Search by job, company or skills

Cyber Assurance Analyst

4-10 Years
  • Posted 3 hours ago
  • Be among the first 10 applicants

Job Description

Job Description

You will independently assess cyber and technology controls, identify emerging risk exposures, and provide objective challenge and assurance to strengthen the Bank's cyber resilience. Working closely with stakeholders across Technology, Information Security and Risk Management, you will help drive effective risk management, control enhancement and continuous improvement across the Bank. As a Cyber Assurance Analyst, you will play a key role in providing independent assurance over cyber and technology risks, supporting the Bank's commitment to maintaining a secure, resilient and well-controlled operating environment.

Job Responsibilities

Responsibilities:- A. Thematic Risk Assurance *Plan and execute thematic assurance reviews across key cyber and technology risk domains, including, but not limited to cyber hygiene, identity and access management, vulnerability management, third-party security risk management, technology governance, cloud security, operational resilience, as well as other priority risk areas identified by management *Design and execute evidence-based validation activities to assess control design and operating effectiveness through walkthroughs, document and configuration reviews, sampling and targeted controls testing against regulatory, industry and internal standards *Identify systemic control weaknesses, recurring risk themes, and underlying root causes that may expose the Bank to elevated cyber or technology risks *Develop and operationalise AI-enabled continuous monitoring use cases to automate control testing, detect control deviations and emerging risk indicators, and provide timely risk intelligence to management and governance committees *Support continuous identification of control gaps, improvement opportunities, and emerging areas of concern. B. Emerging Threat-Informed Assurance *Assess whether existing controls remain effective against evolving threat actor tactics, emerging attack techniques and new technology risks *Incorporate relevant cyber threat intelligence, industry incidents and regulatory developments into thematic assurance reviews *Evaluate the Bank's preparedness against emerging risks including AI-enabled threats, third-party ecosystem attacks, cloud-native threats and identity-based attacks. C. Independent Challenge and Validation *Challenge assumptions in risk assessments, control evaluations, residual risk decisions and remediation strategies, while identifying blind spots and alternative risk perspectives *Review responses to audit findings, regulatory observations and risk assessments; validate that action plans address the risk exposure and that completed remediation is effective and sustainable *Assess whether accepted risks remain within the Bank's risk appetite and escalate significant or unresolved exposures through appropriate governance channels. D. Root Cause and Systemic Risk Analysis *Identify recurring findings and systemic weaknesses across technology domains and determine underlying root causes *Assess whether recurring issues indicate broader governance, process, capability or cultural weaknesses. E. Assurance Reporting, Governance & Remediation Oversight *Produce concise, risk-focused and evidence-based assurance reports, dashboards and control health metrics, and present findings and thematic observations to senior management and governance committees *Track management commitments and remediation activities through to closure *Validate remediation effectiveness and sustainability *Identify recurring issues and escalate significant concerns through governance channels. F. Stakeholder Engagement *Collaborate with Technology, Cyber Security, Control and Prevention, Risk Management, Internal Audit, Compliance, and business teams *Promote a culture of strong risk management, continuous improvement, and cyber resilience.

Job Skills

  • cybersecurity
  • information-security
  • MAS-Notice-FSM-N06-Cyber-Hygiene
  • CIS-Controls

Job Requirements

  • Degree in Cyber Security, Information Security, Computer Science, Information Technology or a related discipline * 4 to 10 years of experience in two or more of the following: Cyber Security Assurance, Threat Intelligence or Threat Hunting, Security Operations (SOC), Penetration Testing or Red Teaming, Security Architecture, Vulnerability Management, Information Security Governance, Cyber Risk Management, Incident Response, Cloud Security *Proven experience assessing security control effectiveness, identifying control weaknesses, and providing independent challenge on cyber risk and remediation activities *Experience within banking, financial services, critical infrastructure, or other highly regulated industries will be an advantage *Strong risk and control mindset, with the ability to apply risk-based thinking in assessing control effectiveness and prioritising assurance activities *Ability to provide constructive independent challenge while maintaining effective stakeholder relationships *Strong analytical, investigative and problem-solving capabilities *Excellent report writing, presentation and communication skills, with the ability to articulate complex technical and risk issues to both technical and non-technical audiences *Highly organised, detail-oriented and evidence-driven, with a structured approach to assurance and risk assessment *Self-motivated and able to thrive in environments requiring critical thinking, objectivity and sound judgement. Preferred Skills *Strong understanding of the following: Cyber security control frameworks and best practices, including but not limited to: -MAS Notice FSM-N06 Cyber Hygiene -MAS Technology Risk Management Guidelines -NIST Cybersecurity Framework -CIS Controls -ISO 27001 -COBIT -Control Testing and Assurance Methodologies -Regulatory Expectations within Financial Services -Technology risk management principles -Information security governance and control assurance -Attack surface management -Vulnerability management programmes -Identity and access management controls -Third-party risk management practices -Security monitoring and incident management processes -Cloud security and emerging technology risks. Only shortlisted candidates will be notified.

More Info

Job Type:
Industry:
Employment Type:

About Company

Job ID: 152260065

Similar Jobs

Singapore, Battery Road

Skills:

information security governance red teaming Vulnerability ManagementCloud SecurityCyber Risk ManagementIncident ResponsePenetration TestingThreat HuntingThreat IntelligenceRegulatory Expectations within Financial ServicesSecurity monitoring and incident management processesThird-party risk management practicesSecurity ArchitectureControl Testing and Assurance MethodologiesTechnology risk management principlesCyber Security AssuranceCyber security control frameworksAttack surface managementInformation security governance and control assuranceIdentity and access management controlsSecurity OperationsAI-enabled continuous monitoring

Beware of Scammers

We don’t charge money for job offers