Cybersecurity Governance and Assurance Specialist

NETS

Singapore

On-site

SGD 120,000 - 180,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

NETS in Singapore seeks an Information Security professional to manage and enforce IS policies, processes and controls across the organisation. You will partner with internal stakeholders to drive cyber risk management and support audit activities.

You will implement frameworks (ISO27000, NIST), align with Cyber Hygiene and PDPA regulations, develop risk metrics, and communicate policy changes to teams to strengthen governance.

Qualifications

  • Degree in Computer Science, Engineering or related disciplines.
  • 6+ years in information security with policy development, risk assessment, compliance & governance.
  • Strong knowledge of enterprise security risk management methods and techniques.
  • Experience implementing a program for security metrics (KRI) such as vulnerability management, open software vulnerabilities, pen tests, alerts & incidents.
  • Experience with ISO27000, NIST, Cyber Hygiene, Technology Risk Management Guidelines and PDPA regulations.
  • Ability to work in a team and deliver high quality results with minimal supervision.
  • Willingness to deep-dive into Information Security in payments domain.
  • Strong writing, communication and inter-personal skills.

Responsibilities

  • Responsible for management and enforcement of IS related policies, processes and procedures.
  • Execute policies and procedures to facilitate cyber risk process and control from audit findings or process maturity.
  • Partner with stakeholders to identify and implement cyber risk process improvements.
  • Reference regulator notices/guidelines (TRM, Cyber Hygiene) to assess risk and work with Line 2 and Tech to improve policies.
  • Prepare and provide data for risk analysis and reporting.
  • Communicate and provide guidance of new IS policies to stakeholders.
  • Support IS audits, regulatory inspections, risk and compliance activities.
  • Review audit findings to determine root cause and verify remedial actions.
  • Support audit lifecycle from kickoff to closure.
  • Innovate and automate as required.

Skills

Security risk management
Security metrics program
Security frameworks (ISO27000, NIST)
Team player
Willingness to learn
Communication
Written communication
Interpersonal skills

Education

Degree in Computer Science, Engineering or related

Job description

  • Responsible for the management and enforcement of IS related policies, processes and procedures.
  • Execute policies, processes and procedures to facilitate effective Cyber related-risk Process and Control arising from Audit Findings or Process improvement maturity
  • Partner and work with internal stakeholders to review, identify, streamline and implement process improvements with regards to Cyber risk management
  • Reference to regulator’s notices, circulares and guidelines (such as, TRM, Cyber Hygiene) to assess risk and gaps, and work with Line 2 and Tech to improve policies and processes to mitigate risks, minimize their impact to operations
  • Prepare and provide data for risk analysis and reporting.
  • Communicate and provide guidance of new IS policies and standards to relevant stakeholders.
  • Support IS related audits, regulatory inspections, Risk and Compliance activities and providing support to business audits that have IS involvement.
  • Review the audit findings with key stakeholders to determine audit findings root cause, formulate action plans accordingly and verify remedial solutions for closure
  • Support audit lifecycle from start to end (eg kick off meeting, RFI, fieldwork, reporting and closure of audit findings).
  • Ability to innovate and automate as required

Requirements

  • Degree in Computer Science, Engineering or any other related disciplines with at least 6 years of progressive experience in Information security, including experience in security policy development, risk assessment, compliance implementation & monitoring and governance
  • Good working knowledge of enterprise security risk management methods and techniques to successfully deliver the security risk management and assessment outcome.
  • Prior experience in implementing a program which includes the collation, management and reporting of security metrics (KRI) such as vulnerability management, open software security vulnerabilities, penetration testing findings, security alerts and incidents
  • Experienced in information security frameworks including ISO27000 standard, NIST framework and regulations such as Cyber Hygiene Notice, Technology Risk Management Guidelines and Personal Data Protection Act.
  • Ability to work in a team environment and work independently with minimal supervision and produce results that meet standards of quality, timeliness and acceptability
  • Willingness to deep-dive and learn about the Information Security function within the payments domain
  • Strong writing, communication and inter‐personal skills
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AVP, Security Governance & Assurance
AVP, Security Governance & Assurance

NETS • Singapore

On-site
SGD 120,000 - 180,000
VP, Security Governance & Assurance
VP, Security Governance & Assurance

NETS • Singapore

On-site
SGD 180,000 - 240,000
Security Governance and Assurance Engineer
Security Governance and Assurance Engineer

NETS • Singapore

On-site
SGD 120,000 - 180,000
Senior Security Analyst (Governance, Risk and Compliance)
Senior Security Analyst (Governance, Risk and Compliance)

energy market company • Singapore

On-site
SGD 120,000 - 180,000
Specialist
Specialist

NTUC First Campus Co-operative Ltd • Singapore

On-site
SGD 90,000 - 120,000
Senior Security Analyst (Governance, Risk and Compliance)
Senior Security Analyst (Governance, Risk and Compliance)

energy market company pte ltd • Shenton Way

On-site
SGD 120,000 - 180,000
Specialist (Cybersecurity)
Specialist (Cybersecurity)

NTUC FIRST CAMPUS LIMITED • Singapore

On-site
SGD 70,000 - 120,000
Cybersecurity Engineering Manager
Cybersecurity Engineering Manager

NETS • Singapore

On-site
SGD 180,000 - 280,000
Cybersecurity and Technology Risk Manager, Global MNC
Cybersecurity and Technology Risk Manager, Global MNC

Kerry Consulting • Singapore

On-site
SGD 150,000 - 220,000
IT Security Governance and Assurance Lead
IT Security Governance and Assurance Lead

Network For Electronic Transfers (S) • Singapore

On-site
SGD 180,000 - 240,000