Senior Consultant – Information Security Governance, Risk & Compliance (GRC)
Eccouncil · Kuala Lumpur, Malaysia (3A - Plaza Sentral) · On-site
Pay: MYR 5,000 – 7,000 a year
Posted Sep 28, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Job Title: Senior Consultant – Information Security Governance, Risk & Compliance (GRC)
#ECGS
EC-Council is the world's largest cyber security technical certification body. We operate in 170 countries globally and we are the owner and developer of various world-famous cyber security programs. We are proud to have trained and certified over 400,000 information security
professionals globally that have influenced the cyber security mindset of countless organizations worldwide.
www.eccouncil.org
Role Overview:
We are looking for an experienced Senior Consultant – Information Security Governance, Risk & Compliance (GRC) to join our cybersecurity consulting team. The successful candidate will be responsible for delivering information security governance, risk management, compliance, audit, assurance, and advisory engagements for clients across various industries. This is a client-facing consulting role suited for someone who is comfortable independently managing assigned workstreams, conducting stakeholder interviews and workshops, assessing cybersecurity controls, reviewing evidence, identifying risks and gaps, and developing high-quality client deliverables. You will also provide guidance to junior consultants and support the successful delivery of multiple GRC engagements.
Key Responsibilities:
Deliver Information Security GRC consulting engagements from planning through reporting.
Conduct cybersecurity governance, risk, compliance, maturity, and control assessments.
Perform information security and cybersecurity risk assessments.
Conduct regulatory and standards-based gap assessments.
Perform cybersecurity audits, internal audits, and independent control assessments.
Assess the design adequacy and operating effectiveness of cybersecurity controls.
Conduct stakeholder interviews, walkthroughs, workshops, and evidence reviews.
Identify control gaps, risks, weaknesses, and areas for improvement.
Develop practical and risk-based recommendations for clients.
Prepare professional assessment reports, audit reports, risk registers, compliance reports, management presentations, and remediation roadmaps.
Develop and review information security policies, procedures, standards, and governance frameworks.
Conduct cybersecurity maturity assessments and develop improvement roadmaps.
Conduct third-party and supplier cybersecurity risk assessments.
Support certification and regulatory compliance readiness activities.
Track project activities, information requests, findings, risks, and deliverables.
Manage assigned engagement workstreams and ensure activities are completed within agreed timelines.
Present assessment findings and recommendations to client stakeholders and management.
Review work performed by Consultants and Junior Consultants.
Mentor and guide junior members of the GRC delivery team.
Maintain high standards of quality, confidentiality, professionalism, and integrity throughout all engagements.
To assist…