- Location
- PUB - WATERHUB OFFICE BLK #04-01, Singapore
- Type
- Full-time
- Department
- IT
- Education
- Bachelor
- Closing date
- Today
- Source
- Workday
Description
[What the role is]
This role is with the InfoTech & Digital Transformation Department at PUB[What you will be working on]
Governance and Policy
- Ensure and continuously enhance the governance, resilience, and integrity of PUB's IT and OT systems against evolving cyber threats
- Communicate, implement, and enforce information security policies, standards, and procedures in accordance with best practices and regulatory requirements from CSA and GovTech
- Promote a cyber-vigilant culture across PUB through awareness campaigns
- Leverage automation tools and streamlined processes to facilitate consistent compliance with cybersecurity policies
Risk Management
- Advise senior management on risk prioritisation, the consequences of various risk management strategies, and the effectiveness of specific security measures
- Translate technical security deficiencies into business risks that are clearly understood by non-technical stakeholders, in order to secure buy-in for security investments
- Develop and maintain risk management and mitigation plans for both IT and OT environments
Compliance and Documentation
- Monitor the effectiveness of security controls, and ensure compliance with documented standards, policies, and procedures
- Monitor and track risk mitigation measures and enforce compliance with cybersecurity policies
- Ensure PUB has developed, documented, and kept current its Business Impact Analysis, System Security Plans, Risk Assessments, Risk Treatment Plans, and other information security documentation
Audit and Reporting
- Generate cybersecurity hygiene and audit reports for PUB Senior Management and relevant stakeholders
- Support and manage various internal and external audit activities from planning through to remediation
- Identify systemic weaknesses surfaced through audit findings and propose feasible solutions to address them, ensuring root causes are addressed with substantive fixes
[What we are looking for]
Requirements
- Bachelor's Degree in Electrical/Electronic or Computer Engineering, Information Systems, Computer Science, or an equivalent discipline
- Strong understanding of cybersecurity controls, best practices, technology processes, risk assessments, and cybersecurity policies (e.g. Cybersecurity Code of Practice for CII, Instruction Manual on IT Management)
- Ability to work effectively across both technical teams and business stakeholders
- Prior relevant experience related to IT or OT cybersecurity is advantageous
- Professional certifications such as GIAC, CISSP, CISA, or CISM are advantageous
Skills
CybersecurityRisk ManagementComplianceCISSP