JobScope - Cyber Risk Analyst / Manager
TheCyber Risk Analyst / Manager is responsible for identifying, assessing, andmanaging cybersecurity risks to support clients in strengthening their securityposture, achieving regulatory compliance, and preparing for cybersecuritycertifications.
KeyResponsibilities
- Conduct cybersecurity risk assessments and maintain risk registers.
- Perform gap assessments against cybersecurity frameworks and regulatory requirements (e.g. Cyber Essentials, Cyber Trust, ISO/IEC 27001, DPTM, PDPA, MAS TRM).
- Review and assess the effectiveness of cybersecurity controls, including governance, asset management, access control, endpoint security, data protection, network security, backup, and incident response.
- Develop risk treatment plans and monitor remediation activities.
- Prepare professional reports, including risk assessments, gap analysis, remediation plans, and management presentations.
- Facilitate stakeholder interviews, workshops, and security assessment sessions.
- Evaluate third-party and cloud service provider cybersecurity risks.
- Provide cybersecurity governance and compliance advisory to clients.
- Support certification readiness, audits, and continuous improvement initiatives.
- Keep abreast of emerging cyber threats, industry best practices, and regulatory developments.
Key Deliverables
- Cyber Risk Assessment Report
- Cyber Risk Register
- Gap Analysis Report
- Remediation Plan
- Compliance & Certification Readiness Report
- Executive Risk Dashboard
- Security Improvement Roadmap