Cybersecurity Vendor Risk Manager

2 weeks ago


Singapore ASM Full time

We’re not like most. We don’t just overcome obstacles - we don’t see them. Instead, we see the potential in every person, and every situation. We don’t wait for opportunity to appear - we create it. Meet ASM. A company that has been searching for people just like you._

**Who is ASM?**

ASM is a leading, global supplier of semiconductor wafer processing equipment. Our ambitious team is dedicated to delivering innovative technology solutions to the world’s leading semiconductor manufacturers. We have over 2,600 employees based in 14 countries, including Belgium, Japan, Netherlands, South Korea, Singapore, Taiwan and United States. Together we work to develop Epitaxy, ALD, PEALD, Vertical Furnaces and PECVD thin-film deposition technologies for our customers. Our goal is to remain an industry leader by being ahead of what’s next. We accomplish this by focusing on finding collaborative solutions to make integrated circuits, or chips, smaller, faster and even more powerful.

**ASM, an inclusive workplace**

We at ASM are a truly global organization that works diligently with an open-mind in all areas of our business. We strive for a culture and work style that fosters trust and transparency. We put our people first, and that is how we will continue to succeed. We are an equal opportunity employer and value diversity. We recognize and value the differences between individuals, including gender, ethnicity, religious beliefs, sexual orientation, knowledge and experience, work background, age, skills, amongst others. Recruiting and developing a diverse workforce provides a wide range of perspectives. This enables a culture of continuously exploring and adopting new technological ideas and innovations, and it also enables us to deliver excellent products and service to our clients.

**Key Responsibilities**:

- Acts as trusted advisor to senior leadership to set strategy for the Cybersecurity Vendor Risk Management program
- Provides strong leadership, develops and sets individual and team goals, acts as a change agent and leader and creates growth opportunities for all team members
- Ensures efficacy and quality of all processes in scope
- Establish contractual supplier agreements for any vendor that may access, process, store, communicate or provide IT infrastructure to an organization’s data.
- Perform initial and periodic risk assessments, and other necessary reviews, to identify, measure and manage cybersecurity vendor risks based on company standards and risk appetite, leveraging demonstrated working knowledge of industry security practices
- Develop cybersecurity compliance processes and/or audits for external services (e.g., cloud service providers, data centers)
- Manage changes to the supplier services, considering re-assessment of risks.
- Implement and maintain cybersecurity vendor risks processes for onboarding and oversight of all new and existing third-party vendor relationships
- Identifies and drives innovation and process improvements
- **At least 10 years of overall IT experience**:

- **At Least 5 years of Cybersecurity Vendor Risk experience**:

- **At Least 5 years of People Management experience**:

- Experience in the manufacturing industries is advantageous
- At least one relevant industry certification, including CISM, CRISC, CISA, CISSP, CCSP
- Broad knowledge of businesses, functions and security control environment on Vendor Risk Management experience
- Working knowledge of industry risk management frameworks, methodologies and best practices
- Strong presentation and communication skills.
- Ability to collaborate effectively with IT, Privacy, Legal and other business partners to define and achieve objectives

**Technical Skills & Knowledge**:

- Skills including being analytical with attention to detail and long periods of focused attention and sitting, ability to prioritize, troubleshooting
- Ability to perform effective cybersecurity vendor risk assessments and the ability to respond to risk assessment in a timely manner
- Strong written skills to produce security feedback on contracts that are easy to understand for each defined audience
- Industry standards and regulatory requirements such as ISO27K, GDPR, COSO, ISO27036, Trade Compliance
- Ability to direct and lead cross-functional, cross-vendor teams.

Job Req ID: 19005
- From the very start of the semiconductor industry to the present day, we’ve been technology leaders who have pioneered innovation and brought new processes into mainstream manufacturing. We are collaborating, creating, and delivering on our vision - a shared vision to drive innovation with new technologies and delivering excellence with dependable products. By doing this, we’ll create new possibilities for everyone to understand, create and share more of what they love._

**Be part of our exciting future and join our team today



  • Singapore Krisvconsulting Services Pte Ltd Full time

    About the job Cybersecurity Governance & Risk Manager Responsibilities: Implement IT risk management frameworks, policies, and compliance checks Maintain cybersecurity policies, vendor governance, and system criticality frameworks Modernize oversight via emerging tech and real-time risk tracking tools Ensure secure SDLC and risk assessments during IT...


  • Central Singapore l'Oréal Full time

    We're not just building brands at L’Oreal, we're shaping how the world experiences beauty (and it takes a lot of cool jobs to do it). Intrigued? Keep reading, this might be the opportunity you've been searching for. **A Day in the Life**: As a Cybersecurity Risk Manager, reporting to the North Asia & SAPMENA GRC Lead, you will be crucial in safeguarding...


  • Singapore STONE CYBERSECURITY PTE. LTD. Full time

    We are looking for a strategic, detail-oriented individual to join our team as a security consultant. Your responsibilities will include developing and reviewing activities across the entire scope of our client's Security Governance, Risk and Compliance programs. (E.g. NIST, ISO27001, MAS-TRM etc.) To be successful as a security consultant, you should have...


  • Singapore Singapore Polytechnic Full time

    A national cybersecurity agency in Singapore is seeking a cybersecurity manager to oversee governance and risk management of organizations. The ideal candidate has a background in Computer Science or Cybersecurity and at least 2 years of relevant experience. Responsibilities include managing cybersecurity requirements, developing technology programmes, and...

  • Project Manager

    1 week ago


    Singapore ANOTECH ENERGY SINGAPORE PTE. LTD. Full time

    ALTEN Group is a world leader in Engineering and Technology consulting services providing outsourced Engineering, R&D, and IT Services for different industries such as Transportation, Defence, Energy and Security with 55,000 engineers in nearly 35 countries. ANOTECH is the subsidiary of the Group delivering ALTEN's Engineering Services in Singapore. As a...

  • Cybersecurity Risk

    2 weeks ago


    Singapore Krisvconsulting Services Pte Ltd Full time

    A leading consulting firm in Singapore is seeking a Cybersecurity Governance & Risk Manager. This role requires over 7 years of experience in cybersecurity and IT risk management. You will be responsible for implementing risk management frameworks, ensuring compliance, conducting audits, and advising on cybersecurity risks. The ideal candidate will have...

  • IT Grc

    2 weeks ago


    Singapore CAREERALLY PTE. LTD. Full time

    We are seeking an experienced **IT Vendor Risk Specialist**to oversee vendor relationships, contracts, and performance for mission-critical systems. You will play a key role in managing risks, ensuring regulatory compliance, and driving continuous improvements in vendor governance processes. **Key Responsibilities**: - Oversee IT vendor relationships,...


  • Singapore Assurity Trusted Solutions Full time

    Assurity Trusted Solutions (ATS) is a wholly owned subsidiary of the Government Technology Agency (GovTech). As a Trusted Partner over the last decade, ATS offers a comprehensive suite of products and services ranging from infrastructure and operational services, authentication services, governance and assurance services as well as managed processes. In a...

  • Assistant Manager

    2 weeks ago


    Singapore ST LOGISTICS PTE. LTD. Full time

    **Responsibilities**: **Technology Governance** - Drive the implementation of a robust Cyber governance and Cyber security risk management framework to ensure appropriate controls - Review existing policies to ensure that the policies are updated to reflect accuracy on the evolving cyber threat and emerging cyber threats. - Ensure appropriate cyber and...


  • Singapore Assurity Trusted Solutions Pte Ltd Full time

    Assurity Trusted Solutions (ATS) is a wholly owned subsidiary of the Government Technology Agency (GovTech). As a Trusted Partner over the last decade, ATS offers a comprehensive suite of products and services ranging from infrastructure and operational services, authentication services, governance and assurance services as well as managed processes. In a...