Information Security Risk

2 weeks ago


Singapore Zurich Insurance Full time

A great opportunity exists as APAC Information Security Risk & Compliance Consultant, reporting to APAC Information Security Risk & Compliance Lead.

The APAC Information Security Risk & Compliance Consultant collaborates with compliance, security, and general IT risks to ensure that IT supports the business objectives of the group, while enforcing policy, standards, and ensuring project implementations are consistent with local, regional, and global strategy. As part of the APAC Information Security team, will collaborate closely with other team members in providing support to APAC Business Units in the risk identification, assessment, and advice to the various stakeholders.

**Key responsibilities**:
- Support APAC Business Information Security Officers (BISOs) in performing the following assessments using the global standard risk-based approach:
- Cloud security assessments-
- Third party vendor assessments-
- Business / IT Application assessments (incl. pre & post implementation reviews)-
- Regulatory assessments (local regulations, ISO27001, PCI DSS, SOC2 etc.)-
- Remediation action review, analysis, and management-
- Themed security reviews-
- Maintain Information Security, Risk and Compliance frameworks, policies, and standards for the APAC region.- Provide governance over, and support BISOs in the coordination of, regional and local information security gap remediation.- Perform analysis to identify common themes and drive regional remediation activities.- Advise APAC Business Information Security Officers (BISOs) and stakeholders in information security policy compliance requirements.- Provide advice, governance and support in information security policy exception and risk acceptance processes.- Work closely with the Information Security Governance (ISG) team in Global Information Security (GIS) to ensure global requirements are communicated to APAC stakeholders, and APAC requirements are considered in global Information security compliance projects.- Drive or support global information security governance initiatives in the APAC region.- Ensure the wellbeing of team members and proactively work to identify and manage workplace exposures which may precipitate workplace stress, bullying, harassment, and discrimination.

**Experience / Qualification Required**:
- University degree (primarily in computer science or comparable technical education),- Minimum 5 years professional experience in Information Security related fields and/ or IT Risk Management- One or more of the following information security related certifications is desirable: CISA, CRISC, CISSP and/or CISM.- PCI ISA and/or ISO27001 experience / certification is a plus.- Ability to operate using highly developed consulting and influencing skills, and able to communicate security-related concepts to a broad range of technical and non-technical staff.- Strong risk management and information security skills.- Big4 information security consulting and/or IT audit experience is a plus.- Insurance industry understanding would be highly beneficial.

**Knowledge**:
- Good working understanding of IT security, architectures, and compliance controls-
- Effective communication, presentation, and relationship management skills at different levels in a multicultural environment- Excellent co-ordination and time management skills for hands on assessment management- Strong report writing skills.- Eye for detail and inquisitive nature- Strong integrity and highly ethical- Innovative ability to contribute to development of processes.- Ethic of continuous improvement in their role- Effective in influencing and persuasion.- Understanding and experience in PowerBI is preferable.- Proficient in English (written and spoken). Cantonese is a plus.

If you’re interested in being part of our adventure that will build a brighter future together, and feel a sense of togetherness, then we look forward to you starting your adventure with us

**Why Zurich**

At Zurich, we like to think outside the box and challenge the status quo. We take an optimistic approach by focusing on the positives and constantly asking What can go right?

We are an equal opportunity employer who knows that each employee is unique - that’s what makes our team so great

Join us as we constantly explore new ways to protect our customers and the planet.
- Location(s): SG - Singapore
- Remote working:

- Schedule: Full Time
- Recruiter name: Ahona Adhikary
- Closing date:



  • Singapore SECURITY & RISK SOLUTIONS PTE. LTD. Full time

    **About the Position (Based in Singapore)** The APAC Security Operations and Risk Manager reports to the Regional Security Operations, Risk, and Crisis Manager and is responsible for implementing key regional security projects. This position involves extensive risk analysis, development of strategic directions, and implementation of new initiatives to...


  • Singapore SECURITY & RISK SOLUTIONS PTE. LTD. Full time

    **Responsibilities** - Manning the 24/7 Regional Security Services Centre (RSCC) in Hong Kong. - Be the focal point for coordinating response to security incidents / crisis events which may expose the Bank's staff, business, reputation and / or facilities to risk. - Monitoring, collation and analyzing security information obtained through specified public...


  • Singapore ERGO Insurance Pte. Ltd. Full time

    **Information Security Risk Officer** ERGO Insurance Pte. Ltd. is a registered general insurer regulated by the Monetary Authority of Singapore. We are a wholly owned Singapore subsidiary of ERGO Group AG, one of the major insurance groups in Germany and Europe, and we are the primary insurance arm of Munich Re, one of the leading reinsurers and risk...


  • Singapore ERGO Insurance Pte. Ltd. Full time

    ERGO Insurance Pte. Ltd. is a registered general insurer regulated by the Monetary Authority of Singapore. We are a wholly owned Singapore subsidiary of ERGO Group AG, one of the major insurance groups in Germany and Europe, and we are the primary insurance arm of Munich Re, one of the leading reinsurers and risk carriers worldwide. We want to become a...


  • Singapore LICO RESOURCES PTE. LTD. Full time

    Lico Resources, the specialist executive search firm, is partnering with a leading financial institution in searching for an Information Technology Risk Management Professional. The institution is a key player in the finance sector and is dedicated to fostering a secure and technologically advanced environment for its clients. they are seeking a dynamic...


  • Singapore INTEGRATED HEALTH INFORMATION SYSTEMS PTE. LTD. Full time

    **Role and Responsibilities** 1. Provide guidance to Business Services Group in ensuring that projects/systems comply with security policies and the relevant legal and regulatory frameworks (such as PDPA or Cybersecurity Act) throughout the product lifecycle 2. Perform adequate risk management, including identification, assessment and provide treatment of...


  • Singapore FCM Full time

    **Job no**: 511715 **Brand**: FCM **Work type**: Full time **Location**: Singapore **Categories**: Information & Technology **The GRC Security Analyst Singapore** will plan and implement policies, procedures, standards, and controls to govern the protection of the company’s information systems, networks, and data. The GRC security analyst will stay up to...


  • Singapore Military Security Department Full time

    **What the role is** - You will be part of a team that conducts audits and evaluates risk-handling of MINDEF/ SAF’S information. **What you will be working on** - You will be part of a team to formulate and review risk assessment frameworks and indicators; conduct security risk assessments of industries and qualify industries and facilities to handle...


  • Singapore SMART INFORMATION MANAGEMENT SYSTEMS PRIVATE LIMITED Full time

    **Key Responsibilities**: **Cybersecurity Risk Assessment & Mitigation**: - **Cyber Risk Assessment**:Conduct comprehensive cyber risk assessments in support of technology initiatives, identifying IT-related risks and recommending appropriate security controls to mitigate those risks. - **Risk Monitoring & Management**:Continuously track and manage risk...


  • Singapore RYSENSE LTD. Full time

    About RySense LTDRySense is a research-driven organisation that seeks to understand the needs and aspirations of Singaporeans. We pride ourselves on delivering quality data and in-depth insights that empower decision-making and shape a better Singapore.We are committed to robust methodologies, timely information, and incisive recommendations that distinguish...


  • Singapore DEUTSCHE BANK AKTIENGESELLSCHAFT Full time

    Key ResponsibilitiesManage IT Security Risks: Identify, assess, and mitigate information security risks associated with our IT assets, infrastructure, and applications.Develop and Implement Controls: Design, implement, and maintain effective information security controls to prevent data breaches and cyber attacks.Collaborate with Teams: Work closely with...


  • Singapore PACIFIC PRIME INSURANCE BROKERS SINGAPORE PTE. LTD. Full time

    **Summary** Working as part of the information security office within the IT department at Pacific Prime CXA, the GRC (Governance, Risk and Compliance) Manager will be responsible for leading the day-to-day IT compliance, data governance and IT risk management functions. Primary responsibility will include defining, creation, management and maintenance of...


  • Singapore SECURITY & RISK SOLUTIONS PTE. LTD. Full time

    The APAC Security Control Center (ASCC) is responsible for providing emergency and non-emergency support, conducting research, and providing event dispatch and emergency notification services 24/7. In emergency situations, the ASCC coordinates regional security assistance and support, issues warnings, disseminates information, and serves as the central...

  • Security Officer

    6 days ago


    Singapore SECURITY & RISK SOLUTIONS PTE. LTD. Full time

    1 year exp **Roles & Responsibilities** - General Screening (Person and properties checks) - Guarding and Patrolling (Guard properties, preventing thefts) - Access and Egress Control (Control entry and exit) - Basic Incident Response (Respond to and report alarms) **Requirements**: - Licensed SO and SSO (PLRD Required) **Location** -...


  • Singapore MANPOWER STAFFING SERVICES (SINGAPORE) PTE LTD Full time

    About the RoleMANPOWER STAFFING SERVICES (SINGAPORE) PTE LTD is seeking an Information Security Risk Manager to join our team. As a Cybersecurity Threat Intelligence Specialist, you will play a critical role in identifying and mitigating potential security risks. Your primary responsibilities will include working cross-functionally with different teams to...


  • Singapore Sygnum Full time

    **About the team** Our CISO team’s mission is to be in the vanguard of digital banking security, fostering a safe and prosperous financial future for our stakeholders while setting pioneering new industry standards for security and trust in the digital age. **About You** You are a dedicated and seasoned Information Security Risk Manager, passionate...


  • Singapore Sygnum Bank AG Full time

    Sygnum’s diverse and talented team of banking, investment and DLT experts in shaping the development of a trusted digital asset ecosystem. Tasks - Support definition and improvement of information and security risk requirements and collaborate with our Corporate IT Services and the rest of IT and the Bank to prioritize new feature or control...


  • Singapore Dynamic Human Capital Pte Ltd Full time

    Key ResponsibilitiesAs our Information Security and Risk Manager, you will be responsible for conducting risk and impact assessments to identify and mitigate data protection risks. You will also manage data requests and provide guidance to enhance data governance practices.Manage data requests and provide guidance to enhance data governance...


  • Singapore TENTEN Partners Pte. Ltd. Full time

    **Key Responsibilities**: - Conduct IT Security Risk Assessments. - Manage third party Information Security Due diligence. - Identify and mitigate Tech Obsolescence Risks. - Collaborate with stakeholders to ensure security risks are identified and communicated. - Support IT Security risk committees for robust governance. - Develop and maintain IT Security...


  • Singapore STANDARD CHARTERED BANK Full time

    About Our TeamWe are a dynamic and innovative cybersecurity team dedicated to protecting our organization's data and systems from insider threats. As a Information Security Risk Analyst, you will play a critical role in identifying and mitigating potential insider risks.Key ResponsibilitiesConduct risk assessments to identify potential insider...