Cyber Security Compliance Officer

4 days ago


Singapore SDAX EXCHANGE PTE. LTD. Full time

**Cyber Security & TRM Governance**:

- Develop, mature and operationalising cybersecurity framework, policies, procedures, guidelines and baseline standards within the organisation.
- Champion the cyber strategy, planning and execution of enterprise cyber security solutions for the organisation.
- Ensure cybersecurity best practices are embedded within new initiatives, ongoing change management and evaluate the security impact of the initiatives.
- Drive internal Cyber Security Risk Assessments (i.e. planning, developing and executing) including 3rd party due diligence reviews, cybersecurity assurance activities, as well as audit readiness reviews and drive timely resolution.
- Validate effectiveness of current security controls and identify potential gaps.
- Provide advisory services on cybersecurity matters to internal stakeholders.
- Ensure organisational compliance with internal Security policies, standards and procedures, as well as external requirements (e.g., ISO27001, Market specific as well as Global Data Protection regulations including GDPR).
- Drive cybersecurity awareness within the organisation, formulating learning curriculum, rolling out training modules ensuring completion remains above agreed metrics.
- Proactively support in organisational roadmap towards maintaining relevant credentials including Trustmark, ISO27001 compliance and establishing SOC2 compliance report.

**Cyber Security & Technology Risk Operations**:

- Implement and administer IT security devices and related systems (e.g. patch management, endpoint security, etc)
- Involve in SOC implementation and administration to actively monitor the organisation’s IT environment.
- Perform internal/external threat security assessments and address the gaps by developing mitigation plan and following-up actions and remediation timelines up to closure.
- Respond to security incidents, including resolution and remediation, and continually enhance the capability of the incident response team.
- Implement network security appliances, endpoint protections, IT Development Operations security, and perimeter and cloud security measures.
- Research new security technologies, threats and vulnerabilities and implement relevant cost-effective preventive and detective measures.
- Conduct security awareness training, guidance and cybersecurity exercises.
- Manage and align the Company processes for recommended Cyber Security controls in TRM guideline as applicable to Company’s environment setup.
- Manage risk-controls and exposures in Cyber Security aspect.
- Manage third-party services on internal audit controls & cyber-risk aspects under IT Outsourcing Management.
- Manage and setup framework processes to enhance compliance to risk-control measures.
- Manage third party assessment in terms of Cyber-Tech proficiency and risk controls.
- Work within Compliance Team to manage internal GRC (risk and governance) commitment.

**Qualifications and Skills Requirements**:

- Polytechnic Diploma in Technology Information or its equivalent. University Degree in Computer Science is preferred.
- Certifications in CCSP (ISC2), CISSP (ISC2), CASP (Comptia) or its equivalent is preferred. Certifications in CISA (ISACA), CRISC (ISACA) or its equivalent will be an advantage.
- Demonstrate knowledge of cyber security architecture principles, applicable to perimeter defenses, emerging cyber threats, malware defenses, DLP, cryptography, etc.
- Have detailed and good understanding of implemented technologies, network and systems, in particular with respect to Cloud Computing and Network server infrastructure setups, to continuously improve threat hunting capabilities to address the evolving cyber threats.
- Have solid understanding of the SSDLC process and follows the process to effectively develop and design solutions.
- Strong understanding of relevant Industry Principles, Best Practices, and Standards, such as PCI, NIST, ISO, IEEE, and TCG is a requirement.
- Knowledgeable in regulatory compliance (MAS TRM, ABS, BNM, HKMA, CBRC, etc), international guidelines and others is preferred.
- Experience in managing the implementation of regional and global cyber security projects, initiatives, and operational process in concert with the relevant stakeholders and teams will be an advantage.
- Familiarity in Digital Banking, FinTech and Outsourcing will be an advantage.



  • Singapore eToro Full time

    eToro has created an intuitive Social Trading platform that gives traders and investors access to global stock markets, commodity trading, cryptocurrency trading, and more. We strive to make money management available and accessible to everyone (even to users with no prior experience or knowledge). We have over 33 million users worldwide, and our platform is...


  • Singapore eToro (Europe) Ltd. Full time

    eToro has created an intuitive Social Trading platform that gives traders and investors access to global stock markets, commodity trading, cryptocurrency trading, and more. We strive to make money management available and accessible to everyone (even to users with no prior experience or knowledge). We have over 33 million users worldwide, and our platform...

  • Asst Director

    6 days ago


    Singapore Cyber Security Agency of Singapore Full time

    **What the role is** - This position is focused on cyber security readiness, protection, and incident response capabilities by developing, designing and conducting cyber exercises and workshops leading to the development of cyber incident planning artefacts for government and CII sectors/industry. **What you will be working on** - This requisition may be...

  • Cyber Security

    14 minutes ago


    Singapore BGC GROUP PTE. LTD. Full time

    Roles & ResponsibilitiesJoin a 24-months Government Cyber Security Project as a Cyber Security / IAM Engineer. You will work on Cloud IAM, Active Directory, and PAM solutions that safeguard critica systems. This role is also suitabl for candidates with backgrounds as System Engineers or Security Engineers looking to specilaize in IAM.Job Highlights24-Month...


  • Singapore beBeeCybersecurity Full time

    Job Title Information Technology Security Specialist Job Description Conduct cyber risk assessments to support technology initiatives and identify IT-related risks. Monitor, track, and manage risk mitigations and exceptions, ensuring adequate monitoring capabilities are incorporated into solutions. Develop and review security frameworks,...


  • Singapore INSYGHTS SECURITY PTE. LTD. Full time

    Insyghts Security is an information security and cybersecurity service and solution provider. As part of our growth plans, we seek talented individuals with strong networking and system engineering skills to join our team. **Key Responsibilities** As a Cyber Security Engineer, your primary role will be, but are not limited to: - Provide network, system...


  • Singapore PLAN B SECURITY PTE. LTD. Full time

    Job Description: As a next-gen Cyber Security Consultant, the successful candidates will be involved in project planning and the rollout of security solutions to secure customer environments. We seek individuals with an open heart and mind, eager to learn sophisticated Cyber Security technologies. Join us and be part of the next-gen journey. Product...

  • Cyber Security Lead

    1 week ago


    Singapore STAR CAREER CONSULTING PTE. LTD. Full time

    **Cyber Security Lead Job Descriptions You will lead to design, architect, review and implement customized cyber security assessments for client-based asset risk. Be involved with corporate policy compliance, conducting vulnerability assessment and mitigating risks which can help provide projects/organizations with more confidence about system stability and...

  • Cyber Security Lead

    15 hours ago


    Singapore STAR CAREER CONSULTING PTE. LTD. Full time

    **Cyber Security Lead Job Descriptions You will lead to design, architect, review and implement customized cyber security assessments for client-based asset risk. Be involved with corporate policy compliance, conducting vulnerability assessment and mitigating risks which can help provide projects/organizations with more confidence about system stability and...


  • Singapore The Resolute Hunter Pte Ltd Full time

    M - Posted by Marie Tay- Recruiter *Seeking for an IT Risk/Cyber Security talent who has minimum 2 years of experience handling Banking’s IT Risk/ cyber security* **THE COMPANY** With their reputable brand and commitment to their clients, this company is increasing their operations in the region. They seek an IT Risk/Cyber Security Senior Officer to be...