IT Compliance Manager

Bank Of China Limited

Singapore

On-site

SGD 120,000 - 180,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Bank Of China Limited in Singapore is seeking a cybersecurity and IT risk professional to oversee security operations, threat intelligence, vulnerability management, and regulatory compliance across the branch's IT landscape.

The role focuses on IT outsourcing risk assessments, internal control strengthening, risk quantification, and collaboration with risk management and internal audit to support management decision-making. English and Mandarin communication is required.

Qualifications

  • Bachelor’s degree or above in Computer Science, Information Security, Software Engineering, or related majors.
  • Candidates holding relevant professional certifications are preferred, such as CISSP, CISM, CISA, ISO27001 Lead Auditor, OSCP, etc.
  • Possess excellent written and verbal communication skills in English
  • Proficiency in written and spoken Mandarin is required, as the role involves viewing Head Office policies and documents prepared in Chinese, drafting bilingual correspondence where required, and liaising regularly with Head Office.
  • Have a strong interest in cybersecurity operations, IT risk governance, IT audit, and regulatory compliance, with a desire for long-term development in the field of IT risk management.
  • Preference will be given to candidates with practical experience in cybersecurity (such as SOC operations, penetration testing, incident response) or IT audit backgrounds.
  • Familiar with local regulatory requirements and industry best practices
  • Familiar with common types of cybersecurity threats and defense technologies, and understand the working principles and configuration logic of mainstream security tools.
  • Possess meticulous review capabilities to accurately assess the quality and compliance of IT policies, processes, reports, and audit responses.
  • Possess outstanding time management skills and a results-oriented mindset, maintaining high efficiency and ensuring delivery quality in a fast-paced, high-demand environment.
  • Demonstrate strong stress resistance and maintain stable performance during emergency security incidents or regulatory inspections.

Responsibilities

  • Cybersecurity Operations and Defense: Oversee daily network security operations and lead threat intelligence collection and analysis.
  • Oversee daily network security operations for the branch, lead the collection and analysis of cyber threat intelligence, coordinate regular vulnerability scanning, penetration testing, and patch management to ensure the security hardening of infrastructure and application systems.

Skills

Cybersecurity operations
IT risk governance
IT audit
Regulatory compliance
SOC operations
Penetration testing
Incident response
CISSP
CISM
CISA
ISO27001 Lead Auditor
OSCP
Bilingual English-Mandarin

Education

Bachelor’s degree in Computer Science or related

Job description

Job Responsibilities


  • Cybersecurity Operations and Defense

  • Oversee daily network security operations for the branch, lead the collection and analysis of cyber threat intelligence, coordinate regular vulnerability scanning, penetration testing, and patch management to ensure the security hardening of infrastructure and application systems.

  • IT Outsourcing Risk Management

  • Participate in IT outsourcing risk assessments, conducting due diligence, access reviews, and regular on-site inspections for key IT outsourcing vendors.

  • First Line of Defense Self-Assessment and Remediation

  • Participating in self-assessments, collaborate with the Second Line (Risk Management) and Third Line (Internal Audit) departments, and jointly strengthen the internal control system.

  • Regulatory Compliance and Gap Analysis

  • Participate incompliance assessments for the Technology Risk Management Framework (TRMG) and local regulatory requirements

  • IT Risk Identification, Assessment, and Quantification

  • Participate in collect, review, and report IT risk quantification data required to support management decision-making.


Job Requirements


  • Bachelor’s degree or above in Computer Science, Information Security, Software Engineering, or related majors.

  • Candidates holding relevant professional certifications are preferred, such as CISSP,CISM, CISA, ISO27001 Lead Auditor, OSCP, etc.

  • Possess excellent written and verbal communication skills in English

  • Proficiency inwritten and spoken Mandarin is required, as the role involves viewing Head Office policies and documents prepared in Chinese, drafting bilingual correspondence where required, and liaising regularly with Head Office.

  • Have a strong interest in cybersecurity operations, IT risk governance, IT audit, and regulatory compliance, with a desire for long-term development in the field of IT risk management.

  • Preference will be given to candidates with practical experience in cybersecurity (such as SOC operations, penetration testing, incident response) or IT audit backgrounds.

  • Familiar with local regulatory requirements and industry best practices

  • Familiar with common types of cybersecurity threats and defense technologies, and understand the working principles and configuration logic of mainstream security tools.

  • Possess meticulous review capabilities to accurately assess the quality and compliance of IT policies, processes, reports, and audit responses.

  • Possess outstanding time management skills and a results-oriented mindset, maintaining high efficiency and ensuring delivery quality in a fast-paced, high-demand environment.

  • Demonstrate strong stress resistance and maintain stable performance during emergency security incidents or regulatory inspections.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Specialist
Cyber Security Specialist

LANDI Global • Singapore

On-site
SGD 90,000 - 130,000
Information Technology Director
Information Technology Director

AMBER TECHNOLOGIES SERVICE PTE. LTD. • Singapore

On-site
SGD 180,000 - 260,000
Information Security Engineer
Information Security Engineer

HAIER SINGAPORE INVESTMENT HOLDING PTE. LTD. • Singapore

On-site
SGD 60,000 - 80,000
Deputy Cyber Security Manager
Deputy Cyber Security Manager

woh hup group • Singapore

Hybrid
SGD 90,000 - 150,000
Security Consultant
Security Consultant

CITIC Telecom International CPC Limited • Singapore

On-site
SGD 120,000 - 180,000
Cybersecurity Engineer (Governance, Risk & Compliance) (A233302)
Cybersecurity Engineer (Governance, Risk & Compliance) (A233302)

Xiaomi Technology • Singapore

On-site
SGD 150,000 - 190,000
Cybersecurity Specialist
Cybersecurity Specialist

LANDI INTERNATIONAL (SINGAPORE) PTE. LTD. • Singapore

On-site
SGD 80,000 - 120,000
Senior Manager, Cybersecurity Operations
Senior Manager, Cybersecurity Operations

GOLDTECH RESOURCES PTE LTD • Singapore

On-site
SGD 80,000 - 130,000
GENERAL MANAGER, CYBERSECURITY
GENERAL MANAGER, CYBERSECURITY

Rikvin Capital Pte. Ltd. • Singapore

On-site
SGD 260,000 - 380,000
Senior Associate, Cyber Risk Assurance
Senior Associate, Cyber Risk Assurance

Ensign InfoSecurity • Singapore

On-site
SGD 60,000 - 80,000