Lead IT Security Grc

7 days ago


Singapore GLOBALFOUNDRIES Full time

**Lead IT Security GRC
**Job Summary**:
Document, monitor and improve the effectiveness of IT operating controls, risk management, and governance processes for Information Security. Participate in or lead audits from external regulators and internal functions including tracking deliverables, tasks, and corrective actions; perform assessments to identify continuous improvements; ensure compliance with regulations, company policies and IT controls; coordinate the audit processes including preparing, hosting, and then reviewing, analyzing, and reporting findings internally; track remediation to ensure follow up until closure; and compile and report on regional IS compliance-related KPIs.

**Specific Responsibilities Include**:

- Define, plan and manage Information Security assessments and activities across APAC sites
- Ensure compliance with regulatory requirements and internal policies, and report on compliance gaps and design and lead remediation plans to address identified gaps
- Ensure successful internal and external audits and certifications for IT
- Act as single point of contact and prepare for audit by researching materials, formulating a plan of action, and identifying and preparing SMEs and evidence.
- Support external auditors by coordinating information requirements.
- Ensure compliance with regulations and controls by examining and analyzing records, reports, operating practices, and documentation; recommend opportunities to strengthen internal control structure and compliance
- Evaluate new products and services to determine compliance with laws and regulations by which GlobalFoundries must abide and best practices
- Perform and document security assessments by documenting evaluation methods and findings, for example, system security plans with plan of action and milestones.
- Communicate assessment progress and findings by preparing presentations, facilitating meetings, and providing information through various means.
- Develop, review and revise IT policies, procedures, and standards
- Help lead IT risk assessment and treatment program, including identification of risks and ensuring implementation of mitigating controls and mapping to authoritative sources and projects
- Enhance Information Security compliance department and organization reputation by accepting ownership for accomplishing new and different requests and projects and exploring opportunities to add value to the team
- Assist in globalization and alignment of Information Security compliance

**Required Qualifications**:

- Experience leading / working with ISO 27001 audits and programs
- Experience leading / working with NIST frameworks and special publications
- Minimum 5 years’ experience in one or more of the relevant disciplines: IT, Information Security, Operational Audit, Compliance
- Bachelor’s Degree in Computer Science, Information Systems, Information Security, or equivalent experience

**Preferred Qualifications**:

- IIA/CISA certified
- Certifications in COBIT, ISO, and other pertinent professional certifications in computer technology, auditing, compliance or related areas
- Certification or experience in project management
- Prior experience with SOX, GDPR
- Experience working with Risk Management
- Attention to detail
- Team player
- Strong ability to drive execution and meet strict deadlines
- Results Oriented
- Ability to communicate effectively with all levels of personnel
- Accountability
- Analytical Thinking
- Continuous Process Improvement
- Problem Solving
- Technical Expertise, e.g. COBIT
- Working knowledge of ServiceNow

GLOBALFOUNDRIES is an equal opportunity employer, cultivating a diverse and inclusive workforce. We believe having a multicultural workplace enhances productivity, efficiency and innovation whilst our employees feel truly respected, valued and heard.

As an affirmative employer, all qualified applicants are considered for employment regardless of age, ethnicity, marital status, citizenship, race, religion, political affiliation, gender, sexual orientation and medical and/or physical abilities.


  • Lead, Security Grc

    2 weeks ago


    Singapore COINBASE SINGAPORE PTE. LTD. Full time

    **GRC Security at Coinbase Coinbase stores more digital currency than any company in the world, making us a prime target on the internet. Security is core to our mission and has been a key competitive differentiator for us as we scale worldwide. Crucial to scaling is building and running a security compliance program that reflects how we protect the data and...

  • SAP Grc Lead

    2 weeks ago


    Singapore Blue Ocean Systems Infotech Pte Ltd Full time

    Hi, Urgent opening for SAP GRC Lead Evaluate & integrate SAP Fiori apps into SAP GRC Perform outside research to develop expertise in SAP GRC security functionality and industry best practices within the SAP GRC, the IT risk management and compliance space Provide technical leadership in the assessment, design, and implementation of SAP GRC security and...

  • SAP Grc Lead

    2 weeks ago


    Singapore BLUE OCEAN SYSTEMS INFOTECH PTE. LTD. Full time

    Hi Urgent opening for SAP GRC Lead Evaluate & integrate SAP Fiori apps into SAP GRC Perform outside research to develop expertise in SAP GRC security functionality and industry best practices within the SAP GRC, the IT risk management and compliance space Provide technical leadership in the assessment, design, and implementation of SAP GRC security and...

  • Grc

    2 weeks ago


    Singapore Good Job Creations Pte Ltd Full time

    1. Job Brief 1. Reporting - Head of Security **Responsibilities**: - Develop IT GRC management framework and processes that gel with Security Strategy. - Develop and maintain Security Policy. - Ensuring that requirements in IT Audit, Standard, Policy, Compliance and Risk controls are met. - Responsible for the maintaining the Risk Registries. - Define...

  • Grc

    1 week ago


    Singapore Good Job Creations Pte Ltd Full time

    1. Job Brief 1. Reporting - Head of Security **Responsibilities**: - Develop IT GRC management framework and processes that gel with Security Strategy. - Develop and maintain Security Policy. - Ensuring that requirements in IT Audit, Standard, Policy, Compliance and Risk controls are met. - Responsible for the maintaining the Risk Registries. - Define...


  • Singapore AMSERS CONSULTING PTE. LTD. Full time

    **About the Role**: We are seeking a detail-oriented and proactive **IT Security GRC (Governance, Risk, and Compliance) Analyst**with a minimum of **4 years of relevant experience**to support and enhance our cybersecurity risk and compliance programs. This role will help ensure that the organization’s information security practices align with regulatory...

  • Security Grc Analyst

    2 weeks ago


    Singapore Databricks Full time

    As a leader on the Security Assurance Team, you will be responsible for implementing and managing the Databricks GRC solution, and assisting with Databricks security compliance projects. You will report to Manager, Security Compliance. **The impact you will have**: - Design, implement, manage, and maintain the Databricks GRC tool solution. - Support OKRs...


  • Singapore NCS Full time

    **IT Security Practice Manager (GRC)**: **Date**:13 Nov 2024 **Location**: Singapore, Singapore **Company**:Singtel Group NCS is a leading technology services firm that operates across the Asia Pacific region in over 20 cities, providing consulting, digital services, technology solutions, and more. We believe in harnessing the power of technology to...


  • Singapore Randstad Singapore Full time

    Information Security GRC Senior Analyst | APAC Join to apply for the Information Security GRC Senior Analyst | APAC role at Randstad Singapore . This is a full-time, mid-senior level position within the Information Technology industry, focusing on cybersecurity, governance, risk management, and compliance (GRC). Responsibilities Develop, implement, and...


  • Singapore Hays Full time

    Senior Cyber Security Specialist (GRC) Hays Technology is looking for a Senior Cyber Security Specialist (GRC) to help our client to provide Governance, Risk, and Compliance expertise and to conduct security assessments to ensure information assets are secured. - Conducting security control assessments, threat and vulnerability assessments, risk and reward...