Manager, Cybersecurity Assurance & Resilience

SMRT Trains Ltd

Singapore

On-site

SGD 120,000 - 180,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

SMRT Trains Ltd seeks a proactive Manager, Cybersecurity Assurance & Resilience to join the GRC team. You will oversee assurance, compliance, and third-party risk programmes, ensuring effective cybersecurity controls across systems and processes.

You will coordinate audits, validate evidence, and lead table-top exercises, reporting findings and driving improvements while collaborating with stakeholders across technical and non-technical domains.

Qualifications

  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or related discipline.
  • 5-10 years of experience in cybersecurity governance, audit, assurance, compliance, resilience or third-party risk management.
  • Familiarity with NIST CSF, ISO/IEC 27001, CIS Controls advantageous.
  • Experience managing vendor cybersecurity assessments and third-party risk management programmes advantageous.
  • Experience designing or facilitating cyber incident response exercises and tabletop exercises advantageous.

Responsibilities

  • Plan, manage and execute cybersecurity assurance activities to assess control effectiveness.
  • Review policies, standards and regulatory requirements to identify gaps and improvements.
  • Assess control implementation and remediation actions; track findings.
  • Coordinate evidence collection, validation and reporting for assurance reviews and audits.
  • Support cybersecurity compliance activities and regulatory inspections.
  • Manage third-party risk management and vendor cybersecurity assessments.
  • Develop and facilitate cyber crisis simulations and incident response exercises.

Skills

Cybersecurity governance
Evidence gathering
Report writing
Stakeholder engagement
Analytical skills

Education

Bachelor's degree in Cybersecurity/IS/CS

Job description

Company description

SMRT Trains Ltd was incorporated in 1987 and operates Singapore's first mass rapid transit system. Today, we manage and operate train services on the North-South Line, East-West Line, the Circle Line, the Thomson-East Coast Line, and the Bukit Panjang Light Rail Transit. With over 5,000 employees, more than 250 trains, and 141 km of rail tracks across 108 stations, we serve millions of commuters daily.


We have set our core values to be Integrity, Service & Safety and Excellence. SMRT is committed to provide safe, reliable and comfortable service for our commuters.


Job description

Job Purpose

In today's rapidly evolving threat landscape, cybersecurity governance is essential to maintaining operational integrity and regulatory compliance. SMRT is seeking a detail-oriented and proactive Manager, Cybersecurity Assurance & Resilience to join our Governance, Risk and Compliance (GRC) team. This role is responsible for ensuring the effectiveness of SMRT's cybersecurity assurance, resilience and third-party risk management programmes through the assessment of cybersecurity controls, oversight of compliance requirements, management of third-party cyber risks, and validation of organisational readiness to respond to and recover from cybersecurity incidents.


Responsibilities

Cybersecurity Assurance


  • o Plan, manage and execute cybersecurity assurance activities to assess the effectiveness of cybersecurity controls across systems, processes and business functions.

  • o Conduct reviews against cybersecurity policies, standards, regulatory requirements and industry frameworks to identify control gaps and improvement opportunities.

  • o Assess the implementation and operating effectiveness of cybersecurity controls and recommend corrective actions where necessary.

  • o Track remediation efforts and monitor the closure of identified findings and weaknesses.

  • o Support cybersecurity maturity assessments and benchmarking exercises to evaluate organisational cybersecurity capabilities.

  • o Coordinate evidence collection, validation and reporting for cybersecurity assurance reviews and audits.


Cybersecurity Compliance Support


  • o Support cybersecurity compliance activities to ensure adherence to internal policies, standards, regulatory requirements and organisational obligations.

  • o Assist in monitoring and reporting cybersecurity compliance posture across business units and systems.

  • o Conduct compliance gap assessments and support remediation planning activities.

  • o Support internal and external audit engagements, regulatory inspections and compliance assessments.


Third-Party Cyber Risk Management & Security Rating Monitoring


  • o Manage and continuously enhance the Cybersecurity Third-Party Risk Management (TPRM) programme and associated assessment processes.

  • o Perform cybersecurity due diligence assessments for vendors, suppliers and service providers.

  • o Monitor vendor's cybersecurity posture and security ratings to identify emerging risks and ensure timely remediation of identified issues.

  • o Prepare assessment repots, risk findings and recommendations to support management decision-making, procurement evaluation and governance reviews.


Cybersecurity Resilience & Table-Top Exercises


  • o Develop, coordinate and facilitate cybersecurity table-top exercises, cyber crisis simulations and incident response exercises.

  • o Design realistic cyberattack scenarios to validate incident response, crisis management and decision-making processes.

  • o Document exercise outcomes, lessons learnt and recommendations for improvement.

  • o Support initiatives to strengthen organisational cyber resilience, operational readiness recovery capabilities.


Qualifications & Work Experience


  • A bachelor's degree in Cybersecurity, Information Systems, Computer Science, or a related discipline.

  • 5-10 years of experience in cybersecurity governance, audit, assurance, compliance, resilience or third-party risk management.

  • Familiarity with cybersecurity frameworks such as NIST CSF, ISO/IEC 27001, and CIS Controls will be advantageous.

  • Experience managing vendor cybersecurity assessments and third-party risk management programmes will be advantageous.

  • Experience designing or facilitating cyber incident response exercises and table-top exercises will be advantageous.

  • Knowledge of regulatory requirements including the Cybersecurity Code of Practice (CCoP), Personal Data Protection Act (PDPA), and sector-specific standards will be advantageous.


Skills

Technical Skills


  • Understanding of cybersecurity governance, assurance and compliance principles.

  • Ability to assess control effectiveness and identify gaps in policy implementation.

  • Skilled in evidence gathering and report writing.

  • Familiarity with third-party risk management methodologies and vendor security assessment practices.

  • Ability to develop meaningful cybersecurity metrics, reports and dashboards.


Core Competencies


  • Excellent analytical and documentation skills, with strong attention to detail.

  • Effective communicator with the ability to engage stakeholders across technical and non-technical domains.

  • High integrity and discretion in handling sensitive information.

  • Proactive and collaborative mindset, with a commitment to continuous improvement

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Manager, Compliance
Manager, Compliance

SMRT Trains Ltd • Singapore

On-site
SGD 120,000 - 180,000
Manager, Cyber Security (Operations)
Manager, Cyber Security (Operations)

SMRT Trains Ltd • Singapore

On-site
SGD 120,000 - 180,000
Manager, Risk Management
Manager, Risk Management

SMRT Trains Ltd • Singapore

On-site
SGD 140,000 - 200,000
Manager, Cybersecurity Assurance & Resilience
Manager, Cybersecurity Assurance & Resilience

SMRT Corporation Ltd • Singapore

On-site
SGD 120,000 - 180,000
Manager, IT Cybersecurity Architect
Manager, IT Cybersecurity Architect

SMRT Trains Ltd • Singapore

On-site
SGD 180,000 - 260,000
Manager, Risk Management
Manager, Risk Management

SMRT Corporation, Ltd. • Singapore

On-site
SGD 90,000 - 120,000
Manager, Compliance
Manager, Compliance

SMRT Corporation, Ltd. • Singapore

On-site
SGD 120,000 - 180,000
Cybersecurity Assurance & Resilience Manager
Cybersecurity Assurance & Resilience Manager

SMRT Trains Ltd • Singapore

On-site
SGD 120,000 - 180,000
Manager, Cyber Security (Operations)
Manager, Cyber Security (Operations)

SMRT Corporation, Ltd. • Singapore

On-site
SGD 120,000 - 190,000
Cybersecurity Governance & Compliance Manager
Cybersecurity Governance & Compliance Manager

SMRT Trains Ltd • Singapore

On-site
SGD 120,000 - 180,000