Senior Manager, Information Security

2 days ago


Singapore SINGAPORE TELECOMMUNICATIONS LIMITED Full time

To develop and drive effective cyber security advisory and assurance programs in Group Enterprise (GE), Singtel. Establish and/or maintain an information security governance framework and supporting processes to ensure that the information security strategy is aligned with business unit (BU) goals and objectives. Manage information risk to an acceptable level based on risk appetite in order to meet BU goals and objectives. Develop and maintain an information security program that identifies, manages and protects the BU’s assets while aligning to information security strategy and business goals, thereby supporting an effective security posture.

**Responsibilities**:

- Establish security architecture for BU aligned to Group Cyber Resilience. Accountable for ensuring that security infrastructure operations handling the cybersecurity defences (e.g. firewalls, endpoint detection & response) remain current and relevant, such as analysing system protection effectiveness, security analytics, user behaviour analytics.
- Administer compliance with Group Cyber Resilience policies and procedures through ongoing security reviews, audits and assessments.
- Strong analytical skills with the ability to collect and analyse significant amounts of information. Capable of summarising and presenting analysis from significant amounts of information to constructively drive actions and decisions. Conduct security risk assessment, business impact analysis and develop security risk treatment plan.
- Analyze organisational and operational environment, such as assess & document threats, determine system protection needs. Collaborate with stakeholders for risk management, mitigation, and remediation measure.
- Leverage Group Cyber Resilience to deliver security awareness training program to foster a secure culture, improve security awareness and compliance.
- Partner with internal and external audit teams, to manage and effect audits from a compliance & point-in-time perspective, to a risk-driven, continuous proactive compliance approach.
- Point of contact to assist and advise Line-of-Business for cyber security related matters. Strong interpersonal and communication skills with the ability to interact with technical SMEs and business stakeholders and present to senior management stakeholders.
- Strong analytical skills with the ability to collect and analyse significant amounts of information, capable of summarising and presenting analysis to constructively support management to drive actions and decisions. Identify, analyze cyber risks, evaluate and recommend risk treatments. Support the development of information security strategy using techniques such as SWOT analysis, gap analysis. Ensure that risk assessments, vulnerability assessments and threat analyses are conducted consistently, and to identify and assess risk to the BU’s information. Analyze BU's information security controls and their effectiveness. Perform cost/benefit analysis to assess risk treatment options.

**Requirements**:

- Degree/Diploma or higher in Computer Science, Information Systems or equivalent
- At least one security certification is preferred, such as Certified Information Security Management (CISM), Certified Risk Information Security Control (CRISC), Certified Information Systems Auditor (CISA) or Certified Information Systems Security Professional (CISSP) or Certified Third Party Risk Professional (CTPRP)
- At least 8 years of experience in IT Risk Management, Governance or Compliance.
- Understanding of control and risk management concepts including control testing, risk assessments, risk treatment and third-party risk.
- Knowledge of risk management policies, methods, standards, processes, governance models, and both quantitative and qualitative risk analysis approaches.
- Knowledge of common information security management frameworks, such as ISO 27001-5, COBIT and NIST, including 800-53 and Cyber security Framework.
- Information security core competencies, e.g. Access Control (Authentication, Authorization, Access), Network Security, Application Testing, Configuration Management, Mobile System Security, Digital Forensics, Cyber Threat Hunting



  • Singapore SINGAPORE AEROSPACE MANUFACTURING PTE LTD Full time

    SAM is looking to fill the position of **Information Security Manager **. This is a regional role and is overall in-charge of all the entities under SAM. He/She will report to the CEO. **Responsibilites** - To develop and implement a long-term Information Security & Cyber Security strategies and roadmap to protect corporate information and IT assets. - Set...


  • Singapore GO-JEK Full time

    **About the Role** The Information Security Manager will play a crucial role in the implementation of the Information Security programs. You will work closely with the Information Security Chief of Staff and collaborate with leadership and technical teams on the continued evolution of Information Security programs across the cybersecurity, and company...


  • Singapore Robert Half Full time

    **The Company** Our client is a leading real estate company, and they are currently looking for a Manager / Senior Manager, Information Security Awareness to join the team. This is an exciting opportunity to be part of a growing organization. **The Role** As a Manager / Senior Manager of the Global Cybersecurity Strategy team, you will be responsible for...


  • Singapore NETWORK FOR ELECTRONIC TRANSFERS (SINGAPORE) PTE LTD Full time

    The NETS Group is a leading payments services group, enabling digital payments for merchants, consumers and banks across the entire payments value chain. The Group operates Singapore’s national debit scheme enabling customers of DBS Bank/POSB, HSBC, Maybank, OCBC Bank, Standard Chartered Bank and UOB to make payments using their ATM cards or mobile devices...


  • Singapore Randstad Singapore Full time

    Information Security GRC Senior Analyst | APAC Join to apply for the Information Security GRC Senior Analyst | APAC role at Randstad Singapore . This is a full-time, mid-senior level position within the Information Technology industry, focusing on cybersecurity, governance, risk management, and compliance (GRC). Responsibilities Develop, implement, and...


  • Singapore D L RESOURCES PTE LTD Full time

    Roles & ResponsibilitiesJob ObjectivesThe Security Governance Specialist role will support the Head of Security Governance in enhancing and maintaining the Security Governance within the Group Information Security(GIS) function in the Bank.Key ResponsibilitiesThis position will support senior Security Governance team members and work closely with various...


  • Singapore Ensign InfoSecurity Full time

    Ensign is hiring ! As Director, Information Security, you will play a crucial role in implementing Ensign's cybersecurity vision. Reporting to the Information Security Office, you will collaborate with senior management and business units on cybersecurity initiatives. You will play a crucial role in supporting the CISO in establishing and maintaining an...


  • Singapore Manpower Singapore Full time

    This range is provided by Manpower Singapore. Your actual pay will be based on your skills and experience — talk with your recruiter to learn more. Base pay range SGD7,500.00/yr - SGD9,500.00/yr Work cross-functionally with different teams to identify and assess vulnerabilities Guide users through the full remediation lifecycle in a timely fashion Utilize...


  • Singapore Singtel Full time

    **Information Security, Senior Specialist**: **Date**:9 May 2025 **Location**: Singapore, Singapore **Company**:Singtel Group **Be a Part of Something BIG!** This is a Senior Specialist role within Singtel Singapore Cyber Operations Team that is responsible and accountable for proactively identifying and mitigating cyber threats by developing and...


  • Singapore Percept Solutions Full time

    1 year ago Be among the first 25 applicants Get AI-powered advice on this job and more exclusive features. Job Description Develop and continually refine the security framework, information security policies, processes, procedures, and guidelines. Ensure compliance with these policies and procedures through regular security reviews and audits, including...