Track This Job
Add this job to your tracking list to:
- Monitor application status and updates
- Change status (Applied, Interview, Offer, etc.)
- Add personal notes and comments
- Set reminders for follow-ups
- Track your entire application journey
Save This Job
Add this job to your saved collection to:
- Access easily from your saved jobs dashboard
- Review job details later without searching again
- Compare with other saved opportunities
- Keep a collection of interesting positions
- Receive notifications about saved jobs before they expire
AI-Powered Job Summary
Get a concise overview of key job requirements, responsibilities, and qualifications in seconds.
Pro Tip: Use this feature to quickly decide if a job matches your skills before reading the full description.
Responsibilities:
GRC leadership & 2nd line of defence
- Act as the de facto lead for GRC, shaping how we govern risk and compliance across managed products and platforms within the team's remit
- Operate as 2nd line of defence for ICT risk and controls providing independent challenge on risk, control design, and effectiveness
- Partner closely with Product team to embed pragmatic security and compliance into day-to-day delivery
- Own the governance and standards for Security Plan submissions across CIOO and product teams - including templates, minimum evidence expectations, and quality benchmarks
- Review Security Plans and supporting evidence, assess control coverage and implementation maturity, and Recommendation of Security Plan approvals to the stakeholders
- Treat automation as an "always-on audit":
- Collaborate with product and platform teams to define the Security Plan evidence that should be checked automatically
- Use automated checks to surface gaps, anomalies, and missing evidence, and drive remediation with product teams
- Track and report KPIs for Security Plan (e.g. coverage and consistency of controls, Security Plan cycle time, defect rates) across CIOO and product teams
- Whether required work has been completed
- Whether evidence provided by product teams is sufficient and reliable
- Coordinate with internal audit (3rd line) on ICT/security audit engagements, facilitate evidence collection, and track closure of findings in the issue-tracking system
- Provide regular management reporting on audit status, key risks, and trends to CIOO leadership and the CISO
- Sandbox usage (development / test environments)
- AI coding practices and guardrails
- SaaS usage, onboarding, and clearance requirements
- Own the policy lifecycle: drafting, stakeholder consultation, impact assessment, approval routing, publication, and periodic review
- Translate policy into clear, practical guidance for product teams (e.g. how to comply in the issue-tracking and collaboration platforms, what "good" evidence looks like, what patterns and exceptions are acceptable)
- Monitor policy adoption and escalate material non-compliance or risk acceptances to the CISO where necessary
- Phishing simulations and follow-up actions
- Security newsletters tailored to different audiences (e.g. tech vs non-tech)
- Brown-bag sessions / clinics to deep-dive into topics like SaaS usage, sandboxing, secure coding, and incident reporting
- Define and track SeTA KPIs (e.g. phishing susceptibility, completion rates, engagement metrics) and use insights to continually refine content and focus areas
- standard issue-tracking and collaboration tools as the primary systems of record for audit and evidence
- automated controls and analytics for continuous, data-driven assurance
- Influence and negotiate with senior stakeholders (Product Directors, Application Owners, central functions) to adopt and sustain these new practices
- Communicate complex policy and risk topics in clear, outcome-focused language, tailored to both technical and non-technical audiences
- Provide clear, actionable recommendations to the CISO and CIOO leadership on risk, remediation priorities, and structural improvements
- Designing or running phishing simulations
- Producing newsletters or comms
- Delivering talks or briefings is a plus
- Comfortable working with automation and AI-enabled tools (such as enterprise search platforms) to scale GRC and audit work
- Excellent stakeholder management, influencing, and negotiation skills, with a track record of:
- Leading change in how teams work (e.g. moving to issue-tracking- and collaboration-based evidence and audit)
- Challenging assumptions respectfully
- Finding pragmatic, risk-aware compromises
The remuneration package will commensurate with your qualifications and experience. Interested applicants, please click "Apply Now".
We thank you for your interest and please note that only shortlisted candidates will be notified.
By submitting your application, you agree that your personal data may be collected, used and disclosed by Assurity Trusted Solutions Pte. Ltd. (ATS), GovTech and their service providers and agents in accordance with ATS's privacy statement which can be found at: https://www.assurity.sg/ or such other successor site.
Benefits
- A wholly-owned subsidiary of GovTech
- We promote a learning culture and encourage you to grow and learn
- Contract Staff enjoys the same benefits as Permanent Employees
Key Skills
Ranked by relevanceReady to apply?
Join Assurity Trusted Solutions Pte Ltd and take your career to the next level!
Application takes less than 5 minutes

