Hiring.Camp

[PUB-IDTD] Sr/Cybersecurity Analyst, Governance, Compliance and Audit

Sggovterp

·

Today

Location
PUB - WATERHUB OFFICE BLK #04-01, Singapore
Type
Full-time
Department
IT
Education
Bachelor
Closing date
Today
Source
Workday

Description

[What the role is]

This role is with the InfoTech & Digital Transformation Department at PUB

[What you will be working on]

Governance and Policy

  • Ensure and continuously enhance the governance, resilience, and integrity of PUB's IT and OT systems against evolving cyber threats
  • Communicate, implement, and enforce information security policies, standards, and procedures in accordance with best practices and regulatory requirements from CSA and GovTech
  • Promote a cyber-vigilant culture across PUB through awareness campaigns
  • Leverage automation tools and streamlined processes to facilitate consistent compliance with cybersecurity policies

Risk Management

  • Advise senior management on risk prioritisation, the consequences of various risk management strategies, and the effectiveness of specific security measures
  • Translate technical security deficiencies into business risks that are clearly understood by non-technical stakeholders, in order to secure buy-in for security investments
  • Develop and maintain risk management and mitigation plans for both IT and OT environments

Compliance and Documentation

  • Monitor the effectiveness of security controls, and ensure compliance with documented standards, policies, and procedures
  • Monitor and track risk mitigation measures and enforce compliance with cybersecurity policies
  • Ensure PUB has developed, documented, and kept current its Business Impact Analysis, System Security Plans, Risk Assessments, Risk Treatment Plans, and other information security documentation

Audit and Reporting

  • Generate cybersecurity hygiene and audit reports for PUB Senior Management and relevant stakeholders
  • Support and manage various internal and external audit activities from planning through to remediation
  • Identify systemic weaknesses surfaced through audit findings and propose feasible solutions to address them, ensuring root causes are addressed with substantive fixes

[What we are looking for]

Requirements

  • Bachelor's Degree in Electrical/Electronic or Computer Engineering, Information Systems, Computer Science, or an equivalent discipline
  • Strong understanding of cybersecurity controls, best practices, technology processes, risk assessments, and cybersecurity policies (e.g. Cybersecurity Code of Practice for CII, Instruction Manual on IT Management)
  • Ability to work effectively across both technical teams and business stakeholders
  • Prior relevant experience related to IT or OT cybersecurity is advantageous
  • Professional certifications such as GIAC, CISSP, CISA, or CISM are advantageous

Skills

CybersecurityRisk ManagementComplianceCISSP