Governance, Risk and Compliance Specialist

About the job

About the Governance, Risk and Compliance Specialist role

We’re looking for a Governance, Risk and Compliance Specialist. They will be assigned to the Client’s Cybersecurity (CySD) Divisions Security Governance & Compliance (SGC) team. There, the GRC Specialist will be a subject matter expert advising internal stakeholders on cybersecurity compliance requirements, working closely with Infrastructure, Application, Line 2 and Auditors.

The scope of work includes:

  • Develop and maintain internal cybersecurity policies and processes
  • Ascertain security compliance with regulatory, and internal policies and processes
  • Support IT / cyber security audits
  • Tracking and reporting cyber risks.

Key Responsibilities:

  • Develop the culture of cybersecurity governance, compliance and risk management across the Organisation, and ensure proper accountability in the management, tracking and reporting of cyber risks
  • Provide subject matter advice to internal stakeholders on cyber security requirements that the Authority is required to comply with, including MAS internal policies and standards, as well as policies and standards from GovTech and Cyber Security Agency of Singapore
  • Develop, review, establish and communicate ICT policies and processes controls, and conduct compliance checks
  • Support the CIO and CISO, and work with internal stakeholders to
    • Track and monitor cyber security initiatives to meet compliance requirements
    • Participate in consultation and conduct gap analysis against new requirements
    • Assess and seek waiver approvals for deviations and dispensations
    • Coordinate and facilitate IT / cyber security audits
  • Track remediation plans to address audit findings

Requirements:

  • Working experience in IT Governance, IT Audit, Cyber security or related field
  • Working experience with Singapore Public Sector and knowledge of Instruction Manual 8 and CSA Cybersecurity Code of Practice
  • Relevant certifications in IT governance, IT audit, cyber or data security (e.g. CISSP, CISM, CISA, CGEIT, etc.)
  • Ability to work with cross-functional, multi-disciplined teams to institute and monitor security policies and procedures
  • Knowledge of Instruction Manual 8 and CSA Cybersecurity Code of Practice preferred