Skip to main content
Compare with other roles
📋High Demand

GRC Analyst

Governance, Risk & Compliance — the business side of security. GRC analysts ensure the organisation meets regulatory requirements and manages risk systematically. High demand in banking and finance.

Avg Salary (MY)

RM 5,000 – RM 12,000/month

Avg Salary (Global)

USD 70,000 – USD 120,000/year

Market Demand

High

What you'll actually do

  • Develop and maintain information security policies and procedures
  • Conduct risk assessments and manage the risk register
  • Lead internal and external security audits
  • Ensure compliance with PDPA, ISO 27001, PCI DSS, etc.
  • Manage third-party vendor risk assessments
  • Report risk posture to senior management and board

Skills you need

Risk assessment methodologiesRegulatory and compliance frameworksPolicy and procedure writingAudit planning and executionVendor risk managementBusiness communication and report writing

Tools & platforms

GRC platforms (ServiceNow GRC, Archer)Microsoft Office / SharePointJIRA (for tracking compliance tasks)Risk management tools (Riskonnect)

Certifications to Target

1CISA (Certified Information Systems Auditor)
2CRISC (Certified in Risk and Information Systems Control)
3ISO 27001 Lead Auditor / Lead Implementer
4CISM (Certified Information Security Manager)

Who Is a Good Fit?

  • Auditors (IT or internal)
  • Compliance officers
  • Legal / Risk management professionals
  • Business analysts pivoting to cybersecurity

Career Growth Path

1
GRC Analyst → Senior GRC Analyst
2
→ GRC Manager / Compliance Manager
3
→ Head of Risk / CISO
4
→ Independent GRC Consultant

LumaShift Career Advisor

Cybersecurity career guidance

Hi! I'm LumaShift's Career Advisor. I can help you find the right coaching service, understand cybersecurity career paths, or answer questions about certifications and salaries.


What can I help you with today?

Or email lumashift@outlook.com

Chat on WhatsApp