[What the role is]As an Assistant Manager in the Governance, Risk and Compliance (GRC) team within the Security, Process and Governance department, Digital Technology Transformation division, you will be responsible for tracking, managing, and reporting on the risk management and governance of ICT and Smart Systems (ICTSS) at Sentosa Development Corporation (SDC).
Reporting to the GRC Manager, you will manage systems under GRC custody, including the IT Service Management (ITSM) system for service/change requests and incident reporting, Project & Portfolio Management, Compliance tracking, Digital Governance Platform, and maintenance of GRC knowledge bases and document repositories.
You will collaborate with system managers to maintain the SDC system inventory, track system changes, conduct periodic and ad hoc cybersecurity testing, perform IT risk assessments, audits, and follow up on findings until resolution.
[What you will be working on]- Managing GRC systems (e.g., ITSM, DGP, etc.)
- Maintaining the GRC knowledge base, guidelines, forms, and templates in SharePoint Online repository
- Coordinating the tracking and reporting of ICT & Smart Systems (ICTSS) delivery and support projects under Project & Portfolio Management
- Supporting the GRC Manager in updating ICTSS policies and System Security Plans (SSPs)
- Working with security testing vendors to track and report on periodic Vulnerability Assessment and Penetration Testing (VAPT)/Security Configuration Review (SCR) security tests, and liaising with system managers to address findings promptly
- Coordinating IT audit review sessions and responses with relevant stakeholders
[What we are looking for]- Diploma or Degree in Information Technology or related field
- Minimum of 2 years' experience in IT application system lifecycle management and/or system support and management
- Familiarity with data and cybersecurity risks and controls during system implementation and support, including VA/PT and SCR for cloud-hosted, web-based, and mobile solutions
- Understanding of IT risk management and controls
- Experience with system audits and/or public sector system policies and governance is advantageous
- Ability to handle occasional tight deadlines and manage project constraints in a dynamic environment, including ad hoc risk profiling and compliance reporting
- Familiarity with government procurement processes
- Good communication skills, both written and spoken