Act as the day-to-day custodian of NLT's cybersecurity Governance, Risk and Compliance (GRC) programme, ensuring policies, controls and regulatory obligations are implemented, monitored and sustained.
Provide management with assurance that cybersecurity risks and control gaps are identified, assessed, treated and tracked through to closure.
Serve as the coordination point between IT, business units, external service providers and assessors for cybersecurity assessments, audits and remediation activities.
Maintain a complete and defensible set of cybersecurity documentation and evidence to support audits, regulatory reviews and management reporting.
Build a security-aware culture across the organisation through training, communication and stakeholder engagement.
Responsibilities :
Develop and maintain cybersecurity policies,standards, procedures, guidelines and governance documents, and drive theirperiodic review and approval.
Monitor and report on compliance with cybersecuritypolicies, standards and regulatory requirements, escalating breaches,exceptions and approved deviations.
Maintain compliance trackers, risk registers andremediation logs, driving control gaps, audit findings, risk treatment actionsand vulnerabilities through to closure.
Support cybersecurity risk assessments for systems ,applications, projects and third-party service providers, and assist in developing risk mitigation strategies.
Perform control reviews, access reviews and policy compliance checks, including validation of supporting evidence.
Coordinate cybersecurity assessments - including VAPT, source code reviews, architecture reviews, threat modelling and configuration reviews - with internal stakeholders and external service providers, from scoping through to closure of findings, escalating delays or issues where necessary.
Support internal and external audits, regulatory reviews, maturity assessments and certification activities, including managing evidence requests and coordinating responses with stakeholders.
Prepare management reports, dashboards, committee materials, meeting records and briefing documents.
Support incident documentation, lessons learnt and post-incident action tracking.
Any other duties as per assigned.
Requirements:
Minimum Bachelor's degree in Computer Science, Information Technology,Cybersecurity, Information Systems or a related discipline
Minimum 2 years experience in Cybersecurity or in a similar GRC, audit,risk or compliance role.
Working knowledge of cybersecurity GRC concepts and frameworks (e.g. ISO27001, NIST CSF, MAS TRM / CCOP 2.0 / relevant local regulatory guidelines) and sound understanding of cybersecurity principles and best practices.
Excellent written and verbal communication, documentation and presentation skills, with the ability to work collaboratively across cross-functional teams and with external service providers.