VP, Security Governance Lead

Kerry Consulting

Singapore

On-site

SGD 180,000 - 240,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Kerry Consulting is seeking an experienced cybersecurity leader to oversee governance, risk and assurance capabilities. Reporting to the CISO, you will drive the GRC function, align policies with regulatory obligations, and guide senior stakeholders on cyber risk across the enterprise.

This role combines strategic leadership with operational oversight in a highly regulated environment, requiring a proven track record of strengthening cyber resilience and governance maturity across large

Qualifications

  • Degree in Information Security, Computer Science, Computer Engineering, or related discipline.
  • At least 10 years of cybersecurity governance, enterprise risk management, information security, or IT assurance experience.
  • Experience leading Governance, Risk & Compliance (GRC) functions or enterprise security governance teams.

Responsibilities

  • Develop and maintain enterprise cybersecurity governance, policies, standards, and control frameworks.
  • Align governance with regulatory obligations, business priorities, and industry best practices.
  • Review policy exceptions and risk acceptance requests with recommendations.
  • Lead risk assessments and oversee security assurance activities (vulnerability assessments, penetration testing, control reviews).
  • Track remediation efforts to close gaps and strengthen controls.
  • Engage with internal/external audit and regulatory bodies to demonstrate compliance.
  • Provide strategic guidance to technology and business stakeholders on cyber risk and governance matters.

Skills

GRC leadership
stakeholder management
risk assessment
regulatory compliance

Education

Bachelor’s in Information Security/CS/CE

Tools

ISO 27001

Job description

We are seeking an experienced cybersecurity leader to oversee the organisation's governance, risk, and assurance capabilities. This role is responsible for establishing and maintaining an effective cyber governance framework, ensuring security risks are appropriately managed, and driving continuous improvements across the enterprise security programme.

Reporting to the Chief Information Security Officer (CISO), you will lead the Governance, Risk & Compliance (GRC) function while partnering closely with technology, risk, audit, and business leaders to strengthen the organisation's overall cyber resilience.

This position combines strategic leadership with operational oversight and is well suited for someone who enjoys influencing enterprise-wide security initiatives in a highly regulated environment.

Key Responsibilities:
Governance & Security Frameworks
  • Develop and maintain enterprise cybersecurity governance, policies, standards, and control frameworks.
  • Ensure governance processes remain aligned with evolving regulatory obligations, business priorities, and industry best practices.
  • Review security policy exceptions and risk acceptance requests, providing appropriate recommendations and oversight.
  • Champion continuous improvement initiatives to enhance governance maturity across the organisation.
  • Lead enterprise cybersecurity risk assessments to identify and evaluate technology and cyber risks.
  • Oversee security assurance activities, including vulnerability assessments, penetration testing, control reviews, and cyber resilience exercises.
  • Track remediation activities to ensure identified risks and control gaps are addressed in a timely manner.
  • Evaluate emerging cyber threats and technologies, recommending appropriate safeguards where necessary.
Audit & Regulatory Engagement
  • Act as the primary cybersecurity representative for internal and external audit engagements.
  • Coordinate responses to audit requests and oversee remediation programmes arising from audit findings.
  • Ensure appropriate governance processes exist to demonstrate compliance with applicable security and regulatory requirements.
  • Partner with internal stakeholders to improve the effectiveness of security controls and governance practices.
Leadership & Stakeholder Management
  • Lead and develop a high-performing Governance, Risk & Compliance team.
  • Foster a collaborative culture focused on accountability, continuous learning, and operational excellence.
  • Provide strategic guidance to technology and business stakeholders on cyber risk and governance matters.
  • Support executive leadership through regular reporting on cyber risks, control effectiveness, and programme maturity.
Performance & Reporting
  • Develop meaningful security metrics and key risk indicators to measure programme effectiveness.
  • Prepare reports and presentations for executive management, governance committees, and senior stakeholders.
  • Drive data-driven decision making through insightful analysis of cyber risks and control performance.
Requirements:
  • Degree in Information Security, Computer Science, Computer Engineering, or a related discipline.
  • At least 10 years of experience within cybersecurity governance, enterprise risk management, information security, or IT assurance.
  • Previous experience leading Governance, Risk & Compliance (GRC) functions or enterprise security governance teams.
  • Experience working within regulated industries or large, complex organisations is highly desirable.
  • Recent years of experience in leading a team.
Technical Expertise
  • Strong understanding of cybersecurity governance, enterprise risk management, and control frameworks.
  • Experience implementing or managing recognised standards such as ISO 27001, NIST CSF, COBIT, CIS Controls, or similar frameworks.
  • Good appreciation of cloud security, infrastructure security, secure software delivery practices, and modern enterprise technology environments.
  • Familiarity with audit methodologies, control assessments, and regulatory compliance programmes.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Analyst (Governance, Risk and Compliance)
Senior Security Analyst (Governance, Risk and Compliance)

ENERGY MARKET COMPANY PTE LTD • Singapore

On-site
SGD 120,000 - 180,000
Head / Lead, Cybersecurity
Head / Lead, Cybersecurity

SCIENTE • Singapore

On-site
SGD 180,000 - 260,000
GENERAL MANAGER, CYBERSECURITY
GENERAL MANAGER, CYBERSECURITY

Rikvin Capital Pte. Ltd. • Singapore

On-site
SGD 260,000 - 380,000
Head of Cybersecurity / Security Engineering Manager
Head of Cybersecurity / Security Engineering Manager

Charterhouse Pte Ltd • Singapore

On-site
SGD 180,000 - 240,000
Head of Security Operations
Head of Security Operations

Kerry Consulting • Singapore

On-site
SGD 260,000 - 420,000
Head / Lead, Cybersecurity
Head / Lead, Cybersecurity

Sciente International • Singapore

On-site
SGD 180,000 - 300,000
Senior / Cybersecurity & Governance Executive
Senior / Cybersecurity & Governance Executive

Singapore LNG Corporation Pte Ltd • Singapore

On-site
SGD 90,000 - 180,000
Cybersecurity Manager (Governance, Risk and Compliance) (JD#11267)
Cybersecurity Manager (Governance, Risk and Compliance) (JD#11267)

SCIENTE INTERNATIONAL PTE. LTD. • Singapore

On-site
SGD 90,000 - 140,000
Cybersecurity and Technology Risk Manager, Global MNC
Cybersecurity and Technology Risk Manager, Global MNC

Kerry Consulting • Singapore

On-site
SGD 150,000 - 220,000
Chief Information Security Officer (CISO)
Chief Information Security Officer (CISO)

Charterhouse Pte Ltd • Singapore

On-site
SGD 300,000 - 420,000