IT Governance Analyst
Job description
IT Governance Analyst at Bamboohr.
About the role
Bamboohr is seeking an IT Governance Analyst to support the organization's technology oversight and compliance functions across its operations in Malaysia. This role involves ensuring that information technology practices align with regulatory standards and internal company policies at every level of the organization. The analyst will work closely with leadership teams to establish and maintain governance frameworks that guide how technology resources are managed, monitored, and protected. The position contributes directly to the broader mission of maintaining secure, compliant, and efficient IT operations within the company. The analyst will also play a key part in shaping the direction of governance policies as the organization continues to grow and evolve its technology landscape.
Key facts
What you'll do
Review and assess existing IT policies and procedures to ensure they meet current regulatory and industry standards consistently.
Develop and regularly update governance documentation that outlines technology usage rules, responsibilities, and standard operating procedures for all staff.
Coordinate with cross-functional teams across departments to evaluate technology risks and recommend appropriate mitigation strategies and controls.
Monitor compliance with data protection regulations and internal security protocols to ensure all departments follow established guidelines.
Conduct periodic audits of IT systems and infrastructure to verify adherence to established governance frameworks and standards.
Prepare detailed reports and visual dashboards that summarize governance metrics, trends, and findings for leadership and stakeholders.
Assist in the design and refinement of access control policies and user privilege management procedures across the organization.
Support the implementation of new technology initiatives with proper governance oversight, documentation, and risk assessment throughout the project lifecycle.
Facilitate training sessions and workshops for staff members on IT governance policies, compliance expectations, and best practices.
Collaborate with external auditors and regulatory bodies during formal assessments, reviews, and compliance verification activities.
Maintain a comprehensive inventory of IT assets and ensure proper classification, handling, and disposal procedures are followed.
Advise project teams and business units on governance requirements during the planning, execution, and post-implementation phases.
Evaluate vendor and third-party technology services to ensure they meet the company's governance and security standards.
Contribute to the continuous improvement of governance processes by identifying gaps and proposing actionable enhancements.
Requirements
Bachelor's degree in information technology, computer science, or a closely related academic discipline from an accredited institution.
At least 3 years of professional experience in IT governance, risk management, or compliance roles within a corporate environment.
Demonstrated familiarity with Malaysian regulatory frameworks applicable to information technology, data protection, and cybersecurity requirements.
Strong understanding of IT service management frameworks such as ITIL or equivalent recognized industry standards and practices.
Proven ability to analyze complex organizational processes and translate findings into clear, actionable policy recommendations for management.
Experience working with cross-functional teams across multiple business units or operational departments in a matrix environment.
Excellent written and verbal communication skills for preparing detailed reports, presentations, and briefing materials for diverse audiences.
Ability to manage multiple priorities simultaneously and consistently meet established deadlines in a fast-paced and dynamic work setting.
Strong attention to detail and a methodical approach to documenting processes, procedures, and governance frameworks accurately.
Willingness to travel between Federal Territory Labuan, Kuala Lumpur, and Johor as business needs require throughout the year.
Nice to have
Professional certifications such as CISA, CISM, or CRISC are valued by the organization and considered a strong advantage.
Prior experience working in a financial services or regulated industry setting provides a meaningful background for this role.
Knowledge of cloud computing governance and emerging technology risk assessment practices is considered a beneficial qualification.
Experience with governance, risk, and compliance GRC software platforms or related tools is helpful for success in this position.
Familiarity with data privacy laws and regulations specific to the Malaysian and Southeast Asian region is a plus.
Skills & tools
Proficiency in Microsoft Office Suite, particularly Excel and PowerPoint, for creating governance reports and analytical presentations.
Familiarity with GRC platforms such as ServiceNow GRC, RSA Archer, or similar enterprise risk and compliance tools.
Understanding of cybersecurity frameworks including ISO 27001 and NIST standards and their application in governance contexts.
Experience with data analysis and visualization techniques for producing meaningful governance metrics and performance reports.
Knowledge of enterprise architecture tools and IT asset management systems for tracking and categorizing technology resources.
Ability to use workflow and project management tools to automate governance processes and improve efficiency.
Familiarity with scripting or programming languages such as Python or SQL for data extraction and analysis tasks.
Understanding of enterprise content management systems and document control procedures for maintaining governance records.
Practical notes
a full-time position based in Malaysia with primary locations in Federal Territory Labuan, Kuala Lumpur, and Johor.
The role requires regular interaction with internal stakeholders across multiple departments and occasional engagement with external partners and vendors.
Candidates should be prepared to travel between the listed locations as business needs require throughout the calendar year.
The hiring process includes multiple interview rounds with various team members and a technical assessment of governance knowledge.
This position reports to the IT governance or risk management leadership team and involves collaboration with senior management.