Senior Manager, Governance, Risk

2 weeks ago


Singapore Marriott International, Inc Full time

**Job Number** 23191088

**Job Category** Information Technology

**Location** Singapore Regional Office, 2 Harbourfront Place #06-08, Singapore, Singapore, Singapore VIEW ON MAP

**Schedule** Full-Time

**Located Remotely?** N

**Relocation?** N

**Position Type** Management
**JOB SUMMARY**:
The APEC security GRC senior manager is a Singapore-based position that is part of APAC GIS team and focuses on security governance, risk and compliance matters for APEC region. This role is as a core member of the GRC team that will mature the Company’s cyber regulation compliance posture and ensure the day-to-day compliance for APEC by collaborating within information security team and the broader business disciplines, such as IT, Digital, Legal, Government Affairs, etc.

**CANDIDATE PROFILE**

**Education and Experience**
**Required**:

- 7+ years progressive experience in related fields such as information security, cyber regulation compliance, IT audit etc. That also includes direct experience with:

- security tooling for logging, monitoring, alerting, and reporting (e.g. Splunk)
- vulnerability management tools (e.g. Tenable.io)
- database security (e.g. MySQL, SQL Server)
- mainstream security products (e.g. Firewall, IDS/IPS, EPP/AV, SWG)
- main APEC counties cloud/infrastructure and operation systems security domains (e.g. Unix/Linux, Windows)
- Must possess English Language proficiency (reading/writing/speaking. Bi/multi-lingual skills

**Additional Preferred skills and experience**:

- Familiarity with security management of mainstream cloud platforms, such as Alicloud, Tencent, AWS etc
- Familiarity with main APEC counties including Australia, Japan, Korea and India Cyber Security laws and data protection requirements
- Bi/multi-lingual skills
- Experience in leading or participating in cyber incident response events
- Industry certifications such as CISSP, PCI ISA, CISA, CISM etc.
- Knowledge of hospitality culture

**Key Stakeholders**
- Singapore Security Center
- Continent Information Security Partnership
- APEC IT leaders
- Hotel IT associates
- Global Information Security
- APAC Digital team
- APAC Legal team
- Other roles involved in data and system protection

**CORE WORK ACTIVITIES**

**Managing Projects and Priorities**
- Responsible for cyber regulation internal assessments and risk management based on APEC countries security law, data protection regulatory requirements etc.
- Partners with continent information security partnership team and cyber fusion center to maintain cyber regulation compliance monitoring mechanism for APEC countries
- Manages and monitors the IT risk posture for hotel IT environment, cloud data platforms, web security, and digital channels
- Coordinates or performs remediation activities identified from internal and external cyber regulation assessments
- Performs regular cyber compliance metric reporting and monitor key risk indicators
- Supports cyber incident response management by localizing the global incident response process to fit with regional purpose and coordinate simulations
- Supports regulator inspections, coordinates submission preparation, and tracks remediations
- Implements cyber regulation awareness program catering various roles in the entity
- Monitors cyber threats, analyzes key risks related to cyber regulations, and defines solutions with wider IT and Security teams
- Monitors compliance controls over key IT assets on daily basis.
- Perform regular Security Risk Assessment including 3rd Party risk assessment and review

**Maintaining Goals**
- Submits reports in a timely manner, ensuring delivery deadlines are met.
- Promotes the documenting of project progress accurately.
- Provides input and assistance to other teams regarding projects.

**Managing Work, Projects, and Policies**
- Manages and implements work and projects as assigned.
- Generates and provides accurate and timely results in the form of reports, presentations, etc.
- Analyzes information and evaluates results to choose the best solution and solve problems.
- Provides timely, accurate, and detailed status reports as requested.
- Provides technical expertise and support to persons inside and outside of the department.
- Demonstrates knowledge of job-relevant issues, products, systems, and processes.
- Demonstrates knowledge of function-specific procedures.
- Keeps up-to-date technically and applies new knowledge to job.
- Uses computers and computer systems (including hardware and software) to enter data and/ or process information.

**Delivering on the Needs of Key Stakeholders**
- Understands and meets the needs of key stakeholders.
- Develops specific goals and plans to prioritize, organize, and accomplish work.
- Determines priorities, schedules, plans and necessary resources to ensure completion of any projects on schedule.
- Collaborates with internal partners and stakeholders to support business/initiative strategies
- Communicates concepts in a clear and persuasive manner th



  • Singapore GREAT EASTERN Full time

    Join to apply for the Manager - Group Ops Risk Governance role at GREAT EASTERN 2 days ago Be among the first 25 applicants Join to apply for the Manager - Group Ops Risk Governance role at GREAT EASTERN You will be part of a dynamic team in Group Operations responsible for the oversight and management of the Great Eastern Regional Operations Functions. We...

  • Senior Manager

    4 days ago


    Singapore Synapxe Full time

    Overview Senior Manager - Technology Risk & Governance (Sector Governance). You will play an important role as the enabler and integrator to drive the development and implementation of cybersecurity policies and risk management programs in the public healthcare sector. In this role, you will be responsible to develop and continuously increase cybersecurity...


  • Singapore wizlynx group Full time

    Join to apply for the Manager & Senior Consultant (Governance, Risk & Compliance)role at wizlynx group Continue with Google Continue with Google Join to apply for the Manager & Senior Consultant (Governance, Risk & Compliance)role at wizlynx group Apply Now Manager & Senior Consultant (Governance, Risk & Compliance)Location: Singapore Job Summary And Mission...


  • Singapore Standard Chartered Full time

    Job ID: 25155 Location: Singapore, SG Area of interest: Operations Job type: Regular Employee Work style: Hybrid Working Opening date: 14 Apr 2025 **Job Summary** - Supporting the Director, Business Risk, Governance and Data, TB; with the execution of the strategic TB Governance agenda, ensuring the right risk, control and governance environment is in...

  • Governance, Risk

    2 weeks ago


    Singapore Quantum infotech Solutions Full time $90,000 - $120,000 per year

    Requirements:At least 5 years of experience in IT Governance, Risk Management and Compliance with 3 to 5 years of relevant experience specifically in IT Governance and Risk management.Candidates from financial/payment industry and familiar with MAS & CCOP regulatory requirements or equivalent are preferred.Candidates with experience in IT/Cyber...


  • Singapore National Trades Union Congress (NTUC) Full time

    Get AI-powered advice on this job and more exclusive features. Are you passionate about enhancing workers’ employment and employability? Can you connect workers with employers through job-matching, career guidance, and skills upgrading? Ready to collaborate on recruitment, training, and job redesign to support nationwide skills development?If your answers...


  • Singapore National Trades Union Congress (NTUC) Full time

    Get AI-powered advice on this job and more exclusive features. Are you passionate about enhancing workers’ employment and employability? Can you connect workers with employers through job-matching, career guidance, and skills upgrading? Ready to collaborate on recruitment, training, and job redesign to support nationwide skills development?If your answers...


  • Singapore THE HONGKONG AND SHANGHAI BANKING CORPORATION LIMITED Full time

    **Principal Responsibilities** The Technology team sits under the Chief Information Officer who reports to the Country Chief Operating Officer. This job is part of the CIO's team providing oversight of the risk and control environment across Technology and the Singapore market. The job is particularly critical with the increased regulatory focus on...


  • Singapore Keppel Infrastructure Full time

    Enterprise Risk Management As part of ERM team, maintain and improve the established ERM framework, methodologies and processes in accomplishing the corporate objectives. That covers: - Facilitate and review risk assessments for key business operations, strategic investments and major projects; - Ensure that processes are in place to analyze risks from...


  • Singapore Standard Chartered Full time

    Area of interest: Governance, Risk Management & Compliance Overview This role could be based in Singapore and Dubai. When you start the application process you will be presented with a drop-down menu showing all countries; please select a country where the role is based. Key Responsibilities Act as the second line Subject Matter Expert for Digital Assets...