Cybersecurity GRC Consultant (Full-Time) #IAC
Job Responsibilities
- Conduct cybersecurity risk assessments and compliance gap assessments.
- Review clients’ cybersecurity governance frameworks, policies, procedures, and controls.
- Develop and maintain cybersecurity risk registers, treatment plans, remediation trackers, and compliance matrices.
- Support the implementation and maintenance of information security management systems.
- Assess cybersecurity controls through interviews, document reviews, walkthroughs, and evidence validation.
- Prepare cybersecurity policies, standards, procedures, guidelines, and supporting templates.
- Support internal audits, external audits, certification consultancy, and regulatory reviews as needed.
- Assist clients in preparing for cybersecurity certifications, customer assessments, and compliance obligations.
- Conduct third-party cybersecurity risk assessments and security due diligence.
- Track audit findings, compliance gaps, corrective actions, and risk treatment activities.
- Prepare assessment reports, management presentations, dashboards, and executive summaries.
- Facilitate workshops and meetings with business owners, system owners, technical teams, and management.
- Provide practical recommendations to improve cybersecurity governance, risk management, and control effectiveness.
- Support proposal preparation, project planning, and other cybersecurity consulting activities.
- Any other ad-hoc duties as assigned by supervisor
Relevant Standards and Frameworks
The role may involve working with recognized cybersecurity standards and frameworks,including:
- ISO/IEC27001;
- NIST Cybersecurity Framework;
- IEC 62443;
- Secure-by-Design principles;
- Data protection and privacy requirements;
- Singapore cybersecurity regulations and industry requirements;
- Client-specific security and contractual obligations.
Requirements
- Relevant professional certifications will be advantageous, including: CISSP; CISM; CISA; CRISC; ISO/IEC 27001 Lead Implementer; ISO/IEC 27001Lead Auditor;
- Experience conducting cybersecurity risk assessments or compliance reviews.
- Experience developing cybersecurity policies, procedures, and risk registers.
- Experience supporting ISO/IEC 27001 implementation, certification, or audit activities.
- Experience with regulatory, customer, or third-party security assessments.
- Experience working in consulting, professional services, government, critical infrastructure, financial services, healthcare, technology, or other regulated sectors.
- Experience managing client stakeholders and preparing professional consulting deliverables.
Interested applicants, please email your resume to Andre Chua Jing Ming
Email: [email protected]
CEI Reg No: R1989053
EA Licence No: 99C4599
Recruit Express Pte Ltd