1 week ago

IT Governance Analyst

Fusang

Remote

📍 On-site

Category: SecuritySubcategory: Compliance & RiskType: Full-time


About Fusang

Fusang is Asia’s first fully-regulated digital securities exchange, pioneering the convergence of traditional finance and blockchain technology.

Licensed by the Labuan Financial Services Authority, we created the world’s first institutional tokenised sukuk—recognised with the IFN Most Innovative Deal 2023 award. With over USD 410 million in tokenised instruments issued, we’re proving that regulated digital securities are the future of capital markets.

Our mission is to build the digital superhighway for traditional finance, making investment opportunities more accessible globally. Backed by 40 years of wealth management expertise through our relationship with Portcullis Group, we combine startup innovation with institutional credibility.

We’re looking for exceptional people who want to shape the future of finance.

Role Overview:

As a licensed digital securities exchange, Fusang operates under the scrutiny of regulators, institutional clients, and external auditors. Our clients run rigorous due diligence processes. Our regulators expect documented, enforceable policies. Our infrastructure must remain continuously monitored to prevent lapses in certificates, domain registrations, and compliance obligations.

We are seeking an IT Governance Analyst to own the operational backbone of our IT governance, compliance, and internal technical audit function. You will maintain the IT policy framework, monitor adherence to processes, respond to regulatory and client security inquiries, and ensure that nothing—a certificate expiry, a policy gap, or an unanswered audit request—falls through the cracks.

While this is not a cybersecurity engineering role, it requires strong technical acumen to act as an effective internal technical auditor. Rather than relying on self-reported evidence or screenshots provided by engineers, you will use your technical skills to establish the true "source of truth." You will independently log into various environments—including cloud systems, Web Application Firewalls (WAF), cybersecurity tools, corporate IT platforms, and SaaS applications—to directly inspect live configurations, audit permissions, and review logs to ensure absolute compliance and regulatory readiness.

Key Responsibilities:

Technical Audit & Source-of-Truth Inspection

  • Independent System Inspection: Directly log into systems—including cloud environments, Web Application Firewalls (WAF), cybersecurity tools, corporate IT infrastructure, and SaaS platforms—to review live configurations and system logs independently.
  • Source-of-Truth Verification: Validate security controls and policy compliance through direct system-level inspection, moving beyond reliance on engineer-provided screenshots or self-reported attestations.
  • Internal Compliance Auditing: Function as an internal technical auditor to continuously test live system parameters and access controls against regulatory requirements, industry benchmarks, and internal policies.
  • Control Drift & Gap Detection: Spot-check access privileges, security rules, and parameter settings to proactively detect configuration drift, unapproved changes, or policy deviations.
  • Audit Evidence Management: Gather and maintain verifiable, system-generated logs and evidentiary artifacts to ensure seamless readiness for regulatory inspections and external audits.

IT Policy & Process Governance

  • Maintain and update the IT policy library (acceptable use, access control, change management, incident response, data classification, vendor management, etc.)
  • Conduct scheduled policy reviews against regulatory requirements and industry frameworks
  • Track organisation-wide policy acknowledgement and follow up on non-compliance
  • Identify process gaps through internal reviews and work with teams to close them
  • Document and maintain standard operating procedures (SOPs) for key IT processes

Regulatory & Client Compliance

  • Respond to regulatory inquiries and information requests from MAS, SFC, Labuan FSA, and equivalent bodies
  • Complete client security questionnaires, due diligence questionnaires (DDQs), and third-party risk assessments
  • Prepare and maintain evidence packs and control documentation for audits (ISO 27001, SOC 2, internal and external audits)
  • Coordinate with Legal, Finance, and Operations to ensure alignment on regulatory obligations
  • Track regulatory changes and assess impact on existing policies and controls

Certificate & Asset Lifecycle Management

  • Maintain a centralised inventory of SSL/TLS certificates, domain registrations, software licences, and SaaS subscriptions
  • Track renewal dates and coordinate with IT, DevOps, and vendors to ensure no lapses or service disruptions
  • Document renewal processes and establish escalation procedures for time-sensitive renewals
  • Maintain an up-to-date IT asset register for hardware, software, and cloud resources

Risk & Vendor Governance

  • Maintain the IT risk register, track risks, mitigations, owners, and review cycles
  • Support third-party vendor assessments and due diligence reviews prior to onboarding
  • Monitor vendor compliance with contractual security obligations and SLAs
  • Assist in Business Continuity Planning (BCP) and Disaster Recovery (DR) documentation and testing

Security Awareness & Training

    • Coordinate IT security awareness programmes and phishing simulation exercises
    • Track completion of mandatory compliance training across the organisation
    • Maintain and update onboarding materials related to IT policies and acceptable use

Requirements:

Required

  • Bachelor's degree in Information Technology, Computer Science, Business, or a related field
  • Minimum 5 years of experience in IT governance, GRC (Governance, Risk & Compliance), IT compliance, or technology risk roles
  • Experience with AWS, Cloudflare, GPO and Active Directory settings and logs.
  • Hands-on experience with at least one compliance framework: ISO 27001, SOC 2, MAS TRM, or equivalent
  • Experience responding to regulatory inquiries or client security questionnaires and DDQs
  • Demonstrated ability to manage a policy lifecycle — drafting, reviewing, approving, and enforcing IT policies
  • Experience maintaining certificate inventories, software licence registers, or similar asset tracking
  • Strong documentation skills — you write policies, procedures, and audit evidence packs that hold up under scrutiny
  • Good English communication skills — written and verbal, including executive-level reporting
  • AI-Assisted Productivity: Comfort using AI-assisted tools such as Claude Code or similar to improve documentation efficiency and workflow automation

Preferred

  • Professional certification: CISA, CRISC, ISO 27001 Lead Implementer/Auditor, or CompTIA Security+
  • Experience in financial services, fintech, or a regulated industry (MAS, SFC, Labuan FSA)
  • Exposure to corporate secretary, trust administration, fund administration, and digital assets.

Share This Job

Apply for this position

Interested? Click below to submit your application.

Apply to this job