Consultant - IT Governance, Risk, Compliance and Enterprise Security Architect
The ITSEC GroupCompany Description
The ITSEC Group is one of the leading cybersecurity groups in the Asia Pacific region, with offices in Singapore, Indonesia, Australia, United Arab Emirates and Mauritius. Our company specializes in providing comprehensive IT security services to businesses across industries. We are committed to ensuring the safety and protection of our clients' digital assets.
Role Description
This is a full-time role for a Consultant - IT Governance, Risk & Compliance. The consultant will be responsible for managing and overseeing IT governance, risk, and compliance activities. This includes conducting risk assessments, developing policies and procedures, and implementing risk mitigation strategies. The consultant will also provide guidance on regulatory compliance and ensure adherence to industry standards. This role is based in Singapore with flexibility for some remote work.
The Candidate will also be involved in the entire project lifecycle of certain IT system and shall be responsible for interpreting the security requirements, designing and implementing the system security architecture, assessing the risks from deviations and non-compliances, as well as supporting security acceptance tests and continual security assessments.
The Candidate must act with credibility and neutrality and possess the following professional qualification and experience:
a. minimum six (6) years of experience in designing, implementing and testing system security architecture of similar scale; OR
b. minimum two (2) years of experience in designing, implementing and testing system security architecture of similar scale – plus having attained at least one (1) of the following:
i. Information Security Masters degree from U.S. National Centres of Academic Excellence in Cyber Defence (NSA/DHS CAE) or those certified by U.K. National Cyber Security Centre (GCHQ’s NCSC); or
ii. CREST Registered Technical Security Architect (CRTSA); or
iii. Information Systems Security Architecture Professional (CISSP-ISSAP).
Minimum Qualifications
- Strong knowledge of IT governance, risk management, and compliance frameworks
- Experience in conducting risk assessments and developing risk mitigation strategies
- Experience in Network and System Security Engineering and Enterprise Security Architectural Design
- Familiarity with relevant regulatory requirements and industry standards
- Excellent problem-solving and analytical skills
- Strong communication and interpersonal skills
- Ability to work independently and collaboratively in teams
- Certifications such as CISSP and CRISC are highly preferred
- Minimum of 5 years of experience in IT governance, risk, and compliance roles
- Bachelor's or master's degree in IT, Computer Science, or a related field
- Had been approved for security clearance (CAT 1 or 2) on other government project