IT Security Consultant (GRC) #IJF
Summary
An IT Security Consultant (GRC) in Singapore who develops and enforces cybersecurity policies and governance frameworks, runs risk assessments and incident response across IT/OT environments, and drives security awareness, metrics, and compliance initiatives.
Job Summary
You will support and lead cybersecurity initiatives to develop policies, conduct risk assessments, manage incidents, and promote cybersecurity culture, ensuring robust protection of IT/OT environments aligned with organizational goals.
Responsibilities
- Develop, implement, and periodically review cybersecurity policies, standards, procedures, and governance frameworks to align with organizational requirements
- Monitor and enforce compliance with cybersecurity policies and standards across IT and OT environments
- Maintain and update cybersecurity documentation including policies, procedures, guidelines, risk registers, and system records to ensure accuracy and currency
- Conduct cybersecurity risk assessments and assurance reviews on IT and OT systems to identify vulnerabilities, threats, and control gaps
- Lead or support vulnerability management activities including assessments, remediation tracking, and reporting
- Provide technical support for implementing, administering, and maintaining cybersecurity technologies, platforms, and security controls
- Lead or support cybersecurity incident response, investigation, and recovery activities to minimize impact
- Coordinate post-incident reviews and recommend corrective actions to strengthen cybersecurity controls
- Support cybersecurity awareness programs, campaigns, and training initiatives to foster a strong cybersecurity culture organization-wide
- Facilitate cybersecurity exercises, simulations, and tabletop exercises to evaluate organizational preparedness
- Develop, monitor, and report cybersecurity metrics, key risk indicators (KRIs), and key performance indicators (KPIs) for management reporting
- Lead or support initiatives related to cybersecurity, data governance, and AI governance to enhance organizational security posture
- Undertake cybersecurity-related projects and perform other duties as assigned by the reporting manager
Required competencies
- Bachelor Degree or Diploma in Information Security or related field
- Minimum of 4 years relevant experience in cybersecurity roles
- Strong knowledge and understanding of IT infrastructure and security operations
- Knowledge of Endpoint Security, Intrusion Detection and Prevention Systems (IDPS), Web Application Firewall (WAF), Advanced Persistent Threats (APT), Firewalls (FW), and Cloud Security
- Experience working with cybersecurity policies, standards, procedures, and governance frameworks
Other Information
Interested applicants, please Email, and look for
Jensen Fang Lifa, jensenfang@recruitexpress.com.sg
Recruit Express Pte Ltd
EA License No. 99C4599
EA Personnel Registration Number: R2197080
We regret that only shortlisted candidates will be contacted.