Position: Cyber Risk / GRC Consultant
Salary: SGD 5,500 - SGD 9,000 / month (commensurate with experience)
About the Role
Recruit123 is partnering with our client, an established Singapore-based organisation, to hire a Cyber Risk / GRC Consultant to join their cybersecurity team. In this role, you will play a central part in strengthening the organisation's information security governance, risk management processes, and regulatory compliance posture.
Key Responsibilities
- Develop, implement, and maintain information security governance frameworks, policies, and standard operating procedures.
- Conduct comprehensive cyber risk assessments to identify, evaluate, and prioritize technical and operational security risks.
- Ensure organizational compliance with Singapore regulatory requirements and international standards (e.g., ISO/IEC 27001, PDPA, MAS TRM Guidelines, CSA Cybersecurity Code of Practice).
- Coordinate internal and external security audits, managing evidence gathering, stakeholder interviews, and audit remediation roadmaps.
- Perform third-party and vendor security risk assessments to evaluate the cyber posture of external partners and suppliers.
- Support business continuity (BCP) and disaster recovery (DR) planning and testing alongside operational stakeholders.
- Conduct security awareness sessions to drive an active culture of risk management across business units.
- Prepare actionable risk registers, dashboards, and executive reports for senior leadership and audit committees.
- Track identified vulnerabilities, control gaps, and audit findings through to resolution.
- Monitor emerging cyber regulations, threat landscapes, and industry best practices.
Requirements
- Degree or Diploma in Cybersecurity, Information Security, Computer Science, Risk Management, or a related discipline.
- Minimum 3 to 6 years of direct experience in cyber risk, GRC, IT audit, or information security compliance.
- Relevant industry certifications strongly preferred (e.g., CISA, CISM, CRISC, ISO 27001 Lead Auditor / Implementer).
- Strong working knowledge of standard security frameworks (ISO 27001, NIST CSF) and Singapore regulatory expectations (MAS TRM, PDPA, CSA guidelines).
- Practical experience leading risk assessments, audit fieldwork, and vendor reviews.
- Excellent analytical, documentation, and technical report-writing abilities.
- Strong communication skills, with the ability to articulate risk concepts clearly to technical teams and business executives.
- Prior background in professional services, IT audit, or advisory firms is advantageous.
What's on Offer
- Competitive monthly base salary ranging from SGD 5,500 to SGD 9,000, tailored to technical depth and credentials.
- Hands-on ownership of enterprise-grade security and governance initiatives.
- Company sponsorship and support for professional security certifications (e.g., CISA, CISM).
- Clear career development pathway toward Senior GRC Manager and CISO-track roles.