Search by job, company or skills

Manager, Cybersecurity Assurance & Resilience

  • Posted 3 hours ago
  • Be among the first 10 applicants

Job Description

Job description:

Job Purpose

In today's rapidly evolving threat landscape, cybersecurity governance is essential to maintaining operational integrity and regulatory compliance. SMRT is seeking a detail-oriented and proactive Manager, Cybersecurity Assurance & Resilience to join our Governance, Risk and Compliance (GRC) team. This role is responsible for ensuring the effectiveness of SMRT's cybersecurity assurance, resilience and third-party risk management programmes through the assessment of cybersecurity controls, oversight of compliance requirements, management of third-party cyber risks, and validation of organisational readiness to respond to and recover from cybersecurity incidents. 

Responsibilities

As Manager, Cybersecurity Assurance & Resilience, you will support Head, Governance, Risk & Compliance in ensuring the effectiveness of SMRT's cybersecurity assurance, resilience and third-party risk management programmes. Your responsibilities include:

 

•    Cybersecurity Assurance
o    Plan, manage and execute cybersecurity assurance activities to assess the effectiveness of cybersecurity controls across systems, processes and business functions. 
o    Conduct reviews against cybersecurity policies, standards, regulatory requirements and industry frameworks to identify control gaps and improvement opportunities. 
o    Assess the implementation and operating effectiveness of cybersecurity controls and recommend corrective actions where necessary. 
o    Track remediation efforts and monitor the closure of identified findings and weaknesses. 
o    Support cybersecurity maturity assessments and benchmarking exercises to evaluate organisational cybersecurity capabilities. 
o    Coordinate evidence collection, validation and reporting for cybersecurity assurance reviews and audits. 

 

•    Cybersecurity Compliance Support
o    Support cybersecurity compliance activities to ensure adherence to internal policies, standards, regulatory requirements and organisational obligations. 
o    Assist in monitoring and reporting cybersecurity compliance posture across business units and systems. 
o    Conduct compliance gap assessments and support remediation planning activities.
o    Support internal and external audit engagements, regulatory inspections and compliance assessments. 

 

•    Third-Party Cyber Risk Management & Security Rating Monitoring
o    Manage and continuously enhance the Cybersecurity Third-Party Risk Management (TPRM) programme and associated assessment processes. 
o    Perform cybersecurity due diligence assessments for vendors, suppliers and service providers. 
o    Monitor vendor's cybersecurity posture and security ratings to identify emerging risks and ensure timely remediation of identified issues. 
o    Prepare assessment repots, risk findings and recommendations to support management decision-making, procurement evaluation and governance reviews.

 

•    Cybersecurity Resilience & Table-Top Exercises
o    Develop, coordinate and facilitate cybersecurity table-top exercises, cyber crisis simulations and incident response exercises. 
o    Design realistic cyberattack scenarios to validate incident response, crisis management and decision-making processes. 
o    Document exercise outcomes, lessons learnt and recommendations for improvement. 
o    Support initiatives to strengthen organisational cyber resilience, operational readiness recovery capabilities. 

Qualifications & Work Experience

•    A bachelor's degree in Cybersecurity, Information Systems, Computer Science, or a related discipline.
•    5–10 years of experience in cybersecurity governance, audit, assurance, compliance, resilience or third-party risk management.
•    Familiarity with cybersecurity frameworks such as NIST CSF, ISO/IEC 27001, and CIS Controls will be advantageous.
•    Experience managing vendor cybersecurity assessments and third-party risk management programmes will be advantageous.
•    Experience designing or facilitating cyber incident response exercises and table-top exercises will be advantageous.
•    Knowledge of regulatory requirements including the Cybersecurity Code of Practice (CCoP), Personal Data Protection Act (PDPA), and sector-specific standards will be advantageous.

Skills

Technical Skills
•    Understanding of cybersecurity governance, assurance and compliance principles.
•    Ability to assess control effectiveness and identify gaps in policy implementation.
•    Skilled in evidence gathering and report writing.
•    Familiarity with third-party risk management methodologies and vendor security assessment practices.
•    Ability to develop meaningful cybersecurity metrics, reports and dashboards. 

 

Core Competencies
•    Excellent analytical and documentation skills, with strong attention to detail.
•    Effective communicator with the ability to engage stakeholders across technical and non-technical domains.
•    High integrity and discretion in handling sensitive information.
•    Proactive and collaborative mindset, with a commitment to continuous improvement

More Info

Job Type:
Industry:
Function:
Employment Type:

Job ID: 152831177

Similar Jobs

Singapore, Paya Lebar

Skills:

Payment ProcessingPayments risk frameworkOperational fraudE-moneyFintechThird-party risksSafeguarding technologyRisk managementManagement Reporting

Singapore, Paya Lebar

Skills:

Incident ResponseServersIt InfrastructureIt Operations ManagementNetworksrisk assessmentsproject managementcybersecurity policiescloud platformscompliance governance

Singapore, Paya Lebar

Skills:

Application ManagementSystems IntegrationEnterprise ApplicationsSoftware DeliveryCybersecurityDigital TransformationPDPA-related controlstechnology risk managementProject Governance

Beware of Scammers

We don’t charge money for job offers