Position Overview:
We are seeking an experienced Senior Consultant to lead end-to-end cybersecurity governance, risk, and compliance engagements across ISO 27001, Cyber Trust Mark, and Cyber Essentials Mark frameworks. The role combines hands-on consultancy delivery, independent audit work, awareness training and tabletop exercise facilitation, with full ownership of client engagements from scoping through to closure.
Key Responsibilities:
- Lead and deliver ISO 27001, Cyber Trust Mark and Cyber Essentials end-to-end engagements, from gap analysis and risk assessment through documentation, controls implementation, and readiness.
- Develop and customise information security management frameworks and policies, and deliver advisory and awareness sessions across all client audience levels.
- Design, facilitate, and report on tabletop exercises covering different type of scenarios, including scenario development, exercise control, and after-action reporting.
- Conduct ISO 27001 and Cyber Trust Mark internal audits, and other similar audit engagements.
- Stay current on cybersecurity frameworks, regulations, and threat landscape relevant to the Singapore market, and contribute to internal methodology, tools, and template development.
Job Requirements:
- Diploma or Bachelor's degree in Information Technology, Computer Science, or a related field.
- 3 to 5 years of relevant experience in cybersecurity GRC consultancy.
- Hands-on experience across ISO 27001, CSA Cyber Trust Mark, or Cyber Essentials Mark implementation and audit engagements.
- Ability to develop and review security policies, procedures, and governance documentation.
- Foundational knowledge of information systems, cloud infrastructure, operating systems, and networking.
- Strong analytical, documentation, and report-writing skills with attention to detail.
- Effective interpersonal and communication skills, with the ability to facilitate confidently across operational and executive stakeholders.
- Able to run engagements independently with minimal supervision and multitask across concurrent priorities.
- Proactive and adaptable mindset, with a willingness to learn, adopt new tools and systems, and take on new challenges.
Preferred Qualifications
- Relevant professional certifications, such as ISO 27001 Lead Implementer / Lead Auditor, CISA, CISSP, CISM, or CRISC.
- Prior consulting or professional services experience.