Cybersecurity Lead

Flo Energy

Singapore

On-site

SGD 180,000 - 260,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Flo Energy is seeking a Security Governance Lead to drive the governance, risk and assurance function within its cybersecurity programme. This role will establish robust governance practices, ensure regulatory compliance, maintain an effective control environment, and provide independent oversight of enterprise cybersecurity risks.

Working closely with Engineering and Platform (DevOps) teams, you will integrate security into the software development lifecycle and cloud environments.

Qualifications

  • 8-12 years of experience in cybersecurity governance, technology risk, compliance or information security assurance.
  • Experience operating within a regulated environment with exposure to regulatory frameworks and technology risk management.
  • Proven experience developing governance frameworks, managing enterprise risk registers and leading control assurance programmes.
  • Strong experience preparing policies, audit responses, executive reporting and regulatory documentation.
  • Good understanding of cybersecurity frameworks and enterprise risk management practices.
  • Experience performing control testing, evidence validation and compliance assessments.
  • Knowledge of third-party risk management and supplier security assurance.
  • Familiarity with cloud security governance and emerging technology risks, including AI, would be advantageous.

Responsibilities

  • Develop, maintain and continuously improve enterprise cybersecurity policies, standards and governance documentation.
  • Establish governance processes to ensure policies remain current, effective and aligned with business and regulatory requirements.
  • Develop operational procedures that enable consistent execution of governance and assurance activities.
  • Partner with engineering teams to ensure security requirements are embedded into day-to-day operations.
  • Lead risk assessments across technology platforms, operational processes, cloud services and third-party providers.
  • Oversee security exception governance, including compensating controls, approvals, review cycles and risk acceptance.
  • Work with technology teams to translate identified risks into practical remediation plans.
  • Maintain alignment with applicable regulatory requirements and recognised cybersecurity frameworks.
  • Design and manage a continuous control assurance programme through control testing, evidence validation and periodic reviews.
  • Maintain an audit-ready evidence repository supporting internal audits, external assessments and regulatory reviews.
  • Coordinate audit responses and oversee remediation activities arising from assurance engagements.
  • Develop meaningful cybersecurity risk metrics, KRIs and governance dashboards for senior management.
  • Support governance committees through agenda preparation, risk reporting and action tracking.
  • Prepare executive updates covering cyber risk posture, compliance status and key security initiatives.

Skills

Cybersecurity governance
Technology risk management
Regulatory compliance
Policy development
Audit & assurance
Executive reporting
Third-party risk management
Cloud security governance
AI risk awareness

Job description

Flo is looking for a Security Governance Lead to drive the governance, risk and assurance function within its cybersecurity programme. This role will be responsible for establishing robust governance practices, ensuring regulatory compliance, maintaining an effective control environment, and providing independent oversight of enterprise cybersecurity risks.

Working closely with horizontal and vertical engineering teams, the lead will ensure governance processes evolve with the regulatory needs of the organisation.

You will also work closely with Engineering and Platform (DevOps) teams to integrate security into the software development lifecycle and cloud environments. This role will involve shaping the Cybersecurity function, governance and policies while remaining hands-on whenever necessary.

What you'll do:
Security Governance & Policy
  • Develop, maintain and continuously improve enterprise cybersecurity policies, standards and governance documentation.
  • Establish governance processes to ensure policies remain current, effective and aligned with business and regulatory requirements.
  • Develop operational procedures that enable consistent execution of governance and assurance activities.
  • Partner with engineering teams to ensure security requirements are embedded into day-to-day operations.
Technology Risk Management
  • Lead risk assessments across technology platforms, operational processes, cloud services and third-party providers.
  • Oversee security exception governance, including compensating controls, approvals, review cycles and risk acceptance.
  • Work with technology teams to translate identified risks into practical remediation plans.
Assurance & Regulatory Compliance
  • Maintain alignment with applicable regulatory requirements and recognised cybersecurity frameworks.
  • Design and manage a continuous control assurance programme through control testing, evidence validation and periodic reviews.
  • Maintain an audit-ready evidence repository supporting internal audits, external assessments and regulatory reviews.
  • Coordinate audit responses and oversee remediation activities arising from assurance engagements.
Reporting & Stakeholder Management
  • Develop meaningful cybersecurity risk metrics, KRIs and governance dashboards for senior management.
  • Support governance committees through agenda preparation, risk reporting and action tracking.
  • Prepare executive updates covering cyber risk posture, compliance status and key security initiatives.
Qualifications
  • 8-12 years of experience in cybersecurity governance, technology risk, compliance or information security assurance.
  • Experience operating within a regulated environment with exposure to regulatory frameworks and technology risk management.
  • Proven experience developing governance frameworks, managing enterprise risk registers and leading control assurance programmes.
  • Strong experience preparing policies, audit responses, executive reporting and regulatory documentation.
  • Good understanding of cybersecurity frameworks and enterprise risk management practices.
  • Experience performing control testing, evidence validation and compliance assessments.
  • Knowledge of third-party risk management and supplier security assurance.
  • Familiarity with cloud security governance and emerging technology risks, including AI, would be advantageous.
About Flo Energy

Hi, we are Flo! We are on a mission to switch as many people and businesses as possible to affordable, renewable solutions.

We began in a small shophouse in Singapore and have grown rapidly ever since, expanding into Australia with even bigger plans ahead.

Unlike other retailers, we have built our own best-in-class energy platform entirely in-house. Designed specifically for the sector, it automates complex processes and keeps costs down, letting us offer genuinely affordable products to our customers.

Behind Flo is a diverse team of passionate engineers, data scientists, operators, and energy experts. We come from different backgrounds, but we are united by the shared goal of creating a more sustainable future. If you want to make an impact and help accelerate the renewable energy transition, we would love to meet you.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Governance Lead: Risk, Compliance & Assurance
Security Governance Lead: Risk, Compliance & Assurance

Flo Energy • Singapore

On-site
SGD 180,000 - 260,000
Senior Software Engineer, Backend
Senior Software Engineer, Backend

Flo Energy • Singapore

On-site
SGD 150,000 - 190,000
Software Engineer - Infrastructure Platform
Software Engineer - Infrastructure Platform

Flo Energy • Singapore

On-site
SGD 70,000 - 110,000
Senior Software Engineer, Frontend (6-12 months contract)
Senior Software Engineer, Frontend (6-12 months contract)

Flo Energy • Singapore

On-site
SGD 70,000 - 100,000
Dynamic work environment
Impactful position
Involvement in product development
Senior Software Engineer, Frontend (6-12 months contract)
Senior Software Engineer, Frontend (6-12 months contract)

Flo Energy • Singapore

On-site
SGD 70,000 - 110,000
Senior Backend Engineer — Scalable Renewable Platform
Senior Backend Engineer — Scalable Renewable Platform

Flo Energy • Singapore

On-site
SGD 150,000 - 190,000
Senior Frontend Engineer - Build Scalable Customer Journeys
Senior Frontend Engineer - Build Scalable Customer Journeys

Flo Energy • Singapore

On-site
SGD 70,000 - 110,000
Cybersecurity Specialist
Cybersecurity Specialist

Meranti Power Pte. Ltd. • Singapore

On-site
SGD 90,000 - 130,000
Platform Engineer: SRE, Automation & Observability
Platform Engineer: SRE, Automation & Observability

Flo Energy • Singapore

On-site
SGD 70,000 - 110,000
Cybersecurity Manager
Cybersecurity Manager

The Hour Glass • Singapore

On-site
SGD 120,000 - 180,000