GRC Analyst

ABOUT MA COMPLIANCE

MA Compliance is a Singapore-headquartered IT and cybersecurity firm that helps small and medium enterprises and fast-growing start-ups become — and stay — audit-ready. With more than two decades of delivery experience across IT infrastructure, information security and compliance, we treat cyber risk management as a business enabler rather than a paperwork exercise.

Our compliance practice covers security consultation, compliance assessment, policy creation and review, security awareness training, IT asset classification, and incident and risk management, against frameworks including ISO 27001, SOC 1/2/3, GDPR, PDPA, CCPA and DPDP. We serve clients across Singapore, Indonesia, Vietnam, the Philippines and India, in industries ranging from manufacturing and logistics to healthcare, technology and financial services.

THE ROLE

The GRC Analyst is a client-facing consulting role. You will work directly on client engagements — helping SME and start-up clients build, run and evidence their risk management and compliance programmes.

Day to day, that means running risk assessments and gap analyses, writing and reviewing policies, preparing clients for certification and surveillance audits, tracking remediation to closure, and reporting risk clearly enough that a client's management team can act on it. You will typically carry two to four concurrent engagements and will be the client's main point of contact for GRC matters on those projects.

KEY RESPONSIBILITIES

Client Risk Management

• Plan and run risk assessments for client organisations— asset and process scoping, threat and vulnerability identification, likelihood and impact rating, and treatment planning.

• Facilitate Risk & Control Self-Assessment (RCSA)workshops with client business owners, and challenge risk ratings and control descriptions where the evidence does not support them.

• Build and maintain client risk registers, and track risks, issues, incidents and remediation actions through to closure.

• Define and monitor Key Risk Indicators (KRIs) so clients have early visibility of exposures rather than after-the-fact surprises.

• Support clients on third-party and vendor risk assessments, including due diligence questionnaires and contractual security requirements.

Compliance Assessment& Audit Readiness

• Conduct gap assessments against ISO 27001, SOC 1/2/3,PDPA, GDPR and other applicable standards, and translate findings into a prioritised, costed remediation roadmap.

• Prepare clients for certification, surveillance and customer audits — evidence collection, control walkthroughs, internal audit support and mock audits.

• Act as the client's liaison with external auditors and certification bodies during fieldwork, and coordinate management responses to findings.

• Perform internal audits of client Information Security Management Systems (ISMS) and report results to client management.

• Support clients' PDPA obligations, including data inventories, DPIAs, consent and retention practices, and breach-notification readiness.

Governance, Policy &Documentation

• Draft, tailor and review information security policies, standards, procedures and supporting records so they fit the client's actual size, risk profile and operating model.

• Carry out IT and information asset classification exercises to underpin clients' data-protection objectives.

• Establish practical governance routines for clients —management review meetings, risk committee packs, exception and waiver handling, and document control.

• Maintain complete, well-organised engagement documentation and evidence so client programmes withstand audit scrutiny.

Reporting & Analytics

• Produce risk dashboards, assessment reports and management reporting packs that are clear to non-technical business owners.

• Analyse risk and control data to surface trends, recurring control weaknesses and areas needing management attention.

• Use reporting and GRC tooling (for example Power BI,JIRA, Excel, and GRC platforms) to improve the accuracy, consistency and turnaround of engagement reporting.

• Contribute to internal delivery quality — reusable templates, assessment checklists and methodology improvements.

Client Engagement &Advisory

• Serve as the day-to-day GRC contact on assigned engagements, managing scope, timelines and deliverables alongside the engagement lead.

• Explain risk and compliance requirements to client stakeholders — from IT administrators to founders and board members — in language they can act on.

• Deliver security awareness and risk training sessions to client teams.

• Support pre-sales and scoping conversations with prospective clients, including proposal input and effort estimation.

• Identify opportunities to extend the value MA Compliance delivers to existing clients.
QUALIFICATIONS

• Degree or equivalent qualification in Information Technology, Cybersecurity, Risk Management, Business or a related discipline.

• Professional certification such as ISO 27001 Lead Implementer or Lead Auditor, CISA, CRISC, CISM, CISSP, or an equivalent GRC credential is an advantage; support is available for candidates working towards one.

REQUIREMENTS

Essential

• 3–6 years' experience in GRC, information security compliance, IT risk, internal audit or a related function.

• Hands-on experience with at least one major framework end to end — ISO 27001, SOC 2, NIST CSF or similar — including gap assessment, remediation and audit.

• Working knowledge of Singapore's PDPA and of GDPR principles; familiarity with other regional data-protection regimes is a plus.

• Practical experience with risk assessments, risk registers, control testing and remediation tracking.

• Strong written English — you will produce policies, assessment reports and management papers that go directly to clients.

• Confidence engaging business stakeholders and senior management, and the judgement to challenge constructively.

• Strong analytical skills and comfort working with data in Excel and reporting tools.

• Ability to manage multiple concurrent engagements and shifting priorities without losing detail.
WHAT WE OFFER

• Direct client ownership from day one — not aback-office reporting seat.

• Breadth across frameworks, industries and markets rather than a single company's control set.

• A small, senior team where your work is visible and your judgement matters.

• Support for professional certification and continuing development.

• Hybrid and flexible working hours, with travel to client sites in Singapore and occasional regional travel.

HOW TO APPLY

Send your CV to info@macomply.com with the subject line "GRC Analyst — [YourName]". Shortlisted candidates will be contacted within one business week.MA Compliance is an equal opportunity employer; we select on merit, skills and experience.

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available