related information security domains
  • 3+ years managing cross-functional teams and influencing senior-level management and stakeholders
  • Previous experience obtaining and maintaining compliance certifications/attestations for at least one of the following: PCI-DSS, Sarbanes-Oxley (SOX), or SOC 2 compliance
  • Strong understanding of PCI-DSS, NIST CSF, and COBIT frameworks
  • Advanced comprehension of security and risk best practices and industry standards from a business, technical, and operational perspective
  • Proven experience leading and developing staff members
  • Ability to maintain the highest level of confidentiality
  • Excellent organizational skills with a proven ability to manage multiple projects simultaneously
Job Responsibility
Job Responsibility
  • Continuously monitor SDLC related processes and provide CST insight into any areas that may require special attention
  • Make recommendations for process improvements and develop target-state process designs, develop implementation plans/roadmaps, and continually revise and report on process efficiencies and redundancies
  • Develop and deliver updated process, policy and procedures documents
  • Support CST’s Annual Statement of Assurance process documentation requirements
  • Conduct and document process evaluations against established performance metrics, recommend corrective actions, and conduct lessons-learned sessions
  • Support the Government in monitoring project teams for adherence to policies and procedures
  • Perform all other Process Improvement activities as directed by the COR/GTM
  • Review CST’s current Knowledge Management processes and Systems, including SharePoint, as well as review existing knowledge management documentation with the view to making improvements
  • Provide support for SharePoint as a Knowledge Management tool. This shall include maintenance of SharePoint sites and repository/document management activities
  • Recommend improvements to CST’s Knowledge Management systems and develop and maintain related Knowledge Management Policies and Procedures documents
What we offer
What we offer
  • health, dental, and vision coverage
  • a retirement plan
  • a profit-sharing/bonus plan
  • Paid Time Off
  • holidays
  • sick days
  • a fun, creative work environment
  • Fulltime
Read More
Arrow Right

Information Security Risk Lead

The Information Security Risk Lead is responsible for driving efforts to support...
Location
Location
Thailand , Bangkok
Salary
Salary:
Not provided
https://www.citi.com/ Logo
Citi
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Master’s/Bachelor’s/University degree or equivalent experience in Computer Science, Cyber Security, Computer/Information Engineering, Information Technology or a related discipline is preferred
  • One or more industry-recognized cybersecurity-related certifications such as CISSP, CISA, CISM, CRISC, ISO 27001
  • 6 - 10 years or above of relevant experience in Cyber Security Management / Cyber Security Operations / Technology Risk Management / Third-party Risk Management or IT Audit, preferably with experience gained from banking / finance services industry / consultancy / control compliance or legal disciplines
  • Experience in assessing cyber regulatory compliance from BOT, SEC etc.
  • Strong understanding of International Standards/Frameworks such as: NIST, ISO 27001series, COBIT, CIS, GDPR, DORA, etc.
  • Proficient in interpreting and applying policies, standards and procedures
  • Excellent project management and organizational skills (PMP, PRINCE2, etc. is a plus)
  • Strong consultation, reporting writing and communication skills with highly proficiency in both spoken and written English and Thai
  • Thai language fluency is a must.
Job Responsibility
Job Responsibility
  • Manage and validate deliverables of all Information Security (IS) programs, ensuring closure per agreed timelines and goals
  • Engagement with local regulators BOT, SEC, TB-CERT, Thai-CERT, MDES, NCSA, etc. on IS related matters
  • Manage regulatory exams and internal & external audits
  • Work closely with Global & Regional Information Security teams to improve processes and reduce risk, and support the IS regulatory related activities for Thailand
  • Manage internal/external resources to organize cyber-attack simulations exercise, coordinating and overseeing vulnerability, mitigation/remediation/correction action plans, and issues management process
  • Accountable for delivery of the associated remediation from regulatory assessments
  • Proficiency in preparing periodic updates / reports / presentation deck for both internal stakeholders and regulators
  • Provide timely and appropriate updates to regional and global stakeholders
  • escalate issues in a timely manner to senior management
  • Build and develop partnerships with business, IT, risk, compliance, IS, senior management staff and stakeholders
  • Fulltime
Read More
Arrow Right