Cybersecurity Consultant

Summary

A cybersecurity consultant assesses risks, ensures compliance with frameworks like ISO 27001, and advises clients on governance and controls in Singapore.

Job Overview

We are looking for a Cybersecurity Consultant with a focus on Governance, Risk and Compliance to support client engagements involving cybersecurity risk management, regulatory compliance, security governance, audit readiness, and policy development.

The successful candidate will work closely with clients, management, technical teams, auditors, and other stakeholders to assess cybersecurity risks, identify control gaps, develop practical recommendations, and support the implementation of cybersecurity frameworks and improvement programmed.

This role is suitable for candidates with experience in cybersecurity consulting, information security governance, risk management, compliance, internal audit, or related advisory functions.

Key Responsibilities

  • Conduct cybersecurity risk assessments and compliance gap assessments.
  • Review clients’ cybersecurity governance frameworks, policies, procedures, and controls.
  • Develop and maintain cybersecurity risk registers, treatment plans, remediation trackers, and compliance matrices.
  • Support the implementation and maintenance of information security management systems.
  • Assess cybersecurity controls through interviews, document reviews, walkthroughs, and evidence validation.
  • Prepare cybersecurity policies, standards, procedures, guidelines, and supporting templates.
  • Support internal audits, external audits, certification consultancy, and regulatory reviews as needed.
  • Assist clients in preparing for cybersecurity certifications, customer assessments, and compliance obligations.
  • Conduct third-party cybersecurity risk assessments and security due diligence.
  • Track audit findings, compliance gaps, corrective actions, and risk treatment activities.
  • Prepare assessment reports, management presentations, dashboards, and executive summaries.
  • Facilitate workshops and meetings with business owners, system owners, technical teams, and management.
  • Provide practical recommendations to improve cybersecurity governance, risk management, and control effectiveness.
  • Support proposal preparation, project planning, and other cybersecurity consulting activities.

Relevant Standards and Frameworks

The role may involve working with recognized cybersecurity standards and frameworks, including:

  • ISO/IEC 27001;
  • NIST Cybersecurity Framework;
  • IEC 62443;
  • Secure-by-Design principles;
  • Data protection and privacy requirements;
  • Singapore cybersecurity regulations and industry requirements;
  • Client-specific security and contractual obligations.

Requirements

  • Diploma or degree in Cybersecurity, Information Technology, Computer Science, Information Security or a related discipline.
  • Relevant experience in cybersecurity consulting, governance, risk, compliance, audit, information security, or technology risk.
  • Good understanding of cybersecurity controls, risk management principles, compliance requirements, and security governance.
  • Ability to review policies, procedures, system documentation, and supporting evidence.
  • Strong report writing, documentation, analytical, and problem-solving skills.
  • Good communication and presentation skills.
  • Ability to explain cybersecurity risks and requirements to both technical and non-technical stakeholders.
  • Ability to manage multiple assignments and work independently or as part of a project team.
  • Strong attention to detail, professionalism, and commitment to confidentiality.

Preferred Qualifications

Relevant professional certifications will be advantageous, including:

  • CISSP;
  • CISM;
  • CISA;
  • CRISC;
  • ISO/IEC 27001 Lead Implementer;
  • ISO/IEC 27001 Lead Auditor;

Preferred Experience

  • Experience conducting cybersecurity risk assessments or compliance reviews.
  • Experience developing cybersecurity policies, procedures, and risk registers.
  • Experience supporting ISO/IEC 27001 implementation, certification, or audit activities.
  • Experience with regulatory, customer, or third-party security assessments.
  • Experience working in consulting, professional services, government, critical infrastructure, financial services, healthcare, technology, or other regulated sectors.
  • Experience managing client stakeholders and preparing professional consulting deliverables.

Key Competencies

  • Cybersecurity governance;
  • Risk assessment and risk treatment;
  • Regulatory and standards compliance;
  • Policy and procedure development;
  • Audit and assurance;
  • Third-party risk management;
  • Control assessment;
  • Stakeholder management;
  • Report writing and presentation;
  • Project coordination.

What We Offer

  • Exposure to diverse cybersecurity consulting projects and industries.
  • Opportunities to work with recognized cybersecurity standards and regulatory requirements.
  • Professional development and certification support.
  • Structured career progression within cybersecurity consulting.
  • Collaborative working environment with experienced cybersecurity professionals.

Additional Information

The role may require attendance at client offices, project sites, data centers, or operational facilities. Occasional travel or after-hours support may be required depending on project requirements.

All consultants are expected to maintain confidentiality, professional integrity, and compliance with approved project scope, client requirements, and organizational policies.