[What the role is]
As an Assistant Manager in the Governance, Risk and Compliance (GRC) team in the Security, Process and Governance department, Digital Technology Transformation division, you will track, manage and report on the risk management and governance of ICT and Smart Systems (ICTSS) at Sentosa Development Corporation (SDC).
Reporting to the GRC Manager, you will manage systems under GRC custody including the IT Service Management (ITSM) system for service/change requests and incident reporting, Project & Portfolio Management, Compliance tracking, Digital Governance Platform and maintenance of GRC knowledge-bases and document repositories.
You will work closely with system managers to maintain the SDC system inventory and track system changes, periodic and adhoc cybersecuriy testing, IT risk assessments, audits and follow-up on findings and open items until closure.
[What you will be working on]
- Manage GRC systems (e.g. ITSM, DGP, etc.)
- Manage the GRC knowledge base, guidelines, forms and templates in SharePoint Online repository.
- Coordinate the tracking and reporting ICT&SS Delivery and Support Projects under Project & Portfolio Management.
- Support the GRC Manager in maintaining ICT&SS Policies and System Security Plans (SSPs).
- Work with the security testing vendor to track and report on periodic VAPT/SCR security tests and liaise with system managers to close findings on a timely basis.
- Coordinate IT Audit review sessions and auditor responses with relevant internal and external stakeholders.
[What we are looking for]
- Diploma/Degree in Information Technology or related field.
- Minimum 2 years of IT application system life-cycle management and/or system support & management.
- Familiarity with data and cybersecurity risks and controls in system implementation and support stages, including vulnerability assessment / penetration testing (VA/PT) and SCR (source code review) for cloud-hosed, web-based and mobile solutions.
- Understanding of IT risk management.and controls.
- Exposure to system audits and/or public sector system policies and governance is an advantage.
- Ability to handle occassional tight deadline, and manage project constraints in a dynamic environment including adhoc risk profiling and compliance reporting.
- Familiarity with government procurement processes.
Good communication skill written and spoken.