Search Jobs

Search by job, company or skills

VP, Cybersecurity Governance

VP, Cybersecurity Governance

Kerry Consulting
10-12 Years
  • Posted an hour ago
  • Be among the first 10 applicants

Job Description

We are seeking an experienced cybersecurity leader to oversee the organisation's governance, risk, and assurance capabilities. This role is responsible for establishing and maintaining an effective cyber governance framework, ensuring security risks are appropriately managed, and driving continuous improvements across the enterprise security programme.

Reporting to the Chief Information Security Officer (CISO), you will lead the Governance, Risk & Compliance (GRC) function while partnering closely with technology, risk, audit, and business leaders to strengthen the organisation's overall cyber resilience.

This position combines strategic leadership with operational oversight and is well suited for someone who enjoys influencing enterprise-wide security initiatives in a highly regulated environment.

Key Responsibilities:

Governance & Security Frameworks

  • Develop and maintain enterprise cybersecurity governance, policies, standards, and control frameworks.
  • Ensure governance processes remain aligned with evolving regulatory obligations, business priorities, and industry best practices.
  • Review security policy exceptions and risk acceptance requests, providing appropriate recommendations and oversight.
  • Champion continuous improvement initiatives to enhance governance maturity across the organisation.

Cyber Risk & Assurance

  • Lead enterprise cybersecurity risk assessments to identify and evaluate technology and cyber risks.
  • Oversee security assurance activities, including vulnerability assessments, penetration testing, control reviews, and cyber resilience exercises.
  • Track remediation activities to ensure identified risks and control gaps are addressed in a timely manner.
  • Evaluate emerging cyber threats and technologies, recommending appropriate safeguards where necessary.

Audit & Regulatory Engagement

  • Act as the primary cybersecurity representative for internal and external audit engagements.
  • Coordinate responses to audit requests and oversee remediation programmes arising from audit findings.
  • Ensure appropriate governance processes exist to demonstrate compliance with applicable security and regulatory requirements.
  • Partner with internal stakeholders to improve the effectiveness of security controls and governance practices.

Leadership & Stakeholder Management

  • Lead and develop a high-performing Governance, Risk & Compliance team.
  • Foster a collaborative culture focused on accountability, continuous learning, and operational excellence.
  • Provide strategic guidance to technology and business stakeholders on cyber risk and governance matters.
  • Support executive leadership through regular reporting on cyber risks, control effectiveness, and programme maturity.

Performance & Reporting

  • Develop meaningful security metrics and key risk indicators to measure programme effectiveness.
  • Prepare reports and presentations for executive management, governance committees, and senior stakeholders.
  • Drive data-driven decision making through insightful analysis of cyber risks and control performance.

Requirements:

  • Degree in Information Security, Computer Science, Computer Engineering, or a related discipline.
  • At least 10 years of experience within cybersecurity governance, enterprise risk management, information security, or IT assurance.
  • Previous experience leading Governance, Risk & Compliance (GRC) functions or enterprise security governance teams.
  • Experience working within regulated industries or large, complex organisations is highly desirable.
  • Recent years of experience in leading a team.

Technical Expertise

  • Strong understanding of cybersecurity governance, enterprise risk management, and control frameworks.
  • Experience implementing or managing recognised standards such as ISO 27001, NIST CSF, COBIT, CIS Controls, or similar frameworks.
  • Good appreciation of cloud security, infrastructure security, secure software delivery practices, and modern enterprise technology environments.
  • Familiarity with audit methodologies, control assessments, and regulatory compliance programmes.

To apply:

If you're interested to apply or find out more, please share across your CV or reach out to Chen Yi at [Confidential Information] for a discussion. Due to anticipated high volume of applications, we regret to inform that only shortlisted candidates will be notified.

Reg: R1876389

Lic: 16S8060

More Info

Job Type:
Industry:
Function:
Employment Type:

Key Skills

secure software delivery practices

cyber resilience exercises

control assessments

NIST CSF

CIS Controls

control frameworks

audit methodologies

regulatory compliance programmes

cybersecurity governance

About Company

Similar Jobs

8-12 yrs
Singapore
Skills:
Aml, Adverse media reviews, Beneficial ownership analysis, CDD, Correspondent banking due diligence, KYC platforms, Management Reporting, ICA Diploma, MAS Notice 626, Regulatory Compliance, AML Risk Assessment, ACAMS, Financial Crime Compliance, Kyc, Digitization initiatives, Customer Risk Rating methodologies, Advanced Certificate CAMS-Audit
10-12 yrs
Singapore
Skills:
technology risk , Pci Dss, Iso 27001, Committee governance, Customer risk assessments, Due Diligence, Operational resilience, Operational Risk, Enterprise Risk Management framework, External assurance activities, Contingency Planning, SOC 2, Business continuity, Cyber risk, Second-line oversight, Third-party risk, Risk appetite policies, Enterprise risk frameworks, Non-Financial risk
8-10 yrs
Singapore
Skills:
telemetry , Scripting, Microsoft Intune, Application Deployment, PowerShell, Group Policy, Automation, Microsoft 365, Azure Ad, Entra ID, EUC endpoint engineering, Endpoint security baselines, Vulnerability remediation, Device compliance, Secure configuration management, Identity-driven access, conditional access, Microsoft Graph APIs, Compliance Reporting, Attack-surface reduction, Configuration-as-code, Active Directory, Security Monitoring, Application control, Control metrics, Modern workplace infrastructure, Security dashboards, Configuration-assurance automation, Device control
12-14 yrs
Singapore
Skills:
Ccsp, Data Protection, cloud, Digital Transformation, risk management, Emerging Technologies, Generative AI, adversarial threats, AI supply-chain risk, Cisa, technology risk governance, third-party risk, CDPSE, Security Architecture, Cissp, cybersecurity governance, AI security, cgeit, assurance frameworks, CRISC, Large Language Models
10-12 yrs
Singapore
Skills:
threat modeling , Cloud Security, Oscp, Cism, Cybersecurity GRC, Threat TTPs, Security Architecture, Third-party Vendor and Software Supply Chain Risk Management, Zero Trust Architecture, Information Security Risk Management, Security Policies, OT ICS Security Environments, OSWE, Security-by-design principles, Security Control Frameworks, Cissp, International Security Standards, CRISC