Make an Impact by
- Plan, manage and perform cybersecurity compliance review on Singtel Group’s Infrastructure, systems and applications.
- Evaluate the effectiveness and compliance level of internal security controls, identify areas of improvements, root cause analysis and provide sound recommendations for remediation.
- Prepare cybersecurity compliance review report to apprise BU stakeholders and senior management.
- Manage and review compliance review reports carried out by independent party and provide guidance for improvement.
- Monitor identified security gaps arising from Internal Audit and Compliance Review till closure. Report non-performance for necessary corrective actions by business owners for timely closure and risk mitigation.
- Develop and maintain excellent working relationships with BU stakeholders, BU Chief Information Officers (CISOs) / Business Information Security Officers (BISOs), internal audit department and other key stakeholders at the Group level to ensure compliance with cybersecurity risk mitigated to acceptable levels.
- Review the risk registers of common security gaps, controls and recommendation knowledge database to drive consistency in the delivery of the compliance service.
- Identify and implement initiatives to improve and optimise the programs by leveraging on digital solutions, data analytics, automation and industry practices.
- Provide feedback loop to security and data protection policy owners to keep policy requirements relevant and up to date with emergent cyber threats and regulatory landscape.
- Perform cybersecurity due diligence compliance review for Merger and Acquisition (M&A) support to GCR or other Singtel Group BU as needed.
- Provide support for CSRC Secretariat administrative activities (e.g., meeting support, minutes writing)
Skills for Success
- Bachelor Degree in Computer Science, Computer Engineering, Electrical Engineering, or other relevant field of study.
- Professional security management certifications such as a Certified Information Systems Security professional (CISSP), Certified Information Security Manager (CISM), Certified Information System Auditor (CISA) or other equivalent credentials, is required.
- Minimum 5 years and preferably in at least one or more areas inCybersecurity compliance review
ICT security audit
Cybersecurity risk assessment
Governance, risk and compliance
- Good technical understanding in the following areas: Platform Security, Data Security, Cloud Security, Infrastructure Security, Network Security, Physical Security, Security Assessment Tools, Security Monitoring Tools.
- Strong understanding of Technology Compliance, IT Security risk, Audit and information security principles
- Strong understanding of regulatory requirements and information security standards such as IMDA Code of Practice for broadcasting and telecommunications, MAS TRM, PCI-DSS CIS Controls, NIST, ISO27001, and OWASP.
- Critical thinking and Team player
- Effective communication and written skills