openqareer

IT Compliance Specialist

Ngân Hàng Á CHÂU ACB · Thành phố Hồ Chí Minh

IT Compliance Specialist is responsible for ensuring that the organization‘s IT systems, processes, and controls comply with applicable regulatory requirements, industry standards, and internal policies. This role supports risk management, security governance, audits, and compliance initiatives to protect information assets and maintain business continuity. Key Responsibilities Compliance Management Develop, implement, and maintain IT compliance programs, policies, standards, and procedures. Ensure compliance with relevant regulations and standards such as ISO 27001, SOC 2, GDPR, PCI-DSS, HIPAA, SOX, and local regulatory requirements. Monitor changes in regulatory requirements and assess their impact on the organization. Audit & Assessment Support Coordinate internal and external IT audits. Prepare audit documentation, evidence, and reports. Track audit findings and ensure timely remediation of identified gaps. Conduct compliance assessments and control reviews. Risk Management Identify and evaluate IT compliance risks. Perform risk assessments on IT systems, applications, and processes. Recommend and monitor corrective actions to mitigate identified risks. Policy & Control Governance Develop and maintain IT policies, standards, and control frameworks. Review and assess effectiveness of security and compliance controls. Collaborate with IT and business teams to ensure controls are properly implemented. Training & Awareness Conduct compliance awareness training for employees. Promote best practices related to information security and regulatory compliance. Support compliance culture initiatives across the organization. Documentation & Reporting Maintain compliance records, risk registers, and audit documentation. Generate regular compliance status reports for management. Track compliance metrics and key performance indicators (KPIs). Stakeholder Collaboration Work closely with Information Security, IT Operations, Legal, Risk Management, and Business Units. Support third-party/vendor compliance assessments. Assist management in responding to regulatory inquiries and audits. Required Qualifications Education Bachelor‘s degree in Information Technology, Information Security, Computer Science, Business Administration, or related field. Experience At least 3 years of experience in IT compliance, information security, IT audit, governance, risk management, or related areas. Experience working with regulatory frameworks and compliance standards. Technical Knowledge Understanding of: ISO 27001 NIST Cybersecurity Framework COBIT SOC 2 PCI-DSS GDPR and data privacy regulations IT General Controls (ITGC) Skills Strong analytical and problem-solving skills. Excellent documentation and report-writing abilities. Knowledge of risk assessment methodologies. Strong communication and stakeholder management skills. Ability to manage multiple projects and deadlines. Preferred Certifications CISA (Certified Information Systems Auditor) CISM (Certified Information Security Manager) CRISC (Certified in Risk and Information Systems Control) CISSP (Certified Information Systems Security Professional) ISO 27001 Lead Implementer or Lead Auditor Certified Compliance & Ethics Professional (CCEP) Lương: Thương lượng Địa điểm làm việc: Hội sở (Tp. HCM) Hạn nộp hồ sơ: 28/08 — 31/10/2026

Наблюдалась 2026-09-15, впервые 2026-08-28, источник — Indeed.

Открыть у работодателя