Jason Ong

Jason Ong

IT Audit Manager

Followers of Jason Ong493 followers
location of Jason OngShah Alam, Selangor, Malaysia

Connect with Jason Ong to Send Message

Connect

Connect with Jason Ong to Send Message

Connect
  • Timeline

  • About me

    Pragmatic IT Risk and Compliance Advocate in Quality Management and Validation with A Dash of Security Management

  • Education

    • Universiti Sains Malaysia

      2000 - 2004
      Bachelor of Computer Science Information Technology
  • Experience

    • CSC

      Jun 2009 - Aug 2012
      IT Audit Manager

      1. Manage internal and external audit engagements. Manage audit activities including compliance assurance, audit support and management responses.2. Manage audit entry meetings, pre exit meetings, exit meetings and post mortem meetings.3. Manage and conduct internal audits on IT Service Delivery with reference to external compliance and audit standards, guidelines, policy and procedures.4. Prepare internal audit plans and audit work programs along with audit scripts with reference to audit plans.5. Responsible for audit management reporting on Account Management and Asia Regional Management (on audit finding, risk, root cause and remediation).6. Assist in compliance and audit remediation. Review remediation artifacts and perform relevant tests to ascertain audit remediation are completed in full. Show less

    • GSK

      Aug 2012 - Oct 2018
      Computer System Validation Lead

      A key position within the Manufacturing Quality organisation with major responsibilities in: 1. ensuring adherence to strict GSK Quality Management System procedures and governance plans including driving of corrective action planning. 2. providing quality approvals for key validation documentation to ensure and confirm compliance with the Quality Management System procedures and governance plans. 3. being the quality authority for projects and change requests responsible for providing the final approval before Go-Live or implementation 4. ensuring the completion of periodic compliance reviews against global, regional and local quality regulation standards and expectations Show less

    • AmBank Group

      Oct 2018 - Nov 2019
      VP, Security Management

      Managing the compliance obligations to regulatory security requirements, internal security standards, as well as adopting external industry best practices on security technologies to ensure the security interest of the bank is continuously safeguarded and improved where necessary. In this role I also managed external audit and assessment engagements from regulators, vendors and partners while owning the liaison responsibilities with internal auditors and compliance officers. This is a vital role within the IT security governance framework of the bank and is also consistently a primary focal point that coordinates the various prevention, remediation and improvement initiatives across multiple IT disciplines and operations teams. A key policymaker in the Sailpoint project and successfully rolled out the system across all the major systems in the bank to elevate the Identity and Access Management infrastructure and updated the supporting processes. Show less

    • Roche

      Nov 2019 - now
      Information Technology Quality Specialist

      As part of Roche Informatics' IT Security, Quality, and Compliance team, I provide governance and oversight for computerized systems that enable high-quality solutions impacting over 10,000 Roche members worldwide. My role ensures IT systems and services meet stringent regulatory standards (CSV, GMP, GCP) and that compliance risks are managed effectively to protect Roche's right to operate and foster innovation.In this role, I am:1. Collaborating across business units (pRED, Dia, PD, PT, RSS) and IT to deliver quality and compliance efficiently, integrating cutting-edge technologies like cloud services and AI.2. Shaping and implementing digital compliance roadmaps, product lifecycles, and IT governance frameworks in alignment with stakeholder needs.3. Developing and revising global standards for Computer Systems Validation (CSV) and providing consultation on regulatory compliance.4. Enabling automated monitoring, tracking quality insights, and ensuring adherence to GxP, data privacy, and regulatory standards.5. Partnering with senior/global leaders to maintain compliance and ensure stability and transparency in product governance.6. Fostering a "One Roche" mindset by connecting and collaborating across teams to drive improvement and innovation.My work balances regulatory rigor with agility, empowering Roche to deliver patient-centric solutions while embracing technological advancements. Show less

  • Licenses & Certifications