Free with a WorkJio account: we compare your profile with this job and show what you already meet.
Share with a friend
Start
Not stated
Work mode
On-site
Experience
Some experience
About the role
This role sits within the cybersecurity governance, risk and compliance function, ensuring security strategy supports business objectives while managing policies, frameworks and regulatory obligations. You will act as a second-line control and assurance partner to first-line teams, providing oversight, review and advisory support. It suits an experienced security or risk professional who is comfortable engaging senior stakeholders and driving compliance across a large organisation.
What you'll do
Lead the full lifecycle of information security governance and policy management
Drive cyber risk management and reporting
Lead second-line assurance and compliance monitoring
Provide second-line oversight and support for audit engagements alongside first-line stakeholders
Senior Engineer, Cyber GRC job at StarHub, Singapore | WorkJio
Promote security culture, advisory work and stakeholder engagement
Develop information security policies and sub-policies for adoption
Manage compliance risk against those policies and sub-policies
Evaluate the adequacy and effectiveness of risk management practices and controls implemented by first-line risk and control owners
Manage the security and risk deviation process for policies and sub-policies
Maintain the risk profile and risk register for IT security and cybersecurity risks, covering both CII and non-CII
Develop and drive regular monitoring and reporting of key cyber risk indicators
Handle regular risk reporting and escalation to senior management and risk forums
Manage the control and compliance framework, keeping industry standards and regulatory requirements up to date
Perform second-line assurance reviews such as control testing on first-line stakeholders, providing actionable recommendations and engaging them on implementation
Communicate policy and sub-policy requirements to stakeholders in a timely manner
Advise stakeholders on information security policy and sub-policy requirements
Conduct briefings and training on cyber risk and policy awareness, including risk processes, compliance, emerging trends, review observations and audit findings
Support the cybersecurity awareness programme
Provide second-line oversight throughout audit engagements, from readiness and fieldwork through to monitoring remediation of findings
Maintain a tracker or register of audit findings to monitor remediation progress, confirm closure and support scoping of assurance reviews
Good to know
Based in Singapore
Requirements
More than 3 years of experience in information or cybersecurity and risk management
Experience leading cybersecurity risk assessment and risk reduction initiatives
Experience developing and implementing IT or IT-security policy
Experience driving IT-security thematic assessments and IT audits
Good knowledge and experience handling IT-security and cybersecurity audits
Good knowledge and experience driving compliance with cybersecurity regulatory requirements
Apply on the company website
You will leave WorkJio. Never pay a fee or share your Singpass password, OTP or bank log-ins to apply.