Information Security Specialist

3 days ago


Singapore COMMERZBANK AKTIENGESELLSCHAFT Full time

**Job purpose**:
This position is part of the Asia information Security and Data Protection function in Singapore with focus on information security and third-party risk management.

**Key activities**:

- Assisting the Head of Information Security Asia in implementing and maintaining the Group's information security strategy, policies, and procedures to manage cyber and Third-Party Information Security risk and ensure compliance with relevant laws and regulations.
- Assessing the security posture of third-party vendors, partners, or service providers to ensure compliance with organizational standards and regulatory requirements.
- Collaborating with procurement, legal, and business units to evaluate the security implications of engaging with third-party vendors and providing guidance and recommendations to stakeholders on selecting, onboarding, and managing third-party vendors securely.
- Reviewing and negotiating information security and data protection clauses in contracts and agreements with third-party vendors to establish security requirements and responsibilities.
- Conducting risk assessments of third-party systems (including cloud), networks, and processes to identify gaps in information security controls.
- Collaborate with head office in developing and implementing strategies in continue monitoring and evaluating third-party security performance through regular assessments and audits.
- Participating in cross-functional teams or committees on vendor risk management and security governance driven regionally and globally.
- Collaborating with auditors to provide necessary documentation, evidence, and support during audit fieldwork, testing, and reporting phases.
- Reviewing audit findings, recommendations, and reports to identify opportunities for improving information security and third-party risk management practices, processes, and controls.

**Formal education**:

- University or college degree or comparable
- Possession of professional qualifications will be advantageous. e.g. CISA, CISM, CRISC, CISSP, CTPRP

**Specialist knowledge (work experience, further qualification)**:

- Minimum 5+ years of related experience in Information Security, third-party risk management or technology Risk function in financial services industry or consultancy.
- Knowledge of Asia regulatory requirements with a strong understanding of the financial industry. PDPC, MAS, NAFR, PBOC, JFA
- Have a strong security risk and analytical mindset in approaching situations and interactions with stakeholders.
- Strong communication and interpersonal skills, with an ability to translate complex technical information for a non-technical audience.



  • Singapore Castlery Full time

    Castlery is looking for an **Information Security Specialist **to join our **Information Security **team, which is a newly created team that manages IT and Information Security for Castlery's global operations and technology infrastructure. In this newly created role, the Information Security Specialist would be one of the pioneer members that would help...

  • Information Security

    2 weeks ago


    Singapore D L Resources Pte Ltd Full time

    Job Objectives The Security Governance Specialist role will support the Head of Security Governance in enhancing and maintaining the Security Governance within the Group Information Security(GIS) function in the


  • Singapore INFINEUM SINGAPORE LLP Full time

    As part of the global IT team, the IT Information Security Specialist will plan and implement policies, procedures, standards, and controls to govern the protection of corporate information systems, networks, and data. The Information Security Specialist will stay up-to-date on the latest cybersecurity intelligence, including hackers' methodologies, in order...


  • Singapore SMART INFORMATION MANAGEMENT SYSTEMS PRIVATE LIMITED Full time

    **Key Responsibilities**: **Cybersecurity Risk Assessment & Mitigation**: - **Cyber Risk Assessment**:Conduct comprehensive cyber risk assessments in support of technology initiatives, identifying IT-related risks and recommending appropriate security controls to mitigate those risks. - **Risk Monitoring & Management**:Continuously track and manage risk...


  • Central Singapore Emprego SG Full time

    **Location** - Singapore, Central Singapore**Job Type** - Full Time**Salary** - $7,000 - $14,000 Per Month**Date Posted** - 5 hours agoAdditional Details **Job ID** - 106911**Job Views** - 1Roles & Responsibilities Description - Plan and coordinate the IT security programs and policies. - Maintain action plans, project plans, incident, issue and risk...


  • Singapore Capital Group Companies Full time

    Role Summary: Reporting into the Regional Head of Information Security, APAC, the Information Security Specialist will be supporting the RISO in aligning control standards of the enterprise Information Security program with cyber regulatory requirements in APAC and other Capital Group operating locales. Partnering closely with regional L&C and the Office of...


  • Singapore Argyll Scott Full time

    Our client who is from a European IT Organization is looking for an IT / Information Security Specialist. You will be in a team that you report directly to the CISO. This is a permanent opportunity. **Responsibilities: -** - Securing on both newly build and existing running systems in the environment, ensuring these systems are running and complying with...


  • Singapore MHA - Internal Security Department (ISD) Full time

    **What the role is** - ISD confronts and addresses threats to Singapore’s internal security and stability. For over 70 years, ISD and its predecessor organisations have played a central role in countering threats such as those posed by foreign subversive elements, spies, racial and religious extremists, and terrorists. A fulfilling and rewarding career...


  • Singapore Rakuten Asia Pte Ltd Full time

    The Regional Chief Information Security Office (CISO) is to lead information security related actions to protect Rakuten Group companies in Asia region from internal/external security threat. You will be required to defines, prioritizes, and tracks large scale, high visibility IT security projects to reduce or eliminate risks that have been identified. This...


  • Singapore SINGAPORE TELECOMMUNICATIONS LIMITED Full time

    **Responsibilities**: - Work with TPRM Associate Director to support the third-party security risk agenda of the Group CISO and GGC Senior Director. - Support the Third-Party Risk Management Program incorporating third-party cyber risk management process and cyber security assessment methodologies using industry standards to safeguard Singtel Group...