Free with a WorkJio account: we compare your profile with this job and show what you already meet.
Share with a friend
Start
Not stated
Work mode
On-site
Experience
Experienced
About the role
This role sits within the Cyber GRC function, ensuring the organisation's cybersecurity strategy stays aligned with business goals while managing policies, standards and frameworks, cyber risk, independent second-line control review and testing, and external regulatory obligations. You will work closely with first-line risk and control owners as well as senior management and risk forums. It suits someone with a strong information security and risk management background who is comfortable providing oversight, advisory and assurance across the business.
What you'll do
Lead the end-to-end lifecycle of information security governance and policy management
Drive cyber risk management and reporting
Lead second-line assurance and compliance monitoring
Manager, Cybersecurity Assurance job at StarHub, Singapore | WorkJio
Provide second-line oversight and support for audit engagements with first-line stakeholders
Drive security culture, advisory and stakeholder engagement
Manage the development of information security policies and sub-policies for adoption
Manage compliance risk relating to information security policies and sub-policies
Evaluate the adequacy and effectiveness of risk management practices and controls implemented by first-line risk owners, control owners, control supervisors and control performers
Manage the security and risk deviation process for policies and sub-policies
Maintain the risk profile and risk register for IT security and cybersecurity risks relating to CII and non-CII
Develop and drive regular monitoring and reporting of key risk indicators for cybersecurity
Manage regular risk reporting and escalation to senior management and relevant risk forums
Manage the control and compliance framework through timely updates of industry standards and regulatory requirements
Perform second-line assurance reviews such as control review and testing on first-line stakeholders, provide actionable recommendations and engage stakeholders on implementation
Communicate and raise awareness of policies and sub-policies with stakeholders for implementation
Advise stakeholders on information security policy and sub-policy requirements
Conduct briefings and training on cyber risk and policy awareness, including risk management processes, policy compliance, emerging cyber risks and trends, issues from second-line control review and testing, and audit findings, in support of the cybersecurity awareness programme
Provide second-line oversight and support throughout audit engagements, covering readiness before the audit, fieldwork execution and monitoring remediation of findings afterwards
Maintain a tracker or register of audit findings to monitor remediation progress, ensure closure of audit issues and support scoping for second-line assurance reviews
Good to know
Based in Singapore
Requirements
More than 5 years of experience in information or cybersecurity and risk management
Experience leading cybersecurity risk assessment and risk reduction initiatives
Experience in IT or IT security policy development and implementation
Experience driving IT security thematic assessments and IT audits
Good knowledge and experience handling IT security and cybersecurity audits
Good knowledge and experience driving compliance with cybersecurity regulatory requirements
Apply on the company website
You will leave WorkJio. Never pay a fee or share your Singpass password, OTP or bank log-ins to apply.