JOB PURPOSE:
The position is responsible for defining, implementing, and continuously improving
enterprise-wide cybersecurity requirements and governance. This role is responsible for
leading and enabling risk-informed decision making for the overall cybersecurity
landscape by utilising a risk-led and threat-informed approach. It is expected that all
definitions and communication of cybersecurity governance across the enterprise should
include timely management reports on security posture and controls applied.
Responsibilities:
- Implementation of cybersecurity framework in accordance with industry standards and best
- practices to ensure they are up to acceptable industry standards and reasonable assurance of
- security of the computing environment.
- Manage cybersecurity operations, including internal and external stakeholders.
- Produce and give cybersecurity governance reports as necessary.
- Consistently monitoring and being aware of industry standard best practices, such as NIST, and conducting gap analysis on current governance are necessary.
- Maintain and enforce IT-related corporate policies and SOPs to ensure proper governance and
- compliance.
- Liaise with other departments such as risk management, quality management, administration,
SHE and external parties such as external auditors, security solution providers and industry
practitioners to carry out the relevant governance and security activities.
- Develop soft skills and technical competencies required for team members for them to
perform current tasks for sustainable capabilities and continuous improvement.
- Manage periodic security activities such as awareness & training program and vulnerability
- management.
- Provide consultancy or advisory services to other business units pertaining to IT governance,
- policy, standards, SOPs and security considerations when required.
Requirement:
- Previously held a role in cybersecurity with a proven track record in managing cyber risks and
- governance.
- Bachelor's degree in IT, ICT, MIS, Computer Engineering or related fields with a minimum of
seven (7) years of related work experience.
- Having CISSP, CISA, or CISM certification is an added advantage, along with knowledge of
relevant industry standards and frameworks such as NIST, CoBIT, ISO/IEC, 27k, and ITIL.
- Proficiency in various security tools, systems, and technologies.
- Excellent communication skills in writing and speaking.