Senior Associate Engineer (Cyber Security)- 1 year contract
Job Purpose
- Act as the day-to-day custodian of NLT's cybersecurity Governance, Risk and Compliance (GRC) programme, ensuring policies, controls and regulatory obligations are implemented, monitored and sustained.
- Provide management with assurance that cybersecurity risks and control gaps are identified, assessed, treated and tracked through to closure.
- Serve as the coordination point between IT, business units, external service providers and assessors for cybersecurity assessments, audits and remediation activities.
- Maintain a complete and defensible set of cybersecurity documentation and evidence to support audits, regulatory reviews and management reporting.
- Build a security-aware culture across the organisation through training, communication and stakeholder engagement.
Responsibilities :
- Develop and maintain cybersecurity policies,standards, procedures, guidelines and governance documents, and drive theirperiodic review and approval.
- Monitor and report on compliance with cybersecuritypolicies, standards and regulatory requirements, escalating breaches,exceptions and approved deviations.
- Maintain compliance trackers, risk registers andremediation logs, driving control gaps, audit findings, risk treatment actionsand vulnerabilities through to closure.
- Support cybersecurity risk assessments for systems ,applications, projects and third-party service providers, and assist in developing risk mitigation strategies.
- Perform control reviews, access reviews and policy compliance checks, including validation of supporting evidence.
- Coordinate cybersecurity assessments — including VAPT, source code reviews, architecture reviews, threat modelling and configuration reviews — with internal stakeholders and external service providers, from scoping through to closure of findings, escalating delays or issues where necessary.
- Support internal and external audits, regulatory reviews, maturity assessments and certification activities, including managing evidence requests and coordinating responses with stakeholders.
- Prepare management reports, dashboards, committee materials, meeting records and briefing documents.
- Support incident documentation, lessons learnt and post-incident action tracking.
- Any other duties as per assigned.
Requirements:
- Minimum Bachelor's degree in Computer Science, Information Technology,Cybersecurity, Information Systems or a related discipline
- Minimum 2 years' experience in Cybersecurity or in a similar GRC, audit,risk or compliance role.
- Working knowledge of cybersecurity GRC concepts and frameworks (e.g. ISO27001, NIST CSF, MAS TRM / CCOP 2.0 / relevant local regulatory guidelines) and sound understanding of cybersecurity principles and best practices.
- Excellent written and verbal communication, documentation and presentation skills, with the ability to work collaboratively across cross-functional teams and with external service providers.