Information Security Governance, Risk and

1 day ago


Singapore FCM Full time

**Job no**: 511715
**Brand**: FCM
**Work type**: Full time
**Location**: Singapore
**Categories**: Information & Technology

**The GRC Security Analyst Singapore** will plan and implement policies, procedures, standards, and controls to govern the protection of the company’s information systems, networks, and data. The GRC security analyst will stay up to date on the latest cybersecurity intelligence to modify standards and controls that govern cybersecurity across the corporation and to oversees effective system-wide security analysis; intrusion detection; standards and testing; risk assessment; awareness and development of policies, standards, and guidelines

The GRC Security Analyst will be responsible for updating and managing the security policy framework and relevant standards; overseeing applicable security, privacy, contractual and compliance requirements (i.e., ISO27001, Payment Act, PDPA, PCI-DSS, AML/KYC, MAS TRM and local privacy laws) through strategy development, controls definition and assessment and process oversight.

The purpose of this position is to provide highly skilled technical and information security expertise for development and implementation of the information security risk management program as well as handling Compliance and security requests coming from Business and customers (E.g. RFP, incidents, communication)

The GRC Security Analyst updates and maintains control matrices and spreadsheets and provides recommendations for management’s consideration. The incumbent works with internal, regional, Global teams, external providers to provide supportive documentation as applicable.

**Key Responsibilities**
- Establish policies, processes, and procedures in line with local and international regulations
- Implements security controls, risk assessment framework, and program that align to regulatory requirements, ensuring documented and sustainable compliance that aligns and advances Company business objectives.
- Implements processes, such as GRC (governance, risk and compliance), to automate and continuously monitor information security controls, exceptions, risks, testing. Develops reporting metrics, dashboards, and evidence artifacts to bring visibility and transparency.
- Updates security controls and provides support to all stakeholders on security controls covering internal assessments, regulations, protecting Privacy data, and Payment Card Industry Data Security Standards (PCI DSS).
- Verify the security compliance posture against the regulations and standards and derive a security implementation plan for remediation
- Liaise with all departments to identify, track, and provide remediation guidance for new projects, services and/or third-party contracts in terms of information security assurance
- Oversee third party assessment standards and privileged user monitoring as a check on critical system access
- Establish and oversee formal vulnerability management, penetration testing and security posture assessment programs
- Oversees and improves execution of Disaster Recovery Plan and BCP, Backup /restore policy (metrics, dashboard) in collaboration with ISS & IT Ops teams.
- Trains, guides, and acts as a resource on security assessment functions to other departments within the Company

**Key Competencies and Skills**
- Minimum 5 years working experience in IT/IS/Audit/Business/Technology
- 5 years in a security governance, risk, and compliance management experience
- Experience in large scale audit or governance projects
- Strong knowledge of current and emerging cyber security risks, and innovative risk management methods and solutions
- Ability to collaboratively develop a risk strategy in conjunction with stakeholders
- Strong analytical thinking, written, and oral communication and presentation skills
- Broad understanding of security and privacy concepts
- Ability to adapt and embrace change in a fast-paced, changing environment
- Ability to effectively communicate and relate to all levels of the organization
- Able to understand contracts and technical documentation and able to assess it for consistency and alignment with processes and controls outlined in requirements and audit materials
- Excellent communication skills at all levels and ability to adapt style to suit audience
- Industry recognized certification in security (e.g., CISSP, CISA, CISM, CEH, etc.) is preferred



  • Singapore AIA Full time

    At AIA we’ve started an exciting movement to create a healthier, more sustainable future for everyone. - As pioneering innovators for over 100 years, we’re now transforming our organisation to be faster, simpler and more connected. Because we want to be even better equipped to develop digital solutions and experiences that help more people live...


  • Singapore Nanyang Technological University Full time

    ABOUT THE NATIONAL INSTITUTE OF EDUCATION (NIE) The National Institute of Education (NIE), Singapore, is Singapore’s national teacher education institute and we are proud to be an integral part of the nation’s education service. We play a key role in the preparation of teachers and in the provision of teacher professional and school leadership...


  • Singapore Castlery Full time

    Castlery is a digitally native furniture brand that offers modern, high-quality furniture at accessible prices. Our mission is to reinvent how furniture is designed, produced, and delivered to create a seamless experience for customers worldwide. As we continue to scale our operations, ensuring the security and compliance of our information assets is...


  • Singapore Housing and Development Board Full time

    Description What the role is: The mission of Housing & Development Board (HDB) is to provide affordable, quality housing and a great living environment where communities thrive. To achieve its mission, HDB aims to be data‑driven to the core and adopt evidence‑based decision making in developing better housing policies service, improving service delivery...


  • Singapore Zurich Insurance Full time

    A great opportunity exists as APAC Information Security Risk & Compliance Consultant, reporting to APAC Information Security Risk & Compliance Lead. The APAC Information Security Risk & Compliance Consultant collaborates with compliance, security, and general IT risks to ensure that IT supports the business objectives of the group, while enforcing policy,...


  • Singapore Bank of Singapore Full time

    Bank of Singapore SingaporePosted 2 hours ago Permanent Competitive - Information Security & Digital Risk (Associate Director) - At Bank of Singapore, we are constantly on the lookout for exceptional individuals to join our team. We promote a culture of openness, teamwork and fairness. Most importantly, we invest in our people through our programmes that...

  • Information Security

    2 weeks ago


    Singapore Bank of Singapore Full time

    At Bank of Singapore, we are constantly on the lookout for exceptional individuals to join our team. We promote a culture of openness, teamwork and fairness. Most importantly, we invest in our people through our programmes that develop them on both professional and personal levels. Besides attractive remuneration packages, we offer non-financial benefits and...


  • Singapore SSquad Global Full time $60,000 - $65,000 per year

    On-Premises GRC (Governance, Risk and Compliance) Analyst - (Associate level and not SME level)Governance & Compliance "Develop, implement, and maintain security policies, procedures, and standards in line with industry best practices (ISO 27001, NIST, CIS, etc.).Ensure compliance with regulatory requirements (MAS TRMG, CCoP).Assist in internal audits and...


  • Singapore TENTEN Partners Pte. Ltd. Full time

    **Key Responsibilities**: - Conduct IT Security Risk Assessments. - Manage third party Information Security Due diligence. - Identify and mitigate Tech Obsolescence Risks. - Collaborate with stakeholders to ensure security risks are identified and communicated. - Support IT Security risk committees for robust governance. - Develop and maintain IT Security...


  • Singapore ERGO Insurance Pte. Ltd. Full time

    **Information Security Risk Officer** ERGO Insurance Pte. Ltd. is a registered general insurer regulated by the Monetary Authority of Singapore. We are a wholly owned Singapore subsidiary of ERGO Group AG, one of the major insurance groups in Germany and Europe, and we are the primary insurance arm of Munich Re, one of the leading reinsurers and risk...