Job Search and Career Advice Platform

Enable job alerts via email!

Cybersecurity Manager, GRC

SBS Transit Limited

Singapore

On-site

SGD 80,000 - 100,000

Full time

Today
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading public transport company in Singapore is seeking a GRC Cybersecurity professional to oversee the development and maintenance of security measures for IT and OT. The role involves formulating cybersecurity policies, conducting security audits, and ensuring compliance with regulatory requirements. Candidates should have a degree in Computer Engineering or related field, 3-5 years of relevant experience, and strong communication skills. Certifications such as CISSP or CISA are preferred.

Qualifications

  • Must have 3-5 years of relevant cybersecurity work experience.
  • Certification such as CISSP/CISM/CISA/CEH/CRISC is required.
  • Strong leadership and ability to work under pressure are essential.

Responsibilities

  • Oversee cybersecurity measures for IT and OT systems.
  • Conduct security audits and assessments.
  • Educate users on cybersecurity policies and procedures.
  • Develop and implement compliance oversight programs.

Skills

Cybersecurity governance
Incident response
Risk management
Vulnerability assessment
Penetration testing
Security audits
Budget planning
Compliance
Communication skills
Teamwork

Education

Degree in Computer Engineering or equivalent

Tools

SIEM
Anti-virus tools
Job description

This GRC role in fulfillment of internal and regulatory requirement to ensure compliance with sector-wide and enterprise-wide cybersecurity policies, standards and procedures.

Main Responsibilities
  • Oversee the development, testing, and maintenance of cybersecurity measures to safeguard both IT and OT Critical Information Infrastructure (CII) and Non CII assets
  • Formulate cybersecurity policies and procedures for IT and OT systems, ensuring compliance with regulatory requirements, including the Cybersecurity Code of Practice (CCoP 2.0)
  • Conduct security audits, vulnerability assessments and risk assessment and checks to ensure security controls are in place and are functioning properly and working with regulatory bodies to ensure organisation meets cybersecurity standards
  • Conduct CII penetration test, red/ purple teaming exercise on a regular basis ensuring organisation Business Continuity Plan (BCP) and Disaster Restoration Plan (DRP) are well documented and communicated
  • Identify emerging threats and vulnerabilities, and recommend appropriate controls and solutions for implementation to enhance cybersecurity posture
  • Liaising with cybersecurity vendors in conducting relevant assessments to fulfil regulatory requirements
  • Plan and implement budgeted cybersecurity projects based on business requirements
  • Develop and implement sector-wide cybersecurity oversight programme to ensure compliance with cybersecurity policies
  • Review waiver and non-compliance of cybersecurity policy and procedures and carry out users engagements to ensure compliance
  • Work closely with internal and external stakeholders on regularly review and enhance cybersecurity incident response plans and playbooks to achieve cybersecurity readiness
  • Conduct cybersecurity exercises
  • Educate users on cybersecurity security, providing training to employees and contractors on cybersecurity policy, standards and procedures
Requirements
  • Degree in Computer Engineering or equivalent. Trained in Cybersecurity, Information Security, Forensics or equivalent
  • 3-5 years of direct and relevant full-time cybersecurity work experience in policy formulation, incident response, and management, regulatory oversight and compliance
  • CISSP/CISM/CISA/CEH/ CRISC or equivalent certification
  • Strong domain knowledge of information security governance and risk management, controls, vulnerability assessment/penetration testing, compliance, business continuity, investigations, system architecture and design, legal, and industry IT/OT and cyber security bestpractices
  • Knowledge on CSA Code of Practice (CCoP), ISO27001 and IEC62443, NIST Cybersecurity Framework.
  • Experience in Threat detection, Penetration testing and red/purple teaming
  • Knowledge in Network, Web Security and Application Security would be highly valued
  • Experience with information security tools (SIEM, anti-virus tools etc.)
  • Experience in forensics and incident management
  • Strong leadership qualities & ability to work under pressure
  • Self-motivated, a good team player and strong ability to multi-task
  • Excellent verbal, written communication, presentation and analytical skills
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.