Information Security Analyst

HRINC (Cambodia) Co., Ltd Job location: Phnom Penh

Login to see salary

Job Overview
# Hiring1
Job TypePermanent Job
Exp. LevelManagement
Job FunctionInformation Technology , Others
IndustryBanking / Financial Service
Preferred ApplicantLocal
Required LanguageKhmer , English
DeadlineMay 9, 2026
LocationPhnom Penh
Job Summary

The Information Security Analyst supports the governance, risk, and compliance (GRC) aspects of information security, including risks associated with artificial intelligence (AI), ensuring alignment with regulatory requirements, internal policies, and established governance frameworks.

The role contributes to the continuous improvement and operation of information security risk management, control assurance, and compliance processes, leveraging data analytics and AI‑enabled techniques where appropriate, and aligning with international best practices such as NIST and ISO standards, as well as national regulations and guidance including TCRMG.

The position provides accurate risk analysis, compliance insights, and reporting to support effective oversight, assurance, and informed decision‑making by Information Security leadership and key internal stakeholders.

Responsibilities and Duties

Performance

  • Support the effective operation of the Bank’s information security governance, risk, and compliance (GRC) activities, including governance of artificial intelligence (AI) and data‑driven technologies, in line with approved frameworks and policies.
  • Contribute to the ongoing enhancement and maintenance of information security and AI‑related GRC processes to ensure alignment with regulatory requirements, internal governance standards, and recognised international best practices (e.g. NIST, ISO).
  • Perform and support assigned GRC activities, including reviews, assessments, and analysis of information security and AI‑related controls, and assist with the documentation, tracking, and follow‑up of identified issues.
  • Maintain accurate, complete, and up‑to‑date information security and AI governance artefacts, including registers, assessments, policies, standards, and supporting documentation.
  • Provide GRC input for projects, significant changes, new technologies, third‑party engagements, and AI initiatives to ensure governance, risk, and compliance considerations are addressed.
  • Prepare clear, timely, and reliable information security and AI‑related GRC reporting and analysis to support management oversight and informed decision‑making.

KPIs

  • Complete assigned information security GRC activities (e.g. risk, policy, compliance, assurance tasks) within agreed timelines and service expectations.
  • Ensure information security documentation, registers, assessments, policies, and compliance artefacts assigned to the role are accurate, current, and complete, with no material quality issues identified.
  • Support ongoing alignment of information security practices with internal policies, governance frameworks, and applicable regulatory or supervisory requirements.
  • Track, follow up, and support resolution of assigned information security issues, findings, or action items, achieving a high rate of on‑time completion or appropriate escalation.
  • Provide timely GRC input into projects, changes, new technologies, and initiatives assigned to the role, ensuring governance and compliance considerations are addressed.
  • Support internal audits, external audits, and regulatory reviews by delivering requested information, evidence, and analysis accurately and within required timeframes.
  • Maintain effective working relationships with internal stakeholders, demonstrated through timely responses, constructive engagement, and positive feedback.
  • Prepare clear, concise, and reliable reports, summaries, and analysis to support Information Security and management decision‑making.
  • Identify and contribute to improvements in information security GRC processes, tools, controls, or ways of working, aligned with regulatory expectations and industry best practices.
  • Complete agreed learning and development objectives annually and apply new knowledge or skills to improve role effectiveness.
  • Support governance, risk, and compliance activities related to AI or data‑driven technologies within assigned scope, in line with internal policies and emerging regulatory guidance.

Customer Service

  • Support the business in achieving its objectives securely by providing timely, accurate, and practical GRC advice and support.
  • Deliver high‑quality, professional services to internal stakeholders by adhering to internal policies, procedures, and agreed service level expectations.
  • Build and maintain effective working relationships with business units, technology teams, and control functions to support information security risk and compliance activities.
  • Communicate clearly and constructively with internal stakeholders to enable consistent, efficient, and positive engagement.
  • Contribute to a collaborative team environment, demonstrating professionalism, accountability, and a strong commitment to supporting internal customers and shared objectives.

Management and Compliance

  • Operate as part of the second line of defence, supporting independent oversight and effective challenge of information security and AI‑related risks, controls, and risk treatment activities across the Bank.
  • Support alignment of information security risk management practices with the Bank’s Total Corporate Risk Management Governance (TCRMG) framework and recognised standards, including NIST and ISO/IEC 27001/27005.
  • Assist with the identification, assessment, documentation, reporting, and escalation of information security risks, ensuring consistency with the Bank’s risk appetite and regulatory expectations.
  • Contribute to the preparation and coordination of information security‑related audits, regulatory reviews, and assurance activities, ensuring timely, accurate, and complete responses.
  • Prepare information security and GRC reports, analyses, and documentation promptly and to a high standard, as required by management and stakeholders.

Learning and Growth

  • Proactively develop and maintain a personal development plan, aligned with role requirements and discussed regularly with the line manager.
  • Seek and provide constructive feedback to support continuous improvement in ways of working, service quality, and professional conduct.
  • Commit to continuous learning by staying up to date with the Bank’s policies, procedures, risk frameworks, regulatory requirements, and relevant information security and AI governance practices.
  • Apply acquired knowledge and skills to enhance individual performance, contribute effectively to team objectives, and support the ongoing maturity of the Information Security GRC function.
Qualifications and Skills

Qualifications

  • Bachelor’s or Master’s degree in Information Technology, Computer Science, Information Security, or a related technical or risk management discipline.
  • One or more of CISSP, CISM, ISO27001, CRISC, CGRC, COBIT, COSO

Experience

  • Minimum of 5 years’ professional experience in Information Technology, Information Security, or related fields, with demonstrable exposure to governance, risk, and compliance activities.
  • Good working knowledge of information security and risk management frameworks and standards, such as NIST, ISO/IEC 27001/27005, COBIT, COSO, ISACA, and ISC².
  • Hands‑on experience supporting the development, implementation, or maintenance of information security GRC processes, including risk assessments, compliance activities, policy management, or assurance support.
  • Experience developing, reviewing, or maintaining information security documentation, such as policies, standards, procedures, risk registers, and assessment artefacts.
  • Strong analytical skills with the ability to assess information, identify issues, and clearly summarise findings for reporting and follow‑up actions.
  • Effective written and verbal communication skills, with the ability to engage constructively with technical and non‑technical stakeholders.
  • High level of integrity, professionalism, and accountability, with a strong attention to accuracy and detail.
  • Experience supporting audits, regulatory reviews, or internal assurance activities.
  • Exposure to AI, data‑driven technologies, or technology risk governance is an advantage.
How to Apply
NameMs. HENG Sokhor (SanSan)
TitleRecruitment Consultant
Phone Number+855 93228868 /
EmailHENG.Sokhor@hrinc.com.kh
AddressThe Edge Phnom Penh, House No. A9-A10, Ayasmayan East Street (St. 139), Phum 1, Sangkat Sras Chork, Khan Daun Penh, Phnom Penh
Other opening vacancies from HRINC (Cambodia) Co., Ltd

To support us!
Please mention www.hrincjobs.com as a source you found the job in your applied email.

Related Jobs

https://hrincjobs-pro.s3.amazonaws.com/media/public/filer_public/3b/cc/3bccd1de-6140-4c7e-94ed-d0d3eb9c4981/mef_logo_transparent.png
Data Engineer

Ministry of Economy and Finance (MEF)

Apr 21, 2026
https://hrincjobs-pro.s3.amazonaws.com/media/public/filer_public/3b/cc/3bccd1de-6140-4c7e-94ed-d0d3eb9c4981/mef_logo_transparent.png
IT Research and Innovation

Ministry of Economy and Finance (MEF)

Apr 22, 2026
https://hrincjobs-pro.s3.amazonaws.com/media/public/filer_public/3b/cc/3bccd1de-6140-4c7e-94ed-d0d3eb9c4981/mef_logo_transparent.png
Senior Network & Security Engineer

Ministry of Economy and Finance (MEF)

Apr 22, 2026
https://hrincjobs-pro.s3.amazonaws.com/media/public/filer_public/3b/cc/3bccd1de-6140-4c7e-94ed-d0d3eb9c4981/mef_logo_transparent.png
Full Stack Developer

Ministry of Economy and Finance (MEF)

Apr 22, 2026
https://hrincjobs-pro.s3.amazonaws.com/media/public/filer_public/3b/cc/3bccd1de-6140-4c7e-94ed-d0d3eb9c4981/mef_logo_transparent.png
Application Administrator

Ministry of Economy and Finance (MEF)

Apr 22, 2026
https://hrincjobs-pro.s3.amazonaws.com/media/public/filer_public/3b/cc/3bccd1de-6140-4c7e-94ed-d0d3eb9c4981/mef_logo_transparent.png
Data Science and AI Specialist

Ministry of Economy and Finance (MEF)

Apr 22, 2026
https://hrincjobs-pro.s3.amazonaws.com/media/public/filer_public/3b/cc/3bccd1de-6140-4c7e-94ed-d0d3eb9c4981/mef_logo_transparent.png
System Functional QA Officer

Ministry of Economy and Finance (MEF)

Apr 22, 2026
https://hrincjobs-pro.s3.amazonaws.com/media/public/filer_public/3b/cc/3bccd1de-6140-4c7e-94ed-d0d3eb9c4981/mef_logo_transparent.png
Senior IT Security Engineer

Ministry of Economy and Finance (MEF)

Apr 22, 2026
https://hrincjobs-pro.s3.amazonaws.com/media/public/filer_public/de/0a/de0a8f36-8302-4f8d-bbf3-5e32badcf0f4/hrinc_sq_logo.png
Head of Information Security Risk Management

HRINC (Cambodia) Co., Ltd

May 9, 2026
https://hrincjobs-pro.s3.amazonaws.com/media/public/filer_public/de/0a/de0a8f36-8302-4f8d-bbf3-5e32badcf0f4/hrinc_sq_logo.png
Senior Associate, Technology Services

HRINC (Cambodia) Co., Ltd

Apr 17, 2026
https://hrincjobs-pro.s3.amazonaws.com/media/public/filer_public/4e/7d/4e7db4f1-61f6-4e77-8815-0791d2dca7e5/photo_2026-03-18_13-43-32.jpg
Engineer Manager

ZTE HK Cambodia

Apr 19, 2026
https://hrincjobs-pro.s3.amazonaws.com/media/public/filer_public/21/5b/215bdeff-fa4d-4678-acf1-2286fc5aa5c5/cbvh_logo_for_telegram_chanel-02.png
IT Business Solution Manager

CBVH.

May 3, 2026
https://hrincjobs-pro.s3.amazonaws.com/media/public/filer_public/ad/b1/adb18558-261e-43c5-85d3-b101b1fb6d63/sm_global_accounting__consulting.png
IT Support

SM Global Accounting & Consulting Co., Ltd

Apr 30, 2026
https://hrincjobs-pro.s3.amazonaws.com/media/public/filer_public/0e/b3/0eb38a54-b3f2-4141-bab0-96b9f9a6e0e1/screenshot_2026-03-17_131812.png
IT Intern

NAKI Group

Apr 16, 2026