
Governance, Risk and Compliance Specialist - 01
As a Governance Risk and Compliance Specialist to join our team, this role is crucial in developing and maintaining a robust culture of technology and cybersecurity risk governance across our organization.
The ideal candidate will have at least 5 years of relevant experience audit management, ICT governance and risk compliance management.
He or She will be responsible for providing expert advice on reviewing and establishing ICT policies and supporting various aspects of our tech governance framework.
In particular, the candidate is required to establish and operationalise testing strategies (including testing automation).
This role offers an opportunity to make a significant impact on our organization's ICT risk management and governance practices.
The successful candidate will work with cross-functional teams for maintaining the highest standards of cybersecurity and ICT compliance. Key Responsibilities •
Develop the culture of Tech risk governance and management across the organisation, and ensure proper accountability in the management, tracking and reporting of tech and cyber risks.
Develop and operationalise a sound and robust testing strategies, include test automation. •
Recommend the re-engineering and streaming of testing strategies and processes to enhance effectiveness of controls implemented.
Present management reporting to stakeholders, with analysis of data and trends, and recommend next steps.
Develop and operationalise a proactive audit management process and provide subject matter advice to internal stakeholders to comply with, including MAS’ internal policies and standards, as well as policies and standards from GovTech and Cyber Security Agency of Singapore.
Review and establish ICT policies and process controls and conduct compliance checks.
Enhance training and other materials in ICT risk management, document case studies and good practices. • Support team lead and work with internal stakeholders to:
Track and monitor tech projects and initiatives to meet compliance requirements.
Track and monitor of Key Risk Indicators and Control Self-Assessment as part of Tech governance framework. Track and monitor incident reporting, including reviewing, monitoring, and reporting on the corrective measures and improvement areas.
Participate in consultation and conduct gap analysis against new or revised requirements.
Assess and seek waiver approvals for deviations and risk treatment strategies.
Organise risk forums, including monitoring of action plans.
Track remediation plans to address audit findings.
Follow up on remediation actions, security and risk assessments with respective stakeholders and project and application managers.
What we are looking for
At least 5 years relevant experience in audit management, governance, risk and compliance management. • Relevant certifications in IT governance i.e. CISA.
Ability to work with cross-functional, multi-disciplined team to operationalise monitor security policies and procedures
Knowledge of Instruction Manual
Technical knowledge and practical experience in test executions
Relevant experience in data visualisation and analytics is preferred
As a Governance Risk and Compliance Specialist to join our team, this role is crucial in developing and maintaining a robust culture of technology and cybersecurity risk governance across our organization.
The ideal candidate will have at least 5 years of relevant experience audit management, ICT governance and risk compliance management.
He or She will be responsible for providing expert advice on reviewing and establishing ICT policies and supporting various aspects of our tech governance framework.
In particular, the candidate is required to establish and operationalise testing strategies (including testing automation).
This role offers an opportunity to make a significant impact on our organization's ICT risk management and governance practices.
The successful candidate will work with cross-functional teams for maintaining the highest standards of cybersecurity and ICT compliance. Key Responsibilities •
Develop the culture of Tech risk governance and management across the organisation, and ensure proper accountability in the management, tracking and reporting of tech and cyber risks.
Develop and operationalise a sound and robust testing strategies, include test automation. •
Recommend the re-engineering and streaming of testing strategies and processes to enhance effectiveness of controls implemented.
Present management reporting to stakeholders, with analysis of data and trends, and recommend next steps.
Develop and operationalise a proactive audit management process and provide subject matter advice to internal stakeholders to comply with, including MAS’ internal policies and standards, as well as policies and standards from GovTech and Cyber Security Agency of Singapore.
Review and establish ICT policies and process controls and conduct compliance checks.
Enhance training and other materials in ICT risk management, document case studies and good practices. • Support team lead and work with internal stakeholders to:
Track and monitor tech projects and initiatives to meet compliance requirements.
Track and monitor of Key Risk Indicators and Control Self-Assessment as part of Tech governance framework. Track and monitor incident reporting, including reviewing, monitoring, and reporting on the corrective measures and improvement areas.
Participate in consultation and conduct gap analysis against new or revised requirements.
Assess and seek waiver approvals for deviations and risk treatment strategies.
Organise risk forums, including monitoring of action plans.
Track remediation plans to address audit findings.
Follow up on remediation actions, security and risk assessments with respective stakeholders and project and application managers.
What we are looking for
At least 5 years relevant experience in audit management, governance, risk and compliance management. • Relevant certifications in IT governance i.e. CISA.
Ability to work with cross-functional, multi-disciplined team to operationalise monitor security policies and procedures
Knowledge of Instruction Manual
Technical knowledge and practical experience in test executions
Relevant experience in data visualisation and analytics is preferred