Cybersecurity Vendor Risk Manager

1 week ago


Singapore ASM Full time

We’re not like most. We don’t just overcome obstacles - we don’t see them. Instead, we see the potential in every person, and every situation. We don’t wait for opportunity to appear - we create it. Meet ASM. A company that has been searching for people just like you._

**Who is ASM?**

ASM is a leading, global supplier of semiconductor wafer processing equipment. Our ambitious team is dedicated to delivering innovative technology solutions to the world’s leading semiconductor manufacturers. We have over 2,600 employees based in 14 countries, including Belgium, Japan, Netherlands, South Korea, Singapore, Taiwan and United States. Together we work to develop Epitaxy, ALD, PEALD, Vertical Furnaces and PECVD thin-film deposition technologies for our customers. Our goal is to remain an industry leader by being ahead of what’s next. We accomplish this by focusing on finding collaborative solutions to make integrated circuits, or chips, smaller, faster and even more powerful.

**ASM, an inclusive workplace**

We at ASM are a truly global organization that works diligently with an open-mind in all areas of our business. We strive for a culture and work style that fosters trust and transparency. We put our people first, and that is how we will continue to succeed. We are an equal opportunity employer and value diversity. We recognize and value the differences between individuals, including gender, ethnicity, religious beliefs, sexual orientation, knowledge and experience, work background, age, skills, amongst others. Recruiting and developing a diverse workforce provides a wide range of perspectives. This enables a culture of continuously exploring and adopting new technological ideas and innovations, and it also enables us to deliver excellent products and service to our clients.

**Key Responsibilities**:

- Acts as trusted advisor to senior leadership to set strategy for the Cybersecurity Vendor Risk Management program
- Provides strong leadership, develops and sets individual and team goals, acts as a change agent and leader and creates growth opportunities for all team members
- Ensures efficacy and quality of all processes in scope
- Establish contractual supplier agreements for any vendor that may access, process, store, communicate or provide IT infrastructure to an organization’s data.
- Perform initial and periodic risk assessments, and other necessary reviews, to identify, measure and manage cybersecurity vendor risks based on company standards and risk appetite, leveraging demonstrated working knowledge of industry security practices
- Develop cybersecurity compliance processes and/or audits for external services (e.g., cloud service providers, data centers)
- Manage changes to the supplier services, considering re-assessment of risks.
- Implement and maintain cybersecurity vendor risks processes for onboarding and oversight of all new and existing third-party vendor relationships
- Identifies and drives innovation and process improvements
- **At least 10 years of overall IT experience**:

- **At Least 5 years of Cybersecurity Vendor Risk experience**:

- **At Least 5 years of People Management experience**:

- Experience in the manufacturing industries is advantageous
- At least one relevant industry certification, including CISM, CRISC, CISA, CISSP, CCSP
- Broad knowledge of businesses, functions and security control environment on Vendor Risk Management experience
- Working knowledge of industry risk management frameworks, methodologies and best practices
- Strong presentation and communication skills.
- Ability to collaborate effectively with IT, Privacy, Legal and other business partners to define and achieve objectives

**Technical Skills & Knowledge**:

- Skills including being analytical with attention to detail and long periods of focused attention and sitting, ability to prioritize, troubleshooting
- Ability to perform effective cybersecurity vendor risk assessments and the ability to respond to risk assessment in a timely manner
- Strong written skills to produce security feedback on contracts that are easy to understand for each defined audience
- Industry standards and regulatory requirements such as ISO27K, GDPR, COSO, ISO27036, Trade Compliance
- Ability to direct and lead cross-functional, cross-vendor teams.

Job Req ID: 19005
- From the very start of the semiconductor industry to the present day, we’ve been technology leaders who have pioneered innovation and brought new processes into mainstream manufacturing. We are collaborating, creating, and delivering on our vision - a shared vision to drive innovation with new technologies and delivering excellence with dependable products. By doing this, we’ll create new possibilities for everyone to understand, create and share more of what they love._

**Be part of our exciting future and join our team today



  • Singapore Temasek International Pte Ltd Full time

    Temasek International Pte Ltd is a global investment company that operates on commercial principles, seeking to deliver sustainable returns over the long term. Our Purpose So Every Generation Prospers guides us to make a difference for today's and future generations.Our team is working in the Cybersecurity Department under the Governance, Risk, and...


  • Singapore Temasek International Pte Ltd Full time

    At Temasek International Pte Ltd, we are seeking a seasoned cybersecurity professional to join our team as a Cybersecurity Governance and Risk Manager. This role will be a key member of the Governance, Risk, and Compliance unit, reporting directly to the CISO.About UsTemasek International Pte Ltd is a global investment company headquartered in Singapore. Our...


  • Singapore Temasek International Pte Ltd Full time

    Company OverviewTemasek International Pte Ltd is a global investment company headquartered in Singapore, with a significant presence in the Asian and international markets. With a strong commitment to sustainable returns over the long term, Temasek seeks to make a difference for today's and future generations.The company operates on commercial principles,...


  • Singapore Willowglen Services Pte Ltd Full time

    Job SummaryWe are seeking an experienced professional to spearhead our cybersecurity initiatives. The successful candidate will be responsible for developing and implementing robust security policies, conducting thorough risk assessments, and ensuring compliance with industry standards.Key Responsibilities:Security Policy Development: Establish comprehensive...


  • Central Singapore l'Oréal Full time

    We're not just building brands at L’Oreal, we're shaping how the world experiences beauty (and it takes a lot of cool jobs to do it). Intrigued? Keep reading, this might be the opportunity you've been searching for. **A Day in the Life**: As a Cybersecurity Risk Manager, reporting to the North Asia & SAPMENA GRC Lead, you will be crucial in safeguarding...


  • Singapore ENSIGN INFOSECURITY (CYBERSECURITY) PTE. LTD. Full time

    Roles & ResponsibilitiesDuties and Responsibilities:This individual will play a crucial role in developing and managing information cybersecurity for our clients. As a Cybersecurity Consultant, you will be responsible for developing, evaluating, and reviewing information security policies in accordance with relevant standards and frameworks such as ISO27001,...


  • Singapore SINGAPORE AIRLINES LIMITED Full time

    Job Title: Cybersecurity Risk ManagerAbout the Role:We are seeking a highly experienced Cybersecurity Risk Manager to join our Internal Audit Division. The successful candidate will play a key role in identifying, assessing, and measuring cybersecurity risks associated with SIA's IT systems and processes.Main Responsibilities:Provide independent assurance on...


  • Singapore PERSOLKELLY SINGAPORE PTE. LTD. Full time

    About the RoleWe are seeking a highly skilled Cybersecurity Risk Management Expert to join our team at PERSOLKELLY SINGAPORE PTE. LTD.Job Description:The Cybersecurity Risk Management Expert will be responsible for safeguarding systems, applications, and infrastructure through proactive vulnerability management, the application of security controls, secure...


  • Singapore PROTIVITI PTE. LTD. Full time

    Required Skills and QualificationsAudit experience in Information Security, IT infrastructure, Cybersecurity, and Vendor Risk Assessments or other related field.Experience reviewing cloud infrastructure-as-a-service (IaaS), software-as-a-service (SaaS), DevOps, virtualization.Experience in IT Audit, IT Risk Management, Information Security and SOX...


  • Singapore STONE CYBERSECURITY PTE. LTD. Full time

    About Stone Cybersecurity Pte LtdWe are a dynamic cybersecurity consulting firm in Singapore, committed to helping organizations enhance their cybersecurity posture and achieve compliance with industry best practices.The OpportunityWe are seeking an experienced Cybersecurity Consultant to lead our ISO 27001 and NIST audit and readiness services. As a key...


  • Singapore STONE CYBERSECURITY PTE. LTD. Full time

    We are looking for a strategic, detail-oriented individual to join our team as a security consultant. Your responsibilities will include developing and reviewing activities across the entire scope of our client's Security Governance, Risk and Compliance programs. (E.g. NIST, ISO27001, MAS-TRM etc.) To be successful as a security consultant, you should have...


  • Singapore MANPOWER STAFFING SERVICES (SINGAPORE) PTE LTD Full time

    Roles & ResponsibilitiesWe are seeking a diligent Cybersecurity Risk Analyst to identify, analyse, and mitigate cybersecurity risks in our systems and networks.This role involves the execution of risk assessments, vulnerability analyses and the development of risk management strategies.You should be well-versed in cybersecurity risk assessment methodologies...


  • Singapore Manpower Singapore Full time

    We are seeking a diligent Cybersecurity Risk Analyst to identify, analyse, and mitigate cybersecurity risks in our systems and networks. This role involves the execution of risk assessments, vulnerability analyses and the development of risk management strategies. You should be well-versed in cybersecurity risk assessment methodologies and familiar with a...


  • Singapore Manpower Singapore Full time

    We are seeking a diligent cybersecurity expert to identify, analyze, and mitigate potential threats in our systems and networks.Job DescriptionThis role involves performing risk assessments, vulnerability analyses, and developing risk management strategies. You should be well-versed in cybersecurity risk assessment methodologies and familiar with various...


  • Singapore Secur Solutions Group Pte Ltd Full time

    Risk Management Specialist - Cybersecurity:As a Risk Management Specialist - Cybersecurity, you will play a critical role in identifying and mitigating cybersecurity risks within our organization. Your expertise will help us maintain a robust security posture and protect our clients' interests.Key responsibilities include conducting risk assessments,...


  • Singapore STONE CYBERSECURITY PTE. LTD. Full time

    About Stone Cybersecurity Pte LtdWe are a leading cybersecurity consulting firm in Singapore, delivering expert advice to organizations across various industries.Our team is passionate about protecting businesses from cyber threats and fostering a collaborative work environment that values continuous learning and professional growth.The OpportunityWe are...


  • Singapore RECRUIT EXPRESS PTE LTD Full time

    Roles & ResponsibilitiesResponsibilities:Risk Assessment: Perform risk assessments to identify potential threats to the organization's information systems. Vulnerability Analysis: Analyse and assess vulnerabilities in the network and system infrastructure. Security Audits: Conduct security audits to ensure policies, processes, procedures and controls are...


  • Singapore STONE CYBERSECURITY PTE. LTD. Full time

    Roles & ResponsibilitiesAbout Stone Cybersecurity Pte LtdStone Cybersecurity Pte Ltd is a leading cybersecurity consulting firm in Singapore and a CREST-accredited service provider. We help organizations across industries strengthen their security posture, achieve compliance, and mitigate cybersecurity risks. Our team is passionate about protecting...


  • Singapore NodeFlair Full time

    **Job Summary**: **Salary** S$6,000 - S$8,000 / Monthly **Job Type** **Seniority** Manager **Years of Experience** At least 5 years **Responsibilities**: - Perform daily cybersecurity operations and incident response. - Provide monthly Security Status Report, containing mínimally the following information: incidents reporting, risk register, security...


  • Singapore SGB Full time

    Job OverviewSGB is seeking a highly skilled Cybersecurity Risk Manager to support daily security operations, monitoring, and incident response. This role requires solid technical expertise and a strong understanding of information security principles, with hands-on experience in security tools and frameworks.