- Experience
- 10+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 3 weeks ago
- Work mode
- In office
- Education
- Bachelor's degree
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Role Overview
We are looking for a seasoned cybersecurity leader to direct the organization's governance, risk, and assurance practices. This role involves defining and upholding a robust cybersecurity governance framework, managing security risks effectively, and promoting ongoing advancements throughout the enterprise security program. Reporting directly to the Chief Information Security Officer (CISO), you will lead the Governance, Risk & Compliance (GRC) division while collaborating closely with technology, risk management, audit, and business teams to enhance the organization's cyber resilience. This role blends strategic leadership with operational control, ideal for a professional passionate about enterprise-level security initiatives in a highly regulated setting.
Key Responsibilities
- Develop and sustain cybersecurity governance policies, standards, and control frameworks aligned with enterprise goals.
- Maintain alignment of governance processes with evolving regulations, business needs, and industry best practices.
- Evaluate security policy exceptions and risk acceptance submissions, providing guidance and oversight.
- Promote continuous governance maturity enhancements across the organization.
- Lead cybersecurity risk assessments to identify and assess technology and cyber vulnerabilities.
- Oversee assurance activities such as vulnerability scans, penetration tests, control audits, and cyber resilience drills.
- Monitor remediation progress to ensure timely resolution of identified risks and control weaknesses.
- Assess emerging cyber threats and technologies, advising on applicable safeguards.
- Serve as the chief cybersecurity liaison during internal and external audit processes.
- Manage audit response coordination and remedial action plans resulting from audit observations.
- Ensure governance mechanisms meet security and regulatory compliance standards.
- Collaborate with internal teams to boost security controls and governance effectiveness.
- Lead and mentor a high-performing Governance, Risk & Compliance team fostering accountability, learning, and excellence.
- Offer strategic counsel to technology and business leaders regarding cyber risk and governance.
- Support executive leadership with routine reporting on cyber risk status, control performance, and program maturity.
- Develop and track key security metrics and risk indicators to gauge program success.
- Prepare insightful reports and presentations for senior management and governance boards.
- Encourage data-driven decisions via comprehensive cyber risk and control performance analysis.
Candidate Requirements
- A bachelor's degree in Information Security, Computer Science, Computer Engineering, or a relevant field.
- Minimum of 10 years' experience in cybersecurity governance, enterprise risk management, information security, or IT assurance.
- Proven leadership experience managing Governance, Risk & Compliance teams or enterprise security governance functions.
- Experience in regulated industries or sizable, complex organizations is highly preferred.
- Recent experience in leading and developing teams.
- Strong expertise in cybersecurity governance, enterprise risk frameworks, and control structures.
- Hands-on experience with standards such as ISO 27001, NIST CSF, COBIT, CIS Controls, or related frameworks.
- Good understanding of cloud security, infrastructure protection, secure software development practices, and modern enterprise technologies.
- Knowledge of audit processes, control evaluations, and regulatory compliance initiatives.
Additional Information
This position is based in Singapore and requires on-site presence. Applicants interested in applying should prepare their CV for submission. Only shortlisted candidates will be contacted due to the expected volume of applications.
Registration Number: R1876389
License Number: 16S8060
Minimum education
Bachelor's Degree
Industry
Management Consulting