VP/AVP, Cybersecurity (Governance, Risk and Compliance)
Location:
SG
Group:
Department:
Section:
Job Type:
Req ID:
Overview of the Team
You'll be working in the Cybersecurity Department under the Governance, Risk, and Compliance unit, which reports directly to the CISO.
The increasing reliance of businesses on technology means that cybersecurity and IT risk management is a strategically important function within Temasek. The continuous enhancement and implementation of an effective governance and risk management framework to manage technology, data security, and cyber risks across the enterprise will enable Temasek to be better prepared to mitigate and manage these risks in the face of evolving cybersecurity threats.
Roles & Responsibilities
- The role will work closely with the CISO to carry out independent oversight and continuous monitoring of technology and business units' compliance with the cyber and IT risk management (TRM) policies and standards.
- Formulate and maintain cybersecurity and IT risk managementpolicies and standards, third-party vendor management as well as system criticality frameworks for the firm to ensure effective IT risk compliance and cyber defence .
- Modernise and optimize conduct of governance and oversight role through adoption of new/emerging technology and application to enable real-time update and maintenance of risk register, third party vendor assessment, leveraging on advanced analytics for trending and compliance monitoring
- Ensure the conduct of risks assessment and implementation of secure System Development Life cycle (SDLC) by Technology and Business units in their development and maintenance of IT infrastructure and applications
- Conduct periodic and ad-hoc assessments to monitor compliance with cybersecurity and technology policies and security controls design and operating effectiveness; review cybersecurity and technology risks; audit and operational risk issues to identify root causes and trends, and recommend appropriate remediationProvide independent IT and cyber risk management advice to the business, technical & operations groups to contribute towards secure implementation of technology initiatives
- Drive the review and enhancement of third party vendor risk management and establish a holistic framework and structure to manage this risk
- Contribute to assessment of vendor risks via pre-contract due diligence processes and ensure development of mitigation plans by Business units
- Identify and assess the impact of technology risks on projects and ensure effective controls are established by business/technology units to mitigate technology risks arising from change requests, new initiatives and processes
- Identify and assess emerging risks, and devise effective mitigating controls together with stakeholders
- Proactively partner risk owners and manage risks to minimize impact from incidents, breaches or non-compliance
- Deliver technology risk oversight to CISO and Senior Management using data-driven risk reports and ensure maintenance of cyber risk register
- Conduct regular communication and refresher trainings to maintain a good level of cybersecurity and information risk awareness
- Support incident response and carry out any other tasks as assigned
Requirements
- At least 9 years of relevant experience in the field of cybersecurity and IT risk management, policy formulation, governance oversight, audits and risk management
- Bachelor degree (and higher) in information security, engineering, cybersecurity and related field. Professional information security certifications such as CISA, CRISC, CISSP, CCSK/CCSP, CGEIT, CDPSE, an advantage
- Possess strong prior experience and knowledge in cyber and IT standards and policy review, oversight and governance, risk management and audit. Experience in cyber strategy and policy formulation and cyber programme execution will be an advantage
- Strong technical background is important, with proven ability in technical security design and implementation
- Possess cyber domain knowledge across areas such as AI, cybersecurity technology architecture and solutioning, SOC/MSS, application & infrastructure security, data & information protection, supply chain security, cyber architecture, quantum, cloud computing security and has knowledge of cyber regulations and compliance
- Good knowledge in industry security practices, frameworks, and standards such as MAS TRM, ISO27001, Cybersecurity Code of Practice, and NIST Cybersecurity Framework including emerging AI related requirements and standards
- Strong communication, interpersonal and leadership skills, with proven ability to manage multiple priorities, drive project teams and collaborate across business units and partners to achieve desired end-goals.
Soft Skills
- Possess an inquisitive, structured, and logical mind to conduct governance and oversight activities
- Strong analytical and problem-solving abilities
- Ability to lead oversight activities as well as work independently to review, assess and manage risks and non-compliances
- Excellent cross-group and interpersonal skills, with the ability to communicate with technical and non-technical teams
- Excellent communication, presentation, and advisory skills, capable of engaging senior stakeholders
- Result-oriented and assertive