Assistant/Deputy Manager (Data & Cybersecurity Governance)
Support and/or lead the development, implementation and periodic review of cybersecurity policies, standards, procedures and governance frameworks to ensure alignment with organisational requirements;
Monitor compliance with cybersecurity policies and standards across IT/OT environments;
Maintain cybersecurity-related documentation, including policies, procedures, guidelines, risk registers and system records, and ensure they remain current and accurate;
Conduct cybersecurity risk assessments and assurance reviews on IT/OT systems to identify vulnerabilities, threats and control gaps;
Support and/or lead vulnerability management activities, including vulnerability assessments, remediation tracking and reporting;
Provide technical support in the implementation, administration and maintenance of cybersecurity technologies, platforms and security controls;
Support and/or lead cybersecurity incident response, investigation and recovery activities;
Coordinate post-incident reviews and recommend corrective actions to strengthen cybersecurity controls;
Support cybersecurity awareness programmes, campaigns and training initiatives to promote a strong cybersecurity culture across the organisation;
Support and/or facilitate cybersecurity exercises, simulations and tabletop exercises to assess organisational preparedness;
Develop, monitor and report cybersecurity metrics, key risk indicators (KRIs) and key performance indicators (KPIs) for management reporting;
Support and/or lead initiatives relating to cybersecurity, data governance and AI governance;
Undertake cybersecurity-related projects and other duties as assigned by reporting manager.
Requirements
Degree in Cybersecurity, Information Technology, Computer Science, Engineering or a related discipline;
Minimum 4 years of relevant cybersecurity experience in IT/OT environment;
Strong knowledge and understanding of IT/OT security best practices, network security, application security, physical security and cybersecurity risk management;
Practical knowledge of one or more industry standards such as NIST CSF, ISO/ICE 27001, ISA/IEC 62443 and IACS UR E26/E27;
Possess relevant cybersecurity certifications or keen to pursue formal training from Microsoft, AWS, SANS, ISC2 would be advantageous;
AZ-900/500/305; AWS Foundational/Associate/Professional; GSEC/GSOC/GCIH; ISC2 CC/CCSP/CISSP etc
Good communication, analytical and problem-solving skills;
Ability to make sound professional judgment, objectivity, and integrity when making decisions and recommendations;
Proactive, self-motivated and able to work independently; and
Strong project management and coordination skills.