IT Security Analyst, Governance, Risk and Compliance

2 weeks ago


Singapore NTU (Nanyang Technology University- Main Office-HR) Full time
ABOUT THE NATIONAL INSTITUTE OF EDUCATION (NIE)

The National Institute of Education (NIE), Singapore, is Singapore's national teacher education institute and we are proud to be an integral part of the nation's education service. We play a key role in the preparation of teachers and in the provision of teacher professional and school leadership development programmes. We are committed to our vision of being An Institute of Distinction: Leading the Future of Education and our mission to Inspire Learning, Transform Teaching and Advance Research. Read more about NIE here.

NIE invites suitable candidates to join the Division of Academic Computing & Information Services (ACIS) as a Security Analyst for Governance, Risk, and Compliance (GRC). This is a 3-year contract position.

Key Responsibilities:

Governance
  • Coordinate with internal and external audit teams and assist in audit planning.
  • Help deliver security awareness programs for staff and manage security governance efforts.
  • Stay updated on IT trends and recommend best practices to align with governance policies.
  • Support cybersecurity projects to ensure alignment with security objectives.


Risk Management
  • Assist in identifying and assessing IT risks and managing vulnerabilities and threats.
  • Support risk management in cybersecurity projects by focusing on threats and vulnerabilities.
  • Track and monitor audit remediation actions related to risk management.
  • Measure the effectiveness of security awareness programs to minimize risks from human error.


Compliance
  • Ensure compliance with internal standards (ISO 27001, ISO 22301) and external regulations.
  • Facilitate responses to internal and external IT audits.
  • Participate in audit engagements and report on audit issues and remediation.
  • Provide ongoing compliance reporting to ensure timely remediation of audit findings.


Requirements:

Educational Qualification(s)
  • A University Degree in Information Technology, Cybersecurity, Risk Management, or Compliance, or an equivalent qualification.
  • Desirable Certifications: CISSP, CISM, CISA, CRISC, or other relevant certifications.


Relevant Experience
  • 3-5 years of experience in Information Security, IT Risk Management, or Compliance, preferably in a higher education or similar environment.
  • Experience with IT security audits and compliance reviews in regulated industries.
  • Experience with vendor security assessments and managing third-party security risks.
  • Experience in security awareness training and working in cross-functional teams.


Knowledge Required
  • Security Frameworks: ISO 27001, CTM, NIST, CIS controls, and their application in operational environments.
  • Regulatory Standards: Understanding of the Cybersecurity Bill, PDPA, and related security laws.
  • Risk Management: Knowledge of risk assessments, mitigation strategies, and identifying threats to information systems.
  • Audit Processes: Understanding security audit processes, compliance, and remediation.
  • IT System: Good knowledge of IT infrastructure, application management, and cybersecurity practices.
  • GRC Tools: Experience with Governance, Risk, and Compliance platforms and software is advantageous.


Skills and Competencies
  • Analytical Skills: Ability to analyze security risks and make data-driven decisions.
  • Communication Skills: Ability to convey technical security concepts to non-technical audiences and document findings.
  • Problem-Solving: Strong problem-solving capabilities, particularly during security incidents.
  • Attention to Detail: High focus on detail in audits and risk assessments.
  • Project Management: Ability to manage multiple projects, prioritize tasks, and meet deadlines.
  • Team Collaboration: Proven ability to work with cross-functional teams (IT, legal, compliance, vendors).


Other Personal Attributes
  • Integrity and Confidentiality: High ethical standards and the ability to handle sensitive information.
  • Proactivity: Ability to act independently and proactively address security challenges.
  • Adaptability: Capable of adjusting to evolving security threats and changes in regulations.
  • Resilience under Pressure: Ability to make sound decisions under pressure, particularly during audits or security incidents.


Closing Date
The closing date of the advertisement is 3 December 2024. We regret that only shortlisted candidates will be notified.

Other Information

NIE staff can take chartered buses at their own expense from or near their home to the NIE campus. This is subject to the availability of bus routes and seats.

Hiring Institution: NIE

  • Singapore NTU (Nanyang Technology University- MainOffice-HR) Full time

    Job Summary:The National Institute of Education (NIE) is seeking an experienced IT Security Analyst to join its Division of Academic Computing & Information Services (ACIS) as a Security Analyst for Governance, Risk, and Compliance (GRC). This is a 3-year contract position.About the Job:In this role, you will be responsible for coordinating with internal and...


  • Singapore MDIS Pte Ltd Full time

    ABOUT THE NATIONAL INSTITUTE OF EDUCATION (NIE) The National Institute of Education (NIE), Singapore , is Singapore’s national teacher education institute and we are proud to be an integral part of the nation’s education service. We play a key role in the preparation of teachers and in the provision of teacher professional and school leadership...


  • Singapore NANYANG TECHNOLOGICAL UNIVERSITY Full time

    Roles & ResponsibilitiesABOUT THE NATIONAL INSTITUTE OF EDUCATION (NIE)The National Institute of Education (NIE), Singapore, is Singapore’s national teacher education institute and we are proud to be an integral part of the nation’s education service. We play a key role in the preparation of teachers and in the provision of teacher professional and...


  • Singapore NTU (Nanyang Technology University- Main Office-HR) Full time

    ABOUT THE NATIONAL INSTITUTE OF EDUCATION (NIE)The National Institute of Education (NIE), Singapore, is Singapore's national teacher education institute and we are proud to be an integral part of the nation's education service. We play a key role in the preparation of teachers and in the provision of teacher professional and school leadership development...


  • Singapore TECH AALTO PTE. LTD. Full time

    Roles & ResponsibilitiesJob Title: Governance, Risk and Compliance SpecialistPosition Type:ContractJob Description:We are looking for experienced Governance, Risk, and Compliance (GRC) Specialists to join our team. This role is focused on enhancing and operationalizing security policies, conducting risk assessments, and managing compliance with cybersecurity...


  • Singapore United Overseas Bank Full time

    About the RoleWe are seeking a skilled Risk Governance and Compliance Analyst to join our team in Singapore.Job SummaryThe successful candidate will be responsible for developing a tool using MS Access and VBA to support monitoring of policy change, test program, credit portfolio management, including tracking of risk appetite metrics for overall PFS...


  • Singapore USER EXPERIENCE RESEARCHERS PTE. LTD. Full time

    Roles & ResponsibilitiesJob SummaryAs a Governance Risk and Compliance Specialist to join our team, this role is crucial in developing and maintaining a robust culture of technology and cybersecurity risk governance across our organization.The ideal candidate will have at least 5 years of relevant experience in ICT cybersecurity, data security, audit...


  • Singapore NTU (Nanyang Technology University- MainOffice-HR) Full time

    ABOUT THE NATIONAL INSTITUTE OF EDUCATION(NIE)The National Instituteof Education (NIE), Singapore, is Singapore's nationalteacher education institute and we are proud to be an integral partof the nation's education service. We play a key role in thepreparation of teachers and in the provision of teacherprofessional and school leadership development...


  • Singapore INFINITE COMPUTER SOLUTIONS PTE LTD Full time

    Roles & ResponsibilitiesKey Responsibilities Develop the culture of Tech risk governance and management across the organisation, and ensure proper accountability in the management, tracking and reporting of tech and cyber risks. Provide subject matter advice to internal stakeholders on cyber security requirements that the Authority is required to comply...


  • Singapore Marina Bay Sands Full time

    About the RoleWe are seeking a highly skilled Cybersecurity Governance Risk Analyst to join our team at Marina Bay Sands. As a key member of our cybersecurity team, you will play a crucial role in ensuring the security and integrity of our systems and data.Our ideal candidate will have a strong background in cybersecurity, with experience in vulnerability...


  • Singapore JOBSTER PRIVATE LTD. Full time

    Job DescriptionWe are seeking a highly skilled Cyber Security Specialist to join our team at JOBSTER PRIVATE LTD. in Singapore. This is a challenging role that requires strong technical knowledge, excellent analytical skills, and the ability to work independently.Key Responsibilities:Develop and implement a culture of tech risk governance and management...


  • Singapore Unison Consulting Pte Ltd Full time

    As a Governance Risk and Compliance Specialist to join our team, this role is crucial in developing and maintaining a robust culture of technology and cybersecurity risk governance across our organization. The ideal candidate will have at least 5 years of relevant experience in ICT cybersecurity, data security, audit management, governance, and risk...


  • Singapore This Is An IT Support Group Full time

    Reporting to the CEO, the Compliance and Risk Manager supports DPH in the areas of corporate governance, Governing Council and its Executive Committee, enterprise risk and strategic planning including business continuity. Responsiblities 1. Secretariat to the Audit, Risk and Governance Committee (ARGC) in order to operate processes for governance and...


  • Singapore KPMG SERVICES PTE. LTD. Full time

    Roles & ResponsibilitiesThe Information Technology Services is dedicated to creating and delivering value to our business by leveraging on IT technology. The team is responsible for delivering customer-focused solutions and high-quality IT services internally to enable our business.We invite a highly motivated & dynamic professional to join our ITS team as a...


  • Singapore Citi Full time

    About the RoleAt Citi, we're looking for a highly skilled Compliance Surveillance Sr Analyst to join our team. As a key member of our Global Legal Affairs and Compliance department, you'll play a critical role in empowering and protecting Citi by providing legal, compliance, investigative, and security services to our firm.Key ResponsibilitiesRegulatory...


  • Singapore Unison Consulting Pte Ltd Full time

    Cybersecurity Risk Governance SpecialistUnison Consulting Pte Ltd is seeking a seasoned Cybersecurity Risk Governance Specialist to develop and maintain a robust culture of technology and cybersecurity risk governance across the organization.The ideal candidate will have at least 5 years of relevant experience in ICT cybersecurity, data security, audit...


  • Singapore PERSOLKELLY SINGAPORE PTE. LTD. Full time

    Roles & ResponsibilitiesThe successful candidate will support the development and implementation of a comprehensive compliance and governance framework to ensure ongoing adherence to relevant IT legislative and regulatory requirements (e.g., PDPA, MAS TRM, PCI). They will report regularly to IT Management on compliance status and engage with various teams to...


  • Singapore Careers@Gov Full time

    About Us:Careers@Gov is a leading organization that values innovation, teamwork, and security. We are dedicated to providing top-notch services to the community.Job Overview:We are seeking an experienced IT Governance and Security Leader to join our team. This role will be responsible for managing day-to-day operations, monitoring systems, and reporting on...


  • Singapore Citi Full time

    Job SummaryWe are seeking a highly skilled Compliance Risk Analyst Senior to join our team in Singapore. This role will be responsible for timely and accurate responses to regulatory inquiries issued by regulators across the Asia North and South clusters.About the RoleThe senior compliance risk analyst will work closely with partners across the first and...


  • Singapore Marina Bay Sands Full time

    Job SummaryThe primary objective of this role is to perform duties in one or more of the following areas: vulnerability management, cyber data governance, risk and verification, cyber policy/standards/standard operating procedures development, and penetration testing and red teaming.All duties are to be performed in accordance with departmental and Marina...