Enable job alerts via email!

Senior Manager, Client Information Security Officer (Apps Gov)

NCS Hong Kong and Singapore

Singapore

On-site

SGD 80,000 - 100,000

Full time

3 days ago
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Start fresh or import an existing resume

Job summary

A leading company is seeking an Information Security Manager to enhance cybersecurity practices. The role involves implementing policies, managing security incidents, and advising on application security, requiring strong knowledge in compliance and risk management. Candidates should have significant experience and certifications in information security management.

Qualifications

  • 5+ years of experience in information security management.
  • At least one recognized security certification (e.g., CISSP, CISM).
  • Good knowledge of security governance frameworks.

Responsibilities

  • Drive implementation of cybersecurity and data protection policies.
  • Support cybersecurity through the project delivery lifecycle.
  • Manage security SLA governance and reporting.

Skills

Cybersecurity Management
Application Security Testing
Security Risk Management
Compliance
Incident Management
Stakeholder Management

Education

Degree/Diploma in Computer Science or Information Systems

Tools

VAPT
IAM
DevSecOps
API Security
Vulnerability Scanners

Job description

What we seek to accomplish together:

  • Drive the implementation of NCS cybersecurity, data protection, and privacy policies, standards, and processes within the practice. You will work to continually improve the security posture of projects through proactive risk management and the establishment of a broad range of cybersecurity controls.
  • Provide direct support to colleagues to ensure cybersecurity is addressed throughout the project delivery lifecycle, from application design, application architecture patterns, testing, vulnerability, and security review.
  • Act as a single point of contact and escalation for LOB application cybersecurity incidents, ensuring timely identification, remediation and lessons learned.
  • Manage the security SLA governance and provide practice-level cybersecurity reporting, metrics and forecasting to leadership.
  • Responsible for information security, data protection, privacy, GRC, and audit requests for the practice, acting as single point of contact on relevant client security assessment and audits execution. For example, independent third-party attestations of industry cybersecurity standards and certifications, such as ISO 27001, CIS Controls, NIST for practice-specific solutions and products
  • Contribute to the definition of the client specific security baseline. Consult and advise internal and external clients about security topics and support the opportunity management process by providing subject matter expertise and support
  • Help win client business by providing cybersecurity assurance to RFIs, RFPs, proposals, contract drafting, security questionnaires, workshops, and other client due diligence processes.

A little bit about you:

  • Degree/Diploma or higher in Computer Science, Information Systems or equivalent
  • At least one industry recognized security certification is, such as Certified Information Security Management (CISM), Certified Information Systems Security Professional (CISSP), CEH, or CASP.
  • 5+ years of experience in information security management specifically in application secured design and patterns (Cloud, Serverless, Containers), application and API security testing methodologies e.g. analysis and recommendation of rectifications using VAPT/WAPT/SAST/DAST/SCA, security architecture, infosec risk management, compliance and audits for Web, Mobile, API, and Cloud Native applications.
  • Good working knowledge of security risk management, security governance framework and compliance (IT Security Audit / log review)
  • Understanding of information security principles, IM8, PDPA, ISO 27001 controls, Center for Internet Security (CIS) controls, Cloud Controls Matrix (CCM) controls.
  • Experience with application security, security technologies and automation tools, e.g., IAM, DevSecOps, CI/CD, IAC, application security, API Security, vulnerability scanners, security technologies (data/application protection & hardening, encryptions).
  • Experience carrying out application penetration testing, vulnerabilities scanning, and security assessment, and security incident management with stakeholders.
  • Senior stakeholder management and working across various parts of the organization
  • Team player with good interpersonal, influencing skills
  • Strong communication skills, both written and verbal
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.