IT Security Governance and Assurance Lead

NETS

Singapore

On-site

SGD 180,000 - 300,000

Full time

25 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Performance bonus

Job summary

BCS, a wholly owned subsidiary of NETS, manages and operates Singapore's payment infrastructure, ensuring security, availability and resilience in line with regulatory requirements.

The Security Governance and Assurance (SGA) lead will head a team of GRC specialists, drive cybersecurity governance, risk assessments, audits, and policy enforcement, reporting to the CISO. The role demands extensive experience and strategic leadership across security disciplines.

Qualifications

  • Bachelor’s or Master’s in Computer Science, Computer Engineering, Information Security, or related fields.
  • Minimum of 10 years in IT governance, risk, or compliance management, preferably within financial services or payment systems.

Responsibilities

  • Design, implement, and continually update cybersecurity policies, standards, guidelines, and processes.
  • Recruit, train, and retain security governance, risk and compliance specialists.
  • Identify automation and process improvements to optimise security monitoring and risk management.
  • Assist the CISO with budgeting, procurement, and resource allocation.
  • Conduct risk assessments to monitor compliance with policies and controls.
  • Oversee audits and remediation efforts, supporting informed decision-making.
  • Develop and report IT Security metrics and KRIs for risk committees.

Skills

Cybersecurity frameworks
Security governance
Leadership
Stakeholder management
Regulatory compliance
Communication skills
DevSecOps

Education

Bachelor’s or Master’s in Computer Science/Engineering/Information Security

Tools

COBIT
ITIL
MAS Notices
PDPA / Personal Data Protection

Job description

BCS, a wholly owned subsidiary of NETS and part of the NETS Group, manages and operates the clearing and payment infrastructure for the Singapore Automated Clearing House. This includes services such as Fast and Secure Transfers (FAST), Inter-bank GIRO (IBG), and the Cheque Truncation System (CTS). BCS also supports PayNow and the SGQR Central Repository, among other services.

The IT Security Team at BCS ensures the security, availability and resilience of BCS systems, protecting data and mitigating emerging cyber threats in alignment with regulatory requirements.

Team and Position Summary

The Security Governance and Assurance (SGA) unit is a key function within IT Security, responsible to drive cybersecurity governance, oversee cybersecurity risk assessments, manage audits, and ensure robust security compliance monitoring across BCS.

The SGA lead reports directly to the BCS CISO and serves as a subject matter expert in cybersecurity technologies and governance. The role is responsible for managing a team of Security GRC specialists and carrying out proactive oversight and monitoring of BCS’ compliance with the cyber risk management policies and standards.

Key Responsibilities
Leadership and Strategy
  • Design, implement, and continually update BCS’ cybersecurity policies, standards, guidelines, and processes to meet evolving business and regulatory requirements.
  • Recruit, train, and retain security governance, risk and compliance specialists skilled in cybersecurity frameworks and IT standards.
  • Identify and implement automation and process improvements to optimise the efficiency in security monitoring and risk management by Security Governance and Assurance.
  • Assist the CISO with budgeting, procurement, and resource allocation as needed.
  • Conduct risk assessments to monitor BCS’ compliance with cybersecurity policies and security controls, including review of security deviations and risk acceptance submissions from business units to recommend appropriate remediations.
  • Leverage knowledge and assess emerging security technologies and risks to recommend effective solutions and controls to enhance overall operational efficiency and security enforcement across BCS.
  • Drive the assessment of BCS cybersecurity vulnerabilities, mitigation of findings and implementation of cybersecurity controls for BCS systems and the underlying IT infrastructure.
  • Review security breaches and vulnerabilities, ensuring that they are promptly and thoroughly investigated so potential cyber threats are addressed effectively and efficiently.
Compliance Monitoring
  • Stay current with emerging security regulations (e.g., Cyber Security Act, MAS Notices) assess its impact and ensure BCS’ compliance.
  • Monitor cybersecurity assurance activities, including Vulnerability Assessment and Penetration Testing (VAPT), red teaming, and table-top exercises, to ensure adherence to internal policies and proactively address any gaps in compliance or security posture.
  • Oversee and maintain BCS’ Risk Management framework, including the tracking of security gaps, audit findings, and other security risk-related initiatives. Ensure policies and processes are in place, monitor their effectiveness, and assess the impact on BCS.
Audit Management
  • Coordinate and manage IT-security related audits, including collecting and submitting required artifacts, facilitating audit reviews, and ensuring timely responses to audit inquiries.
  • Drive remediation efforts for identified gaps by advising on risk assessments, ensuring completeness of corrective actions, and providing IT security subject matter expertise to support informed decision-making.
Metrics and Reporting
  • Develop and report on IT Security metrics and KRIs to provide insights into security performance, risks, and vulnerabilities across the enterprise. Present findings in internal risk committee meetings and external forums in alignment with BCS’ risk posture.
Requirements
Education and Experience
  • Bachelor’s or Master’s in Computer Science, Computer Engineering, Information Security, or related fields.
  • Minimum of 10 years in IT governance, risk, or compliance management, preferably within the financial services or payment systems industry.
Skills and Knowledge
  • Strong knowledge of Cybersecurity frameworks (risk management methodologies, regulatory and legal requirements, and industry practices)
  • Ability to demonstrate deep technical expertise/knowledge in in cyber and IT standards and policy review, oversight and governance, risk management and audit execution.
  • Familiarity with MAS & CCOP regulations, COBIT, ITIL, Personal Data Protection and Payment Services Acts, and emerging security standards and solutions.
  • Proficiency in architecture of secure, scalable, and resilient solutions within hybrid cloud environments, along with a strong grasp of CI/CD and DevSecOps methodologies.
  • Strong understanding of various audit standards, with the ability to interpret contracts and technical documents, ensuring alignment with process controls and requirements.
  • Excellent written and oral communication skills, with strong interpersonal abilities to collaborate and foster constructive relationships across all organisational levels.
  • Skilled at managing stakeholder groups, influencing decision-making in IT risk management, balancing diplomacy and assertiveness, and adapting to a rapidly changing environment.
  • Demonstrated leadership skills, with proven ability to foster a collaborative, high-performance team culture.
  • Ability to make informed decisions under pressure and effectively manage crisis situations.
  • Excellent communication, analytical, and problem-solving skills, with the ability to engage effectively with stakeholders at all levels.
Professional Certifications
  • Preferred certifications include Certified Information Security Manager (CISM), Certified Secure Software Practitioner (CSSP), Certified in the Governance of Enterprise IT (CGEIT), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), or any relevant certification in governance, risk, and compliance.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Governance & Assurance Analyst
IT Security Governance & Assurance Analyst

NETS • Singapore

On-site
SGD 60,000 - 100,000
Cyber Security Engineer
Cyber Security Engineer

NETS • Singapore

On-site
SGD 110,000 - 150,000
Security Governance and Assurance Engineer
Security Governance and Assurance Engineer

NETS • Singapore

On-site
SGD 120,000 - 180,000
Director, Security Governance & Assurance
Director, Security Governance & Assurance

NETS • Singapore

On-site
SGD 180,000 - 300,000
Performance bonus
VP, Security Governance & Assurance
VP, Security Governance & Assurance

NETS • Singapore

On-site
SGD 180,000 - 240,000
GENERAL MANAGER, CYBERSECURITY
GENERAL MANAGER, CYBERSECURITY

Rikvin Capital Pte. Ltd. • Singapore

On-site
SGD 260,000 - 380,000
Cybersecurity Specialist (Audit Readiness)
Cybersecurity Specialist (Audit Readiness)

NETS • Singapore

On-site
SGD 70,000 - 110,000
IT Security Manager (Public Sector)
IT Security Manager (Public Sector)

NEWTONE CONSULTING PTE. LTD. • Singapore

On-site
SGD 90,000 - 130,000
Cybersecurity Governance and Assurance Specialist
Cybersecurity Governance and Assurance Specialist

NETS • Singapore

On-site
SGD 120,000 - 180,000
Deputy Cyber Security Manager
Deputy Cyber Security Manager

woh hup group • Singapore

Hybrid
SGD 90,000 - 150,000