Key Responsibilities
- Conduct cybersecurity risk assessments and compliance gap assessments.
- Review clients cybersecurity governance frameworks, policies, procedures, and controls.
- Develop and maintain cybersecurity risk registers, treatment plans, remediation trackers, and compliance matrices.
- Support the implementation and maintenance of information security management systems.
- Assess cybersecurity controls through interviews, document reviews, walkthroughs, and evidence validation.
- Prepare cybersecurity policies, standards, procedures, guidelines, and supporting templates.
- Support internal audits, external audits, certification consultancy, and regulatory reviews as needed.
- Assist clients in preparing for cybersecurity certifications, customer assessments, and compliance obligations.
- Conduct third-party cybersecurity risk assessments and security due diligence.
- Track audit findings, compliance gaps, corrective actions, and risk treatment activities.
- Prepare assessment reports, management presentations, dashboards, and executive summaries.
- Facilitate workshops and meetings with business owners, system owners, technical teams, and management.
- Provide practical recommendations to improve cybersecurity governance, risk management, and control effectiveness.
- Support proposal preparation, project planning, and other cybersecurity consulting activities.
- Other ad hoc duties as assigned.
Requirements
- Diploma or degree in Cybersecurity, Information Technology, Computer Science, Information Security or a related discipline.
- Relevant experience in cybersecurity consulting, governance, risk, compliance, audit, information security, or technology risk.
- Good understanding of cybersecurity controls, risk management principles, compliance requirements, and security governance.
- Ability to review policies, procedures, system documentation, and supporting evidence.
- Ability to explain cybersecurity risks and requirements to both technical and non-technical stakeholders.
- Ability to manage multiple assignments and work independently or as part of a project team.
Preferred Qualifications
- CISSP
- CISM
- CISA
- CRISC
- ISO/IEC 27001 Lead Implementer
- ISO/IEC 27001 Lead Auditor
Interested applicants, please Email, and look for [Confidential Information]
Joanne Loo Sze Min
EA Personnel Registration Number: R26160686
Recruit Express Pte Ltd
Company Reg No. 199601303W
EA License No. 99C4599