Fusang logo

IT Governance Analyst

Fusang

Federal Territory Labuan & Kuala Lumpur / Johor, MalaysiaFull-timePosted Oct 6, 2026

Job description

About Fusang Fusang is Asia’s first fully-regulated digital securities exchange, pioneering the convergence of traditional finance and blockchain technology. Licensed by the Labuan Financial Services Authority, we created the world’s first institutional tokenised sukuk—recognised with the IFN Most Innovative Deal 2023 award.

With over USD 410 million in tokenised instruments issued, we’re proving that regulated digital securities are the future of capital markets. Our mission is to build the digital superhighway for traditional finance, making investment opportunities more accessible globally. Backed by 40 years of wealth management expertise through our relationship with Portcullis Group, we combine startup innovation with institutional credibility.

We’re looking for exceptional people who want to shape the future of finance. Role Overview: As a licensed digital securities exchange, Fusang operates under the scrutiny of regulators, institutional clients, and external auditors. Our clients run rigorous due diligence processes. Our regulators expect documented, enforceable policies.

Our infrastructure must remain continuously monitored to prevent lapses in certificates, domain registrations, and compliance obligations. We are seeking an IT Governance Analyst to own the operational backbone of our IT governance, compliance, and internal technical audit function. You will maintain the IT policy framework, monitor adherence to processes, respond to regulatory and client security inquiries, and ensure that nothing—a certificate expiry, a policy gap, or an unanswered audit request—falls through the cracks.

While this is not a cybersecurity engineering role, it requires strong technical acumen to act as an effective internal technical auditor. Rather than relying on self-reported evidence or screenshots provided by engineers, you will use your technical skills to establish the true "source of truth." You will independently log into various environments—including cloud systems, Web Application Firewalls (WAF), cybersecurity tools, corporate IT platforms, and SaaS applications—to directly inspect live configurations, audit permissions, and review logs to ensure absolute compliance and regulatory readiness.

Key Responsibilities

Technical Audit & Source-of-Truth Inspection Independent System Inspection: Directly log into systems—including cloud environments, Web Application Firewalls (WAF), cybersecurity tools, corporate IT infrastructure, and SaaS platforms—to review live configurations and system logs independently. Source-of-Truth Verification: Validate security controls and policy compliance through direct system-level inspection, moving beyond reliance on engineer-provided screenshots or self-reported attestations.

Internal Compliance Auditing: Function as an internal technical auditor to continuously test live system parameters and access controls against regulatory requirements, industry benchmarks, and internal policies. Control Drift & Gap Detection: Spot-check access privileges, security rules, and parameter settings to proactively detect configuration drift, unapproved changes, or policy deviations.

Audit Evidence Management: Gather and maintain verifiable, system-generated logs and evidentiary artifacts to ensure seamless readiness for regulatory inspections and external audits. IT Policy & Process Governance Maintain and update the IT policy library (acceptable use, access control, change management, incident response, data classification, vendor management, etc.)

Conduct scheduled policy reviews against regulatory requirements and industry frameworks Track organisation-wide policy acknowledgement and follow up on non-compliance Identify process gaps through internal reviews and work with teams to close them Document and maintain standard operating procedures (SOPs) for key IT processes Regulatory & Client Compliance Respond to regulatory inquiries and information requests from MAS, SFC, Labuan FSA, and equivalent bodies Complete client security questionnaires, due diligence questionnaires (DDQs), and third-party risk assessments Prepare and maintain evidence packs and control documentation for audits (ISO 27001, SOC 2, internal and external audits) Coordinate with Legal, Finance, and Operations to ensure alignment on regulatory obligations Track regulatory changes and assess impact on existing policies and controls Certificate & Asset Lifecycle Management Maintain a centralised inventory of SSL/TLS certificates, domain registrations, software licences, and SaaS subscriptions Track renewal dates and coordinate with IT, DevOps, and vendors to ensure no lapses or service disruptions Document renewal processes and establish escalation procedures for time-sensitive renewals Maintain an up-to-date IT asset register for hardware, software, and cloud resources Risk & Vendor Governance Maintain the IT risk register, track risks, mitigations, owners, and review cycles Support third-party vendor assessments and due diligence reviews prior to onboarding Monitor vendor compliance with contractual security obligations and SLAs Assist in Business Continuity Planning (BCP) and Disaster Recovery (DR) documentation and testing Security Awareness & Training Coordinate IT security awareness programmes and phishing simulation exercises Track completion of mandatory compliance training across the organisation Maintain and update onboarding materials related to IT policies and acceptable use Requirements: Required Bachelor's degree in Information Technology, Computer Science, Business, or a related field Minimum 5 years of experience in IT governance, GRC (Governance, Risk & Compliance), IT compliance, or technology risk roles Experience with AWS, Cloudflare, GPO and Active Directory settings and logs.

Hands-on experience with at least one compliance framework: ISO 27001, SOC 2, MAS TRM, or equivalent Experience responding to regulatory inquiries or client security questionnaires and DDQs Demonstrated ability to manage a policy lifecycle — drafting, reviewing, approving, and enforcing IT policies Experience maintaining certificate inventories, software licence registers, or similar asset tracking Strong documentation skills — you write policies, procedures, and audit evidence packs that hold up under scrutiny Good English communication skills — written and verbal, including executive-level reporting AI-Assisted Productivity: Comfort using AI-assisted tools such as Claude Code or similar to improve documentation efficiency and workflow automation Preferred Professional certification: CISA, CRISC, ISO 27001 Lead Implementer/Auditor, or CompTIA Security+ Experience in financial services, fintech, or a regulated industry (MAS, SFC, Labuan FSA) Exposure to corporate secretary, trust administration, fund administration, and digital assets.

More jobs at Fusang

See all openings at Fusang

More jobs in Johor Bahru

See all jobs in Johor Bahru