Search Jobs

Search by job, company or skills

VP, Security Governance Lead

VP, Security Governance Lead

Kerry Consulting
10-12 Years
  • Posted 17 hours ago
  • Be among the first 10 applicants

Job Description

We are seeking an experienced cybersecurity leader to oversee the organisation's governance, risk, and assurance capabilities. This role is responsible for establishing and maintaining an effective cyber governance framework, ensuring security risks are appropriately managed, and driving continuous improvements across the enterprise security programme.

Reporting to the Chief Information Security Officer (CISO), you will lead the Governance, Risk & Compliance (GRC) function while partnering closely with technology, risk, audit, and business leaders to strengthen the organisation's overall cyber resilience.

This position combines strategic leadership with operational oversight and is well suited for someone who enjoys influencing enterprise-wide security initiatives in a highly regulated environment.

Key Responsibilities:

Governance & Security Frameworks

  • Develop and maintain enterprise cybersecurity governance, policies, standards, and control frameworks.
  • Ensure governance processes remain aligned with evolving regulatory obligations, business priorities, and industry best practices.
  • Review security policy exceptions and risk acceptance requests, providing appropriate recommendations and oversight.
  • Champion continuous improvement initiatives to enhance governance maturity across the organisation.

Cyber Risk & Assurance

  • Lead enterprise cybersecurity risk assessments to identify and evaluate technology and cyber risks.
  • Oversee security assurance activities, including vulnerability assessments, penetration testing, control reviews, and cyber resilience exercises.
  • Track remediation activities to ensure identified risks and control gaps are addressed in a timely manner.
  • Evaluate emerging cyber threats and technologies, recommending appropriate safeguards where necessary.

Audit & Regulatory Engagement

  • Act as the primary cybersecurity representative for internal and external audit engagements.
  • Coordinate responses to audit requests and oversee remediation programmes arising from audit findings.
  • Ensure appropriate governance processes exist to demonstrate compliance with applicable security and regulatory requirements.
  • Partner with internal stakeholders to improve the effectiveness of security controls and governance practices.

Leadership & Stakeholder Management

  • Lead and develop a high-performing Governance, Risk & Compliance team.
  • Foster a collaborative culture focused on accountability, continuous learning, and operational excellence.
  • Provide strategic guidance to technology and business stakeholders on cyber risk and governance matters.
  • Support executive leadership through regular reporting on cyber risks, control effectiveness, and programme maturity.

Performance & Reporting

  • Develop meaningful security metrics and key risk indicators to measure programme effectiveness.
  • Prepare reports and presentations for executive management, governance committees, and senior stakeholders.
  • Drive data-driven decision making through insightful analysis of cyber risks and control performance.

Requirements:

  • Degree in Information Security, Computer Science, Computer Engineering, or a related discipline.
  • At least 10 years of experience within cybersecurity governance, enterprise risk management, information security, or IT assurance.
  • Previous experience leading Governance, Risk & Compliance (GRC) functions or enterprise security governance teams.
  • Experience working within regulated industries or large, complex organisations is highly desirable.
  • Recent years of experience in leading a team.

Technical Expertise

  • Strong understanding of cybersecurity governance, enterprise risk management, and control frameworks.
  • Experience implementing or managing recognised standards such as ISO 27001, NIST CSF, COBIT, CIS Controls, or similar frameworks.
  • Good appreciation of cloud security, infrastructure security, secure software delivery practices, and modern enterprise technology environments.
  • Familiarity with audit methodologies, control assessments, and regulatory compliance programmes.

To apply:

If you're interested to apply or find out more, please share across your CV or reach out to Chen Yi at [Confidential Information] for a discussion. Due to anticipated high volume of applications, we regret to inform that only shortlisted candidates will be notified.

Reg: R1876389

Lic: 16S8060

More Info

Job Type:
Industry:
Employment Type:

Key Skills

secure software delivery practices

cyber resilience exercises

control assessments

NIST CSF

CIS Controls

control frameworks

audit methodologies

regulatory compliance programmes

cybersecurity governance

About Company

Similar Jobs

6-10 yrs
Singapore
Skills:
Regulatory Compliance, Data analytics tools and techniques, QA monitoring and control testing frameworks
10-12 yrs
Singapore
Skills:
data engineering , Java, Apache Spark, Networking, Sql, Google Cloud, Iam, Python, Capacity Management, GenAI, subnet design, inference cost optimisation, agent orchestration frameworks, containerisation, private connectivity, observability stacks, LLM-based platforms, role-based access design, DNS routing, caching approaches, GCP security
10-12 yrs
Singapore, Toa Payoh
Skills:
Itil, MAS CCOP regulations, Industry practices, Governance risk management, DevSecOps methodologies, Cybersecurity frameworks, Hybrid cloud environments, Cyber and IT standards, Regulatory and legal requirements, Audit execution, Policy review oversight, Cobit, Emerging security standards, Payment Services Act, Risk management methodologies, Architecture of secure scalable and resilient solutions
10-13 yrs
SGD 10,400 - 18,700 per month
Singapore
Skills:
data engineering , Java, Capacity Management, Networking, Apache Spark, Google Cloud, Sql, Iam, Python, Inference cost optimisation, GenAI, Subnet design, Consumption modelling, Containerisation, Agent orchestration frameworks, Caching strategies, Observability stacks, LLM-based platforms, DNS routing, GCP security, Private connectivity
10-12 yrs
Singapore
Skills:
Avaloq, Automation, Bloomberg OMS, Agile Delivery, FinIQ, Regulatory change programmes, Operational resilience, Audit engagement, Process Improvements, Regulatory Compliance, Trade Execution, Platform enhancements, Target operating model design, Risk and controls, Pricing and valuation governance, Product governance