StarHub

Manager, Cybersecurity Assurance

StarHub

Singapore · Full Time

Be the first to apply

Experience
5+ yrs
Salary
—
Openings
1
Posted
2 days ago
Work mode
In office
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

Role Overview

The Cybersecurity Governance, Risk, and Compliance (GRC) Manager is responsible for aligning the organization's cybersecurity strategy with business objectives. This role involves managing policies, standards, and frameworks, overseeing cyber risk management, conducting independent 2nd line control reviews and testing, and ensuring compliance with external mandates.

Key Accountabilities

  • Lead the management and full lifecycle of information security governance and policy administration.
  • Oversee cyber risk identification, evaluation, and reporting activities.
  • Direct 2nd line assurance efforts including compliance monitoring and control review.
  • Coordinate with 1st line stakeholders to facilitate audit readiness, fieldwork, and remediation follow-up.
  • Promote a strong security culture and facilitate stakeholder advisory and engagement.

Primary Responsibilities

  • Develop and maintain StarHub’s Information Security policies and related sub-policies for organizational adoption.
  • Oversee compliance risk associated with security policies and address security/risk deviations.
  • Conduct oversight on cyber risk management by assessing the effectiveness of 1st line controls and risk practices.
  • Maintain the risk register focusing on IT Security and Cybersecurity risks for critical and non-critical infrastructure.
  • Implement monitoring systems and report on key cybersecurity risk indicators regularly.
  • Escalate risk matters to senior management and relevant risk forums as appropriate.
  • Manage the Control and Compliance framework including timely incorporation of regulatory and industry standard updates.
  • Execute 2nd line assurance reviews, including control testing of 1st line functions, and provide actionable recommendations for improvements.
  • Communicate policy requirements and raise awareness among stakeholders to ensure effective implementation.
  • Advise stakeholders on Information Security policy and compliance demands.
  • Deliver briefings and training sessions on cyber risk management, policy compliance, emerging risks, and findings from reviews and audits to support the cybersecurity awareness program.
  • Provide oversight and support during audits ensuring stakeholder preparedness, execution facilitation, and follow-up on remediation.
  • Maintain detailed audit issue trackers to monitor progress and facilitate audit closure and future assurance planning.

Qualifications

  • Over five years of experience in information or cybersecurity and risk management roles, with leadership in cybersecurity risk assessments and mitigation efforts.
  • Proven expertise in developing and implementing IT and IT-Security policies.
  • Experienced in conducting IT security thematic assessments and audits.
  • Familiarity with IT-security and cybersecurity audit processes.
  • Strong background in ensuring compliance with cybersecurity regulatory requirements.
  • Effective problem analysis and resolution capabilities.
  • Competent in managing diverse stakeholders and fostering collaboration.

How they work

Communication Problem Solving Attention to Detail Relationship Building

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help
Broxer