The Security & Compliance Manager governs Service Provider infrastructure security operations and the Customer regulatory evidence pipeline under the Managed Services SOW. The role serves as the single point of accountability for translating Security Operations and Compliance towers into a defensible operating rhythm, while security risk acceptance, cyber incident ownership, and policy decisions remain with the Customer.
RESPONSIBILITIES
- Regulatory & Audit Governance: Own delivery of the Compliance/Audit Tower, providing operational evidence (logs, SLA reports, change records) for MAS TRM guidelines and regional regulatory frameworks. Act as the primary contact for Customer and regulator audits. Oversee subcontractor disclosure and outsourced control reviews.
- Access & Identity Management: Administer CyberArk (PSM/CPM health, credential reconciliation, DR testing, quarterly recertification RACI). Oversee Azure AD/Entry ID end-user accounts, role administration, conditional access, and identity security remediation. Maintain personnel vetting registers and segregation-of-duties matrices.
- PKI & Cryptographic Operations: Manage the Microsoft Internal CA hierarchy (Root/Issuing CA, certificate issuance/renewal/revocation, CRL/AIA publication, monthly health/expiry reports). Execute the full Thales KMS/HSM key lifecycle under Customer-approved cryptographic policy and quorum control.
- Infrastructure Security & Vulnerability Management: Integrate device logs, maintain SIEM forwarders, and support Customer-led security investigations. Run Tenable vulnerability scans, track findings, oversee Defender/antivirus agents, and apply approved OS/device patches within agreed windows.
- Governance Forums & Policy: Chair monthly/quarterly Security and PKI/PAM Reviews. Represent security matters at QBRs and DR Readiness Reviews. Provide operational incident input for the Customer's annual Information Security Policy review. Ensure team members maintain role-appropriate security certifications.
REQUIREMENTS
- Experience & Education: 7–10 years of relevant experience with a Bachelor's degree in CS, IT, Engineering, or equivalent. CISSP, CISM, or CISA certification expected.
- Regulatory Expertise: Strong background in MAS TRM Guidelines and APAC regulatory/outsourcing frameworks (e.g., BNM, HKMA) with experience facilitating third-party and regulator audits.
- Hands-On Technical Mastery: Deep operational expertise with CyberArk (PSM/CPM), Microsoft Active Directory Certificate Services (Internal CA), and Thales KMS/HSM key lifecycles.
- Identity & Cloud Security: Working knowledge of Azure AD/Entry ID administration, conditional access implementation, and identity governance.
- SecOps & Tooling: Practical experience with Microsoft Defender, SIEM log-forwarding architecture, and Tenable vulnerability management.
- Governance & Soft Skills: Proven ability to manage stakeholders across Provider/Customer risk and audit functions while enforcing segregation-of-duties and personnel-vetting controls.
* Due to the sensitive nature of this project, only Singapore Citizens and Singapore Permanent Residents are eligible.