GRC, Senior Security Consultant

GTS Consulting

Singapore

On-site

SGD 90,000 - 150,000

Full time

37 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

GTS Consulting seeks an experienced Cybersecurity Consultant specializing in Governance, Risk and Compliance (GRC) to support ISO/IEC 27001, CSA marks, DPTM/SS 714, TRA, and regulatory engagements. You will collaborate closely with client management and IT teams to strengthen governance, prepare for audits, and meet regulatory requirements.

You will work with Stone Cybersecurity’s testing and SOC teams to translate findings into governance actions and risk treatment plans, delivering practical,

Qualifications

  • GRC and regulatory compliance experience with cybersecurity programs.
  • Experience delivering readiness, implementation, and certification engagements for ISO/IEC 27001 and CSA marks.
  • Strong ability to conduct regulatory gap assessments against MAS TRM, PDPA, NIST CSF, GDPR.

Responsibilities

  • Support and deliver readiness, implementation, and certification engagements for ISO/IEC 27001 and CSA marks.
  • Conduct compliance gap assessments and cybersecurity maturity evaluations against applicable standards and regulations.
  • Develop audit‑ready ISMS documentation, including policies, risk registers, and control mappings.
  • Assist clients during internal and external audits and regulatory assessments.
  • Prepare and present assessment findings and remediation plans to client stakeholders.

Skills

GRC
Regulatory Compliance
Audit Readiness
Stakeholder Engagement
Risk Management
ISO 27001

Education

CISSP/CISA/CISM/CRISC/CCSP or ISO 27001/27701 LA/LI

Job description

We are seeking an experienced Cybersecurity Consultant specialising in Governance, Risk and Compliance (GRC) to support the delivery of ISO/IEC 27001, CSA Cyber Essentials Mark (CEM), CSA Cyber Trust Mark (CTM), Data Protection Trustmark (DPTM)/ SS 714, Threat and Risk Assessment (TRA), and regulatory compliance engagements.


Reporting to the GRC Lead, you will work with clients to strengthen their cybersecurity governance, prepare for audits and certifications, meet regulatory requirements, and develop sustainable security capabilities.


You will collaborate closely with clients’ management and IT teams, as well as Stone Cybersecurity’s penetration testing, Security Operations Centre (SOC), cloud security, and security architecture teams.


Key Responsibilities


  • GRC and Regulatory Compliance

  • Support and deliver readiness, implementation, and certification engagements for

  • ISO/IEC 27001, the CSA Cyber Essentials Mark, and the CSA Cyber Trust Mark.

  • Conduct compliance gap assessments and cybersecurity maturity evaluations against

  • applicable standards, frameworks, and regulations, including MAS Technology Risk Management (TRM) Guidelines, Singapore’s Personal Data Protection Act (PDPA), the NIST Cybersecurity Framework, and the General Data Protection Regulation (GDPR).

  • Develop audit-ready Information Security Management System (ISMS) documentation, including policies, procedures, Statements of Applicability, risk registers, control mappings, and risk treatment plans.

  • Support clients during internal audits, external certification audits, and regulatory assessments.

  • Track audit and assessment findings and work with client stakeholders to support the timely completion of remediation activities.

  • Threat and Risk Assessments and Cyber Exercises

  • Conduct cybersecurity Threat and Risk Assessments for cloud, enterprise, and regulated environments.

  • Identify critical assets, threats, vulnerabilities, business impacts, and cybersecurity risks, and recommend appropriate risk treatment and mitigation measures.

  • Produce clear and comprehensive assessment reports aligned with applicable CSA, NIST, and ISO methodologies.

  • Design, facilitate, and document tabletop exercises, incident response simulations, and cyber crisis exercises under the guidance of the GRC Lead.

  • Assess clients’ incident response preparedness and recommend improvements to their response plans, procedures, and capabilities.

  • Security Governance and Advisory

  • Develop and enhance cybersecurity policies, incident response plans, governance frameworks, and risk management processes.

  • Review enterprise systems, cloud environments, and business processes from a governance, risk, and compliance perspective.

  • Assess security areas such as identity and access management, logging and monitoring, encryption, network security, data protection, and data flows.

  • Provide practical, risk-based recommendations that balance cybersecurity, regulatory compliance, operational requirements, and business objectives.

  • Deliver cybersecurity awareness briefings and support clients’ wider security governance initiatives.

  • Project Delivery and Stakeholder Engagement

  • Manage assigned project activities and workstreams under the direction of the GRC Lead.

  • Support the management of project timelines, deliverables, risks, dependencies, and stakeholder expectations.

  • Collaborate with penetration testing, SOC, cloud security, and security architecture teams to translate technical findings into business and compliance risks.

  • Prepare and present assessment findings, risk positions, and recommendations to client stakeholders, including management and technical teams.

  • Escalate material risks, project issues, delays, and compliance concerns to the GRC Lead in a timely manner.

  • Provide regular progress updates and contribute to the successful delivery and closure of client engagements.


Prerequisie Requirements


  • Technical Skillset and Competency

  • Relevant certifications such as ISO 27001/27701 LA/LI, CISSP, CISA, CISM, CRISC, CCSP, Practitioner Certificate in Personal Data Protection, or equivalent.

  • Proven experience in GRC, cybersecurity consulting, or risk management.

  • Hands‑on experience implementing ISO/IEC 27001 and/ or 27701.

  • Strong understanding of Risk Management framework and Methodology

  • Excellent stakeholder engagement, communication, and presentation skills

  • Outspoken personality and advanced interpersonal skills


REPORTING LINE

This position reports directly to the GRC Lead.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Consultant - Cybersecurity (GRC) at ACCESS PEOPLE (SINGAPORE) PTE. LTD.
Lead Consultant - Cybersecurity (GRC) at ACCESS PEOPLE (SINGAPORE) PTE. LTD.

ACCESS PEOPLE (SINGAPORE) PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
Lead Consultant - Cybersecurity (GRC)
Lead Consultant - Cybersecurity (GRC)

ACCESS PEOPLE (SINGAPORE) PTE. LTD. • Singapore

On-site
SGD 150,000 - 210,000
Cyber Risk / GRC Consultant
Cyber Risk / GRC Consultant

RECRUIT123 PTE. LTD. • Singapore

On-site
SGD 61,000 - 100,000
Sponsorship for security certs
Career development toward Senior GRC /
CISO-track opportunities
Senior GRC & Cybersecurity Consultant
Senior GRC & Cybersecurity Consultant

GTS Consulting • Singapore

On-site
SGD 90,000 - 150,000
Cybersecurity GRC Consultant (Full-Time) #IAC
Cybersecurity GRC Consultant (Full-Time) #IAC

RECRUIT EXPRESS PTE LTD • Singapore

On-site
SGD 120,000 - 180,000
GRC Analyst
GRC Analyst

MA COMPLIANCE PTE. LTD. • Singapore

On-site
SGD 60,000 - 90,000
GRC Application Security Specialist (Contract)
GRC Application Security Specialist (Contract)

Public Service Division • Singapore

On-site
SGD 90,000 - 130,000
Cyber Security GRC Lead — Governance, Risk & Compliance
Cyber Security GRC Lead — Governance, Risk & Compliance

Eames Consulting • Singapore

On-site
SGD 120,000 - 180,000
Cybersecurity Risk & Assurance Specialist
Cybersecurity Risk & Assurance Specialist

1-FINITY CONSULTING PTE. LTD. • Singapore

On-site
SGD 90,000 - 130,000
Senior Cybersecurity GRC Leader: Zero Trust Risk Strategy
Senior Cybersecurity GRC Leader: Zero Trust Risk Strategy

GovTech Singapore • Singapore

On-site