[What the role is]This role is with the InfoTech & Digital Transformation Department at PUB[What you will be working on]Governance and PolicyEnsure and continuously enhance the governance, resilience, and integrity of PUB's IT and OT systems against evolving cyber threatsCommunicate, implement, and enforce information security policies, standards, and procedures in accordance with best practices and regulatory requirements from CSA and GovTechPromote a cyber-vigilant culture across PUB through awareness campaignsLeverage automation tools and streamlined processes to facilitate consistent compliance with cybersecurity policiesRisk ManagementAdvise senior management on risk prioritisation, the consequences of various risk management strategies, and the effectiveness of specific security measuresTranslate technical security deficiencies into business risks that are clearly understood by non-technical stakeholders, in order to secure buy-in for security investmentsDevelop and maintain risk management and mitigation plans for both IT and OT environmentsCompliance and DocumentationMonitor the effectiveness of security controls, and ensure compliance with documented standards, policies, and proceduresMonitor and track risk mitigation measures and enforce compliance with cybersecurity policiesEnsure PUB has developed, documented, and kept current its Business Impact Analysis, System Security Plans, Risk Assessments, Risk Treatment Plans, and other information security documentationAudit and ReportingGenerate cybersecurity hygiene and audit reports for PUB Senior Management and relevant stakeholdersSupport and manage various internal and external audit activities from planning through to remediationIdentify systemic weaknesses surfaced through audit findings and propose feasible solutions to address them, ensuring root causes are addressed with substantive fixes[What we are looking for]RequirementsBachelor's Degree in Electrical/Electronic or Computer Engineering, Information Systems, Computer Science, or an equivalent disciplineStrong understanding of cybersecurity controls, best practices, technology processes, risk assessments, and cybersecurity policies (e.g. Cybersecurity Code of Practice for CII, Instruction Manual on IT Management)Ability to work effectively across both technical teams and business stakeholdersPrior relevant experience related to IT or OT cybersecurity is advantageousProfessional certifications such as GIAC, CISSP, CISA, or CISM are advantageous