Epicareer Might not Working Properly
Learn More

Project Risk and Compliance Analyst

Salary undisclosed

Apply on


Original
Simplified

Job Summary:

The Project, Risk, and Compliance Analyst is responsible for ensuring the efficient management and coordination of risk, compliance, and information security projects. The role includes managing projects, supporting the Information Security Management System (ISMS), evaluating and managing risks, compliance evaluation with organization policy and compliance standards and working closely with cross-functional teams to deliver project management and compliance initiatives. The analyst will also be responsible for fraud detection and remediation activities, ensuring that proper mechanisms are in place to monitor and address fraud risks. Acting as the Information Security Management Representative (ISMR), the analyst will maintain and continually improve the ISMS framework in line with ISO standards.

Key Responsibilities:

Project Management:

  • Support and assisting in compliance-related projects, ensuring timelines and deliverables are met.
  • Coordinate with cross-functional teams to plan, execute, and close projects in alignment with organizational objectives.
  • Oversee the tracking and reporting of project status, risks, and issues to stakeholders on assigned projects/task.
  • Develop project documentation, including project plans, status reports, and risk assessments.

Risk Management:

  • Conduct risk assessments to identify, analyze, and evaluate risks related to business processes, projects, and compliance efforts.
  • Assist in the development and implementation of risk mitigation strategies, policies, and procedures.
  • Collaborate with the relevant teams towards continuous monitoring of risk exposure
  • Maintain a risk register, update it regularly with identified risks, and provide risk reports to senior management.
  • Perform ongoing risk reviews, maintaining a risk register and ensuring timely updates.

Fraud Monitoring and Remediation:

  • Implement and oversee fraud detection mechanisms, including transaction monitoring systems and behavioral analytics, to identify suspicious activities.
  • Collaborate with internal teams to investigate suspected fraud cases, escalate issues, and ensure swift remediation actions.
  • Develop and update fraud prevention policies and procedures, ensuring alignment with legal and regulatory requirements.
  • Monitor fraud trends and emerging threats, adjusting monitoring techniques and tools to stay ahead of potential fraud schemes.
  • Coordinate fraud response efforts, including internal reviews, reporting incidents, and liaising with law enforcement or external agencies when necessary.

Information Security Management System (ISMS) & ISMR Responsibilities:

  • Support as the Information Security Management Representative (ISMR), coordinating efforts across teams towards adherence to the organization’s ISMS policies, procedure and other relevant standards.
  • Support the maintenance and improvement of the ISMS to ensure compliance with internal policies, external regulations, and ISO standards.
  • Coordinate internal and external audits, ensuring that corrective actions are implemented and tracked.
  • Review and provide recommendations and updates to security policies, procedures, and controls to ensure continued relevance.
  • Liaise with internal and external stakeholders to address security incidents and support continuous improvement.

Compliance Management:

  • Support and coordinating effort to ensure compliance with regulatory and contractual obligations, such as data protection, privacy regulations (GDPR, PDPA), and industry standards (ISO 27001, PCI DSS).
  • Coordinate on projects related to legislative and regulatory developments to ensure ongoing compliance with the respective stakeholders – internal and external.
  • Coordinate with relevant parties on compliance training materials and conduct training sessions for employees.
  • Monitor records of compliance reviews, audit findings, and remediation efforts.

Reporting & Communication:

  • Prepare regular reports on the status of projects, risk management efforts, and compliance initiatives for management and external stakeholders.
  • Communicate effectively with internal departments to ensure collaboration and alignment on security, risk, and compliance matters.
  • Act as the point of contact for compliance audits and external regulatory assessments.

Required Skills and Qualifications:

  • Bachelor's degree in IT, Information Security, Risk Management, Compliance, or related field.
  • 2 to 3 years of experience in project management, risk management, and compliance roles.
  • Some experience working with ISO 27001 standards and experience in managing ISMS.
  • Understanding of risk assessment methodologies and mitigation strategies.
  • Hands-on experience in fraud detection systems and remediation processes.
  • Knowledge and familiarity with regulatory requirements is an added advantage but not necessary.
  • Excellent communication and report-writing skills, with the ability to convey complex information clearly and effectively to various stakeholders.
  • Proficiency in project management tools and techniques.
  • Relevant certification is an added advantage.

Key Competencies:

  • Strong command of English in both written and verbal.
  • Strong analytical and problem-solving skills.
  • Attention to detail and a methodical approach to risk and compliance tasks.
  • Ability to work independently and collaboratively in a fast-paced environment.
  • Excellent organizational skills, with the ability to manage multiple projects and priorities simultaneously.
  • Ability to manage multiple priorities in a dynamic environmen