Search by job, company or skills

VP, Security Governance Lead

10-12 Years
  • Posted a day ago
  • Be among the first 10 applicants

Job Description

We are seeking an experienced cybersecurity leader to oversee the organisation's governance, risk, and assurance capabilities. This role is responsible for establishing and maintaining an effective cyber governance framework, ensuring security risks are appropriately managed, and driving continuous improvements across the enterprise security programme.

Reporting to the Chief Information Security Officer (CISO), you will lead the Governance, Risk & Compliance (GRC) function while partnering closely with technology, risk, audit, and business leaders to strengthen the organisation's overall cyber resilience.

This position combines strategic leadership with operational oversight and is well suited for someone who enjoys influencing enterprise-wide security initiatives in a highly regulated environment.

Key Responsibilities:

Governance & Security Frameworks

  • Develop and maintain enterprise cybersecurity governance, policies, standards, and control frameworks.
  • Ensure governance processes remain aligned with evolving regulatory obligations, business priorities, and industry best practices.
  • Review security policy exceptions and risk acceptance requests, providing appropriate recommendations and oversight.
  • Champion continuous improvement initiatives to enhance governance maturity across the organisation.

Cyber Risk & Assurance

  • Lead enterprise cybersecurity risk assessments to identify and evaluate technology and cyber risks.
  • Oversee security assurance activities, including vulnerability assessments, penetration testing, control reviews, and cyber resilience exercises.
  • Track remediation activities to ensure identified risks and control gaps are addressed in a timely manner.
  • Evaluate emerging cyber threats and technologies, recommending appropriate safeguards where necessary.

Audit & Regulatory Engagement

  • Act as the primary cybersecurity representative for internal and external audit engagements.
  • Coordinate responses to audit requests and oversee remediation programmes arising from audit findings.
  • Ensure appropriate governance processes exist to demonstrate compliance with applicable security and regulatory requirements.
  • Partner with internal stakeholders to improve the effectiveness of security controls and governance practices.

Leadership & Stakeholder Management

  • Lead and develop a high-performing Governance, Risk & Compliance team.
  • Foster a collaborative culture focused on accountability, continuous learning, and operational excellence.
  • Provide strategic guidance to technology and business stakeholders on cyber risk and governance matters.
  • Support executive leadership through regular reporting on cyber risks, control effectiveness, and programme maturity.

Performance & Reporting

  • Develop meaningful security metrics and key risk indicators to measure programme effectiveness.
  • Prepare reports and presentations for executive management, governance committees, and senior stakeholders.
  • Drive data-driven decision making through insightful analysis of cyber risks and control performance.

Requirements:

  • Degree in Information Security, Computer Science, Computer Engineering, or a related discipline.
  • At least 10 years of experience within cybersecurity governance, enterprise risk management, information security, or IT assurance.
  • Previous experience leading Governance, Risk & Compliance (GRC) functions or enterprise security governance teams.
  • Experience working within regulated industries or large, complex organisations is highly desirable.
  • Recent years of experience in leading a team.

Technical Expertise

  • Strong understanding of cybersecurity governance, enterprise risk management, and control frameworks.
  • Experience implementing or managing recognised standards such as ISO 27001, NIST CSF, COBIT, CIS Controls, or similar frameworks.
  • Good appreciation of cloud security, infrastructure security, secure software delivery practices, and modern enterprise technology environments.
  • Familiarity with audit methodologies, control assessments, and regulatory compliance programmes.

To apply:

If you're interested to apply or find out more, please share across your CV or reach out to Chen Yi at [Confidential Information] for a discussion. Due to anticipated high volume of applications, we regret to inform that only shortlisted candidates will be notified.

Reg: R1876389

Lic: 16S8060

More Info

Job Type:
Industry:
Function:
Employment Type:

About Company

Job ID: 152091135

Similar Jobs

Singapore

Skills:

it grc control testing technology risk risk registers Iso 27001Cismaudit readinessMAS TRMNIST CSFMAS Notice 658Cisatechnology auditRisk AssuranceCobitCisspremediation trackingcybersecurity governanceCRISC

Singapore

Skills:

it controls information security governance technology governance ServicenowJIRAIt OperationsCybersecurity OperationsIT RiskThird-party Technology GovernancePrivileged Access GovernanceTechnology Assurance

Singapore

Skills:

it grc control testing technology risk risk registers Iso 27001Cismaudit readinessMAS TRMNIST CSFMAS Notice 658Cisatechnology auditRisk AssuranceCobitremediation trackingCisspcybersecurity governanceCRISC

Singapore

Skills:

cloudIamData Governancesystem development processesgovernance and control frameworks

Singapore, Toa Payoh

Skills:

ItilMAS CCOP regulationsIndustry practicesGovernance risk managementCI CDDevSecOps methodologiesCybersecurity frameworksCyber and IT standardsHybrid cloud environmentsRegulatory and legal requirementsAudit executionPolicy review oversightCobitPayment Services ActArchitecture of secure scalable and resilient solutionsRisk management methodologiesEmerging security standards and solutions

Beware of Scammers

We don’t charge money for job offers