Cybersecurity GRC Consultant (Full-Time) #IAC
Summary
The consultant conducts cybersecurity risk and compliance assessments, reviews governance frameworks, and supports ISO 27001 implementation and audits for clients. Core frameworks include ISO 27001, NIST, and IEC 62443.
Job Responsibilities
- Conduct cybersecurity risk assessments and compliance gap assessments.
- Review clients’ cybersecurity governance frameworks, policies, procedures, and controls.
- Develop and maintain cybersecurity risk registers, treatment plans, remediation trackers, and compliance matrices.
- Support the implementation and maintenance of information security management systems.
- Assess cybersecurity controls through interviews, document reviews, walkthroughs, and evidence validation.
- Prepare cybersecurity policies, standards, procedures, guidelines, and supporting templates.
- Support internal audits, external audits, certification consultancy, and regulatory reviews as needed.
- Assist clients in preparing for cybersecurity certifications, customer assessments, and compliance obligations.
- Conduct third-party cybersecurity risk assessments and security due diligence.
- Track audit findings, compliance gaps, corrective actions, and risk treatment activities.
- Prepare assessment reports, management presentations, dashboards, and executive summaries.
- Facilitate workshops and meetings with business owners, system owners, technical teams, and management.
- Provide practical recommendations to improve cybersecurity governance, risk management, and control effectiveness.
- Support proposal preparation, project planning, and other cybersecurity consulting activities.
- Any other ad-hoc duties as assigned by supervisor
Relevant Standards and Frameworks
The role may involve working with recognized cybersecurity standards and frameworks,including:
- ISO/IEC27001;
- NIST Cybersecurity Framework;
- IEC 62443;
- Secure-by-Design principles;
- Data protection and privacy requirements;
- Singapore cybersecurity regulations and industry requirements;
- Client-specific security and contractual obligations.
Requirements
- Relevant professional certifications will be advantageous, including: CISSP; CISM; CISA; CRISC; ISO/IEC 27001 Lead Implementer; ISO/IEC 27001Lead Auditor;
- Experience conducting cybersecurity risk assessments or compliance reviews.
- Experience developing cybersecurity policies, procedures, and risk registers.
- Experience supporting ISO/IEC 27001 implementation, certification, or audit activities.
- Experience with regulatory, customer, or third-party security assessments.
- Experience working in consulting, professional services, government, critical infrastructure, financial services, healthcare, technology, or other regulated sectors.
- Experience managing client stakeholders and preparing professional consulting deliverables.
Interested applicants, please email your resume to Andre Chua Jing Ming
Email: andrechua@recruitexpress.com.sg
CEI Reg No: R1989053
EA Licence No: 99C4599
Recruit Express Pte Ltd