Lead IT Security Grc
1 week ago
**Lead IT Security GRC
**Job Summary**:
Document, monitor and improve the effectiveness of IT operating controls, risk management, and governance processes for Information Security. Participate in or lead audits from external regulators and internal functions including tracking deliverables, tasks, and corrective actions; perform assessments to identify continuous improvements; ensure compliance with regulations, company policies and IT controls; coordinate the audit processes including preparing, hosting, and then reviewing, analyzing, and reporting findings internally; track remediation to ensure follow up until closure; and compile and report on regional IS compliance-related KPIs.
**Specific Responsibilities Include**:
- Define, plan and manage Information Security assessments and activities across APAC sites
- Ensure compliance with regulatory requirements and internal policies, and report on compliance gaps and design and lead remediation plans to address identified gaps
- Ensure successful internal and external audits and certifications for IT
- Act as single point of contact and prepare for audit by researching materials, formulating a plan of action, and identifying and preparing SMEs and evidence.
- Support external auditors by coordinating information requirements.
- Ensure compliance with regulations and controls by examining and analyzing records, reports, operating practices, and documentation; recommend opportunities to strengthen internal control structure and compliance
- Evaluate new products and services to determine compliance with laws and regulations by which GlobalFoundries must abide and best practices
- Perform and document security assessments by documenting evaluation methods and findings, for example, system security plans with plan of action and milestones.
- Communicate assessment progress and findings by preparing presentations, facilitating meetings, and providing information through various means.
- Develop, review and revise IT policies, procedures, and standards
- Help lead IT risk assessment and treatment program, including identification of risks and ensuring implementation of mitigating controls and mapping to authoritative sources and projects
- Enhance Information Security compliance department and organization reputation by accepting ownership for accomplishing new and different requests and projects and exploring opportunities to add value to the team
- Assist in globalization and alignment of Information Security compliance
**Required Qualifications**:
- Experience leading / working with ISO 27001 audits and programs
- Experience leading / working with NIST frameworks and special publications
- Minimum 5 years’ experience in one or more of the relevant disciplines: IT, Information Security, Operational Audit, Compliance
- Bachelor’s Degree in Computer Science, Information Systems, Information Security, or equivalent experience
**Preferred Qualifications**:
- IIA/CISA certified
- Certifications in COBIT, ISO, and other pertinent professional certifications in computer technology, auditing, compliance or related areas
- Certification or experience in project management
- Prior experience with SOX, GDPR
- Experience working with Risk Management
- Attention to detail
- Team player
- Strong ability to drive execution and meet strict deadlines
- Results Oriented
- Ability to communicate effectively with all levels of personnel
- Accountability
- Analytical Thinking
- Continuous Process Improvement
- Problem Solving
- Technical Expertise, e.g. COBIT
- Working knowledge of ServiceNow
GLOBALFOUNDRIES is an equal opportunity employer, cultivating a diverse and inclusive workforce. We believe having a multicultural workplace enhances productivity, efficiency and innovation whilst our employees feel truly respected, valued and heard.
As an affirmative employer, all qualified applicants are considered for employment regardless of age, ethnicity, marital status, citizenship, race, religion, political affiliation, gender, sexual orientation and medical and/or physical abilities.
-
SAP Grc Lead
2 weeks ago
Singapore Blue Ocean Systems Infotech Pte Ltd Full timeHi, Urgent opening for SAP GRC Lead Evaluate & integrate SAP Fiori apps into SAP GRC Perform outside research to develop expertise in SAP GRC security functionality and industry best practices within the SAP GRC, the IT risk management and compliance space Provide technical leadership in the assessment, design, and implementation of SAP GRC security and...
-
Security Consultant
22 hours ago
Singapore Genesis Networks Pte Ltd Full timeWe are looking for a strategic, detail-oriented individual to join our team as a Security Consultant with a focus on Governance, Risk, and Compliance (GRC). Your responsibilities will include assessing security risks, ensuring compliance with regulatory standards, and developing policies to enhance the security posture of our organisation and clients. As the...
-
IT Security
1 week ago
Singapore Charterhouse Full timeIT Security - GRC Manager Position Overview We are seeking a seasoned professional to lead and manage security governance initiatives, ensuring robust protection of organizational information and systems. The role encompasses compliance oversight, risk management, security audits, data loss prevention, DevSecOps release management, and security architecture...
-
Lead Consultant, GRC
2 days ago
Singapore NCS Full time $80,000 - $120,000 per yearLead Consultant, GRCDate: 27 Oct 2025Location: Singapore, SingaporeCompany: Singtel GroupNCS is a leading technology services firm that operates across the Asia Pacific region in over 20 cities, providing consulting, digital services, technology solutions, and more. We believe in harnessing the power of technology to achieve extraordinary things, creating...
-
Senior Manager
6 days ago
Singapore Singtel Group Full timeSelect how often (in days) to receive an alert: At Singtel, we believe in the strength of a vibrant, diverse and inclusive workforce where backgrounds, perspectives and life experiences of our people help us innovate and create strong connections with our customers. We strive to ensure all our people practices are non-discriminatory and provide a fair,...
-
Grc Apac, India
6 days ago
Singapore Pernod Ricard Full timeThis role will involve driving security and privacy risk evaluations, coordinating response actions for suspected data breaches, and supporting the implementation and maintenance of a Cyber Security framework across key security domains: - Define, help implement, and govern Cyber Security policies, standards and guidelines. - Drive security and privacy risk...
-
Information and Cyber Security Engineer
2 weeks ago
Singapore SCIENTE Full timeInformation and Cyber Security Engineer - GRC Seeking an experienced Information & Cyber Security Engineer to strengthen a centralized technology function and accelerate secure cloud adoption across a regional operations footprint. The role focuses on cybersecurity risk assessment, cloud security, third‑party assurance, and governance in a regulated...
-
Information and Cyber Security Engineer
1 week ago
Singapore SCIENTE Full timeInformation and Cyber Security Engineer - GRC Seeking an experienced Information & Cyber Security Engineer to strengthen a centralized technology function and accelerate secure cloud adoption across a regional operations footprint. The role focuses on cybersecurity risk assessment, cloud security, third-party assurance, and governance in a regulated...
-
Project Engineer(IT Security/grc) Perm Role
1 week ago
Singapore ZENITH INFOTECH (S) PTE LTD. Full time**Presently we have a Job Opening for a Project Engineer(IT Security/GRC)** **EMPLOYMENT TYPE: PERM** Benefits: AWS and VB **Job scope**: Central effort to check and handhold project teams to make sure that they have fully onboarded to enterprise compliance platforms and have proper, sustainable processes in place to fulfil IT compliance...
-
Senior Manager, Cyber Security Grc
2 weeks ago
Singapore CAREERALLY PTE. LTD. Full timeYou will join the Security team, collaborating closely with cross-functional teams in a dynamic environment. Your role will be within the Governance, Risk & Compliance (GRC) team, where your expertise in cybersecurity frameworks, policies, and standards will be essential. As part of the line 1.5 team, you will help ensure that the organization meets all...