Jobiglo

No results.

Technology Risk & Compliance Consultant & Penetration Tester

iValue Group · Phnom Penh

🇬🇧 English
ISO 27001 implementation ISO 27002 NIST Cybersecurity Framework CIS Controls PCI DSS Risk assessment IT General Controls (ITGC) assessment Cloud security Vulnerability assessment Attack simulation Source code review

Job description

About the role

We are looking for experienced professionals to join our security team as Technology Risk & Compliance Consultants and Penetration Testers. You will help clients assess technology risk, achieve compliance, and improve their security posture across cloud, applications, and infrastructure.

Key responsibilities

  • Conduct technology risk gap assessments for IT infrastructure, applications, cloud services, and operational environments.
  • Perform compliance readiness and maturity assessments against ISO 27001, ISO 27002, NIST Cybersecurity Framework, CIS Controls, PCI DSS and other regulatory requirements.
  • Develop risk registers, treatment plans, remediation roadmaps and lead ISO 27001 implementation projects.
  • Execute penetration testing of web and mobile applications, APIs, internal networks and external infrastructure, including vulnerability assessments and attack simulations.
  • Validate remediation actions, produce detailed technical reports and present findings to stakeholders.
  • Support third‑party risk assessments, vendor security reviews and advise on security governance best practices.

Required profile

  • Bachelor’s degree in Information Security, Computer Science, Information Systems or related field.
  • 5+ years of experience in information security, IT risk, compliance or audit.
  • Strong knowledge of ISO 27001/27002, risk management frameworks, ITGC assessments and cloud security fundamentals.
  • Hands‑on experience with penetration testing tools and methodologies for web, mobile, API and infrastructure targets.
  • Relevant certifications such as CISSP, CISA, CISM, ISO 27001 Lead Auditor/Implementer, CRISC are preferred.

Required skills

  • ISO 27001 implementation and certification readiness
  • Risk assessment and gap analysis
  • IT General Controls (ITGC) assessment
  • Cloud security assessment
  • Penetration testing (web, mobile, APIs, infrastructure)
  • Vulnerability assessment and attack simulation
  • Source code review

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec iValue Group.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

Apply now →

By continuing, you accept our terms of use.

Already have an account? Login

A question about this job?

Ask it here: you will get the full job summary by e-mail, right away.

💬 Chat with us on Telegram

Published 1 month ago

Expires 1 week from now

12 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

iValue Group

Phnom Penh