[LTA-PT] MANAGER/DEPUTY MANAGER, TICKETING SYSTEM & GOVERNANCE (GOVERNANCE, RISK & COMPLIANCE)
GVT Government Technology Agency- Posted 10 hours ago
- Be among the first 10 applicants
Job Description
[What the role is]
[LTA-PT] MANAGER/DEPUTY MANAGER, TICKETING SYSTEM & GOVERNANCE (GOVERNANCE, RISK & COMPLIANCE)[What you will be working on]
Become a catalyst for effective system ownership, operations and governance as a Transit Ticketing System and Governance officer!
Are you passionate about optimising public service delivery and making a difference Join our team and take a lead role in maintaining, enhancing and governing the transit ticketing system to maintain commuter trust, strengthen people-centric service delivery and ensure a future-ready public transport transit ticketing system that provides seamless fare payment services.
Transit ticketing system is an integrated fare collection and contactless smart card payment system that enables commuters to pay for their public transport journeys across Singapore and consists of frontend system (MRT/LRT fare gates, bus fare readers, top up machines devices and applications) and backend system (servers, network, infrastructure and applications).
Responsibilities:
Governance Framework
. Maintain oversight of Transit Ticketing System security, risk management and compliance in the role of operations lead supporting the system owner, to ensure the confidentiality, integrity, and availability of systems, in accordance with regulatory and organisational governance requirements.
. Maintain the governance framework and ensure its operational effectiveness by overseeing process, metrics, audit and risk management reports by internal and external stakeholders, to achieve the framework's objectives and perform commuter, operational and financial impact assessment to mitigate risk, minimize service disruption and improve commuter experience.
Cybersecurity and Data Protection Governance:
. Enforce cybersecurity and data protection policies, standards, and procedures aligned with government IM8 requirements and industry standards such as ISO 27001, NIST and PCI-DSS.
. Collaborate with internal technical cyber security team and contractors to monitor the effectiveness of cybersecurity and controls of IT infrastructure, cloud services, networks and applications in transit ticketing system.
. Establish key metrics (KPIs) on cyber security and data protection and review report submitted by contractors and periodically update to senior management.
Compliance and Risk Management:
. Review cybersecurity policy developed by the technical security team and enforce compliance.
. Support internal and external audits and assessments related to cybersecurity and data protection and assess commuter, operational and financial impact and ensure closure of audit action plan.
. Maintain a register of risks related to information security and data protection, and track mitigation plans.
. Collaborate with technical cyber security teams to ensure internal delivery teams and third-party service providers meet security and privacy requirements for transit ticketing system.
.Oversee data protection measures and access controls of transit ticketing system.
Incident Management:
. Manage cybersecurity and data protection incidents including detection, analysis, containment, eradication, and recovery.
. Review incident management report and post-incident reports, assess root cause analysis conducted by technical security team and contractors, and coordinate implementation of corrective/preventive actions.
. Coordinate with required stakeholders for incident response, business continuity and disaster recovery.
Awareness and Training:
. Collaborate with technical cyber security team to implement cybersecurity and data privacy awareness programs, including phishing simulations and incident response tabletop exercises.
. Support staff training on cyber security, secure data handling, breach prevention, and compliance obligations.
[What we are looking for]
Knowledge in computer science, engineering or information technology, cyber security.
Candidates with proven experience in managing cyber security and data protection operations and incident management.
Strong understanding of information security and data protection principles, ISO 27001, PDPA, PCI-DSS Security Standards and cloud security standards.
Strong incident response, good communication, situational awareness and stakeholder management skills.
Ability to analyze complex problems and recommend practical solutions.
As part of the shortlisting process for the role, you may be required to complete a medical declaration and / or undergo further assessment.
More Info
Key Skills
Transit Ticketing System
PCI-DSS


