Search Jobs

Search by job, company or skills

Cybersecurity and Risk Engineer

Cybersecurity and Risk Engineer

quess selection & services pte. ltd.
5-8 Years
SGD 6,000 - 7,000 per month
  • Posted 12 hours ago
  • Be among the first 10 applicants

Job Description

We are looking for an experienced Technology Risk & Third-Party Security Assessment Specialist to join our team and support the assessment and management of technology and cybersecurity risks associated with third-party service providers and outsourcing arrangements.

Key Responsibilities

  • Conduct third-party risk and vendor security assessments as part of the vendor due diligence and onboarding process.
  • Review vendor information security policies, cybersecurity controls, certifications, audit reports, SOC reports, risk assessments and supporting evidence.
  • Assess third-party technology, information security, cloud, compliance and outsourcing risks.
  • Identify security and control gaps and work with vendors and internal stakeholders to define appropriate remediation and risk mitigation actions.
  • Prepare clear and comprehensive risk assessment reports, findings and recommendations for management review.
  • Monitor outstanding risk issues and remediation actions through to closure.
  • Partner with Business, Technology, Cybersecurity, Compliance, Risk, Procurement and vendor stakeholders to support effective risk management.
  • Support ongoing monitoring and periodic reassessment of critical third-party service providers.
  • Ensure assessments are aligned with relevant regulatory, security and internal risk management requirements.

Requirements

  • Minimum 5 years of experience in Technology Risk, Cybersecurity, Information Security, IT Audit, Third-Party Risk or Vendor Risk Management.
  • Strong understanding of Third-Party Risk Management (TPRM) and vendor due diligence processes.
  • Experience assessing cybersecurity controls, technology risks, cloud security and outsourcing arrangements.
  • Ability to review and interpret SOC reports, ISO 27001 certifications, audit reports, security assessments and control evidence.
  • Strong analytical and report-writing skills, with the ability to communicate technical risks clearly to business stakeholders.
  • Good stakeholder management skills and experience working with internal teams and external vendors.
  • Familiarity with MAS Technology Risk Management (TRM) and MAS Outsourcing Guidelines is highly advantageous.
  • Experience in banking, financial services, fintech or other regulated environments is preferred.

Certifications

Relevant certifications such as CISA, CISSP, CRISC, CISM or ISO 27001 are advantageous.

Ankita

EA License Number: 23C2060 Registration ID is R22109715

Disclaimer: The company is committed to ensuring the privacy and security of your information. By submitting this form, you consent to the collection, processing, and retention of the information you provide. The data collected (which may include your contact details, educational background, work experience and skills) will be used solely for the purpose of evaluating your qualifications for the position you're applying for. Your data will be stored securely and retained for the duration necessary to fulfill our hiring process. If you are not selected for the position, your data will be kept on file for a limited period in case future opportunities arise. You have the right to access, correct, or delete your data at any time by contacting us at Quess Singapore | A Leading Staffing Services Provider in Singapore (quesscorp.sg)

This is in partnership with the Employment and Employability Institute Pte Ltd (e2i).

e2i is the empowering network for workers and employers seeking employment and employability solutions. e2i serves as a bridge between workers and employers, connecting with workers to offer job security through job-matching, career guidance and skills upgrading services, and partnering employers to address their manpower needs through recruitment, training, and job redesign solutions. e2i is a tripartite initiative of the National Trades Union Congress set up to support nation-wide manpower and skills upgrading initiatives. By applying for this role, you consent to Quesscorp Singapore's PDPA and e2i's PDPA

More Info

Job Type:
Industry:
Employment Type:

Key Skills

Control evidence

MAS Outsourcing Guidelines

ISO 27001 certifications

Cybersecurity controls

Outsourcing arrangements

SOC reports

Similar Jobs

5-8 yrs
SGD 6,500 - 7,000 per month
Singapore
Skills:
technology risk , cloud security, Cybersecurity, Information Security, Iso 27001, Cism, It Audit, vendor due diligence processes, Outsourcing Guidelines, Vendor Risk Management, MAS Technology Risk Management TRM, outsourcing risk management, Cisa, third-party risk management, cybersecurity controls, Cissp, CRISC
5-8 yrs
SGD 5,500 - 7,000 per month
Singapore
Skills:
MAS Technology Risk Management (TRM) Guidelines, Cloud Security, Cybersecurity, Information Security, Iso 27001, Cism, It Audit, Security Assessments, Technology Outsourcing Risk, Third-Party Risk Management, MAS Outsourcing Guidelines, Cisa, Vendor Due Diligence, Cybersecurity Controls, Vendor Third-Party Risk Management, Cissp, CRISC, Technology Risk Management
4-7 yrs
SGD 3,000 - 7,000 per month
Singapore, Ubi
Skills:
MAS Technology Risk Management (TRM), technology risk , Cloud security, Cybersecurity, Information Security, Iso 27001, Cism, It Audit, Outsourcing risk management, Outsourcing Guidelines, Vendor Risk Management, Cisa, Third-party risk management, Cybersecurity controls, Vendor due diligence, Cissp, CRISC
5-7 yrs
Singapore
Skills:
MAS Technology Risk Management (TRM), cloud security, Iso 27001, Cism, outsourcing risk management, Cisa, third-party risk management, cybersecurity controls, Cissp, outsourcing guidelines, vendor due diligence, CRISC
5-8 yrs
SGD 5,000 - 7,000 per month
Singapore, Ubi
Skills:
Cloud security, Cybersecurity, Information Security, Iso 27001, Cism, It Audit, Outsourcing risk management, Outsourcing Guidelines, Vendor Risk Management, MAS Technology Risk Management TRM, Cisa, Third-party risk management, Cybersecurity controls, Vendor due diligence, Cissp, CRISC, Technology Risk Management