Search Jobs

Search by job, company or skills

AVP, Security Governance & Assurance

AVP, Security Governance & Assurance

NETS
8-10 Years
  • Posted 14 days ago
  • Be among the first 10 applicants

Job Description

Job description:

Key Responsibilities

  • Responsible for the management and enforcement of IS related policies, processes and procedures.
  • Execute policies, processes and procedures to facilitate effective IT and cyber related-risk Process and Control arising from Audit Findings or Process improvement maturity
  • Partner and work with internal stakeholders to review, identify, streamline and implement process improvements with regards to Cyber risk management
  • Reference to regulator's notices, circulares and guidelines (such as, TRM, Cyber Hygiene) to assess risk and gaps, and work with Line 2 and Tech to improve policies and processes to mitigate risks, minimize their impact to operations
  • Prepare and provide data for risk analysis and reporting.
  • Communicate and provide guidance of new IS policies and standards to relevant stakeholders.
  • Manage IS related audits, regulatory inspections. Review the audit findings with key stakeholders to determine audit findings root cause, formulate action plans accordingly and verify remedial solutions for closure
  • Laision for IS audits, Risk and Compliance activities and providing support to business audits that have IS involvement.
  • Manage audit lifecycle from start to end (eg kick off meeting, RFI, fieldwork, reporting and closure of audit findings).
  • Ability to innovate and automate as required

Requirements

  • Degree in Computer Science, Engineering or any other related disciplines with at least 8 years of progressive experience in Information security, including experience in security policy development, risk assessment, compliance implementation & monitoring and governance (preferably from financial/banking/payment industry
  • Good working knowledge of enterprise security risk management methods and techniques to successfully deliver the security risk management and assessment outcome.
  • Prior experience in implementing a program which includes the collation, management and reporting of security metrics (KRI) such as vulnerability management, open software security vulnerabilities, penetration testing findings, security alerts and incidents
  • Experienced in information security frameworks including ISO27000 standard, NIST framework and regulations such as Cyber Hygiene Notice, Technology Risk Management Guidelines and Personal Data Protection Act.
  • Ability to work in a team environment and work independently with minimal supervision and produce results that meet standards of quality, timeliness and acceptability
  • Willingness to deep-dive and learn about the Information Security function within the payments domain
  • Strong writing, communication and inter‐personal skills 

More Info

Job Type:
Industry:
Employment Type:

Key Skills

Technology Risk Management Guidelines

ISO27000 standard

Cyber Hygiene Notice

Monitoring and governance

NIST framework

Personal Data Protection Act

Enterprise security risk management

About Company

Similar Jobs

10-12 yrs
Singapore
Skills:
Penetration TestingIso 27001Vulnerability ManagementMAS TRM GuidelinesCyber HygieneNIST FrameworkGovernanceRisk AssessmentRegulatory RequirementsCompliancesecurity policy development
6-10 yrs
Singapore
Skills:
Generative AIData analytics tools and techniquesQA monitoring and control testing frameworksSampling methodologiesRegulatory reporting governance
6-12 yrs
Singapore
Skills:
MAS Technology Risk Management (TRM) GuidelinesThird Party Risk Management frameworksOperational resilienceConcentration risk assessmentsOutsourcing governance frameworksISO certificationsMAS Notice 658MAS Guidelines on OutsourcingReviewing and challenging independent assurance reports and certificationsTechnology and cybersecurity assessmentResilience testingSecurity AssessmentsSOC reportsRecovery objectives
7-9 yrs
Singapore
Skills:
security assurance Identity And Access ManagementInformation SecurityData ProtectionIso 27001It AuditThreat ModellingCloud TransformationNIST CSFControl Frameworksoperational controlsNIST 800-53Technology Risk ManagementGovernance Assessment MethodologiesMAS TRM Guidelines
7-9 yrs
Singapore, Tampines
Skills:
metrics reporting compliance monitoring Vulnerability ManagementData ProtectionIso 27001Incident Managementcontrol gapscybersecurity governance frameworkarchitecture riskssecurity resiliencesecure-by-design assessmentsMAS Technology Risk Management GuidelinesRegulatory Compliancevendor security assessmentscontrol requirementsCISsecure design standardsStakeholder EngagementSecurity Policiesnistarchitecture review checklistsarchitecture review criteria