Job Seeker Reactivate Your Account
Thank you, this account has been Deactivated.
Do you want to Reactivate your account?
No
Yes
X

Assistant Manager, Technology Risk & Compliance

ATOM
Kyauktada | Yangon
  1 Post
Verified This Job has been Verified as
Real by the Company.
This Job has been Verified as
Real by the Company.
Today
Recruiter active5 hours ago This Company is Actively
Hiring. Your CV will be Sent
Directly to the Company.
This Company is Actively
Hiring. Your CV will be Sent
Directly to the Company.
Sorry, Unable to Apply
x
55%
Please Upload CV Attachment, or update your JobNet Profile to at least 55% of completion.
Upload CV
Update Profile
Assistant Manager, Technology Risk & Compliance
ATOM, Kyauktada | Yangon

Assistant Manager, Technology Risk & Compliance

ATOM

Assistant Manager, Technology Risk & Compliance

ATOM
Recruiter active5 hours ago This Company is Actively
Hiring. Your CV will be Sent
Directly to the Company.
This Company is Actively
Hiring. Your CV will be Sent
Directly to the Company.
Myanmar - Yangon
Verified This Job has been Verified as
Real by the Company.

Experience level

Experienced Non-Manager

Job Function

IT Hardware, Software

Job Industry

Telecommunications

Min Education Level

Bachelor Degree

Job Type

Full Time

Job Description

A Big Opportunity for ...

Job Purpose:

 

Assistant Manager, Technology Risk & Compliance is responsible for supporting the day-to-day operation of the Governance, Risk & Compliance (GRC) program. The role performs security risk assessments, compliance monitoring, audit support, third-party security reviews, issue tracking, policy administration, awareness activities, and reporting. The position acts as a key operational resource to ensure security controls, compliance requirements, and risk management activities are executed effectively and consistently across the organization.

 

Key Responsibilities:

Risk Assessment & Risk Register Management

  • Conduct cybersecurity and technology risk assessments for systems, projects, applications, and business initiatives.
  • Identify, assess, and document risks using established methodologies.
  • Maintain and update risk registers.
  • Track risk treatment plans and remediation progress.
  • Follow up with risk owners on overdue actions.
  • Prepare risk reports and risk dashboards.

Compliance Monitoring

  • Perform periodic compliance reviews against organizational policies and standards.
  • Collect and validate compliance evidence from stakeholders.
  • Monitor compliance with regulatory and contractual requirements.
  • Support control testing and compliance assessments.
  • Assist in the implementation and monitoring of corrective actions.

Audit Support

  • Coordinate audit requests from internal and external auditors.
  • Gather and review required audit evidence.
  • Maintain audit documentation and evidence repositories.
  • Track audit findings and management action plans.
  • Monitor remediation progress and closure status.
  • Prepare audit status reports.

Third-Party Risk Management (TPRM)

  • Perform vendor and supplier security assessments.
  • Review security questionnaires and supporting documents.
  • Assess third-party security controls against established requirements.
  • Track remediation actions arising from vendor assessments.
  • Maintain third-party risk assessment records.
  • Monitor assessment schedules and renewals.

Policy & Control Management

  • Support development, review, and maintenance of security policies, standards, and procedures.
  • Track policy review cycles and approvals.
  • Maintain control inventory and compliance mappings.
  • Assist business and IT teams in understanding security requirements.
  • Ensure policy exceptions are properly documented and tracked.

Security Awareness Operations

  • Coordinate cybersecurity awareness campaigns.
  • Support phishing simulation activities.
  • Track employee training completion rates.
  • Prepare awareness communications and educational materials.
  • Maintain awareness metrics and reporting.

Security Metrics & Reporting

  • Prepare weekly and monthly GRC operational reports.
  • Track key risk indicators (KRIs) and compliance metrics.
  • Maintain dashboards and management reporting packs.
  • Analyze trends and highlight emerging risks.
  • Escalate overdue compliance and risk actions.

Project & Change Risk Reviews

  • Participate in project security reviews.
  • Perform risk assessments for new systems, applications, and technology changes.
  • Review security controls during project lifecycle activities.
  • Track closure of security requirements before implementation.

Documentation & Record Management

  • Maintain GRC repositories and documentation.
  • Ensure evidence and records are properly stored and retrievable.
  • Support regulatory inquiries and information requests.
  • Maintain accurate and up-to-date compliance records.

Open To

Male/Female

Job Requirements

Education:

  • Bachelor’s degree in information technology, Computer Science, Cybersecurity, or a related field.
  • Professional certifications such as Security+, CISA, CRISC, CISSP, CISM, or similar are advantageous.

Experience:

  • 2-5 years of experience in Cybersecurity, Information Security & GRC related roles.

Good understanding of:

  • Information Security Principles
  • Technology Risk Management
  • Third-Party Risk Management
  • Security Control Frameworks
  • Audit and Compliance Processes
  • Security Governance Concepts
  • Incident Management Processes
  • Vulnerability and Risk Management Concepts
  • Cloud Security Fundamentals

What we can offer

Benefits

- Airtime Usage
- Medical Insurance Coverage
- Bonus Entitlement

Highlights

- Make a difference!
- Join an experienced team!

Career Opportunities

- Learn new skills on the job