Cybersecurity Consultant (GRC) #IJO

Summary

A cybersecurity consultant focused on governance, risk, and compliance (GRC) who assesses clients’ security frameworks, develops risk registers, and ensures alignment with regulatory standards.

Key Responsibilities

  • Conduct cybersecurity risk assessments and compliance gap assessments.
  • Review clients’ cybersecurity governance frameworks, policies, procedures, and controls.
  • Develop and maintain cybersecurity risk registers, treatment plans, remediation trackers, and compliance matrices.
  • Support the implementation and maintenance of information security management systems.
  • Assess cybersecurity controls through interviews, document reviews, walkthroughs, and evidence validation.
  • Prepare cybersecurity policies, standards, procedures, guidelines, and supporting templates.
  • Support internal audits, external audits, certification consultancy, and regulatory reviews as needed.
  • Assist clients in preparing for cybersecurity certifications, customer assessments, and compliance obligations.
  • Conduct third-party cybersecurity risk assessments and security due diligence.
  • Track audit findings, compliance gaps, corrective actions, and risk treatment activities.
  • Prepare assessment reports, management presentations, dashboards, and executive summaries.
  • Facilitate workshops and meetings with business owners, system owners, technical teams, and management.
  • Provide practical recommendations to improve cybersecurity governance, risk management, and control effectiveness.
  • Support proposal preparation, project planning, and other cybersecurity consulting activities.
  • Other ad hoc duties as assigned.


Requirements

  • Diploma or degree in Cybersecurity, Information Technology, Computer Science, Information Security or a related discipline.
  • Relevant experience in cybersecurity consulting, governance, risk, compliance, audit, information security, or technology risk.
  • Good understanding of cybersecurity controls, risk management principles, compliance requirements, and security governance.
  • Ability to review policies, procedures, system documentation, and supporting evidence.
  • Ability to explain cybersecurity risks and requirements to both technical and non-technical stakeholders.
  • Ability to manage multiple assignments and work independently or as part of a project team.


Preferred Qualifications

  • CISSP;
  • CISM;
  • CISA;
  • CRISC;
  • ISO/IEC 27001 Lead Implementer;
  • ISO/IEC 27001 Lead Auditor;

Interested applicants, please Email, and look for joanneloo@recruitexpress.com.sg

Joanne Loo Sze Min

EA Personnel Registration Number: R26160686

Recruit Express Pte Ltd

Company Reg No. 199601303W

EA License No. 99C4599

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available