

Search by job, company or skills

The GRC Lead is a newly created, group-level role responsible for building and operationalising the organisation's cybersecurity governance, risk, and compliance capabilities from the ground up. This role will define foundational policies, frameworks, and risk management processes while enabling scalable and sustainable security governance across the group.
You will take a hands-on approach to design, implement, and embed governance structures, risk processes, and supporting GRC tooling. The role partners closely with technology, security, legal, audit, and business stakeholders to establish clear accountability, control visibility, and risk-informed decision-making.
Responsibilities:
GRC Strategy & Foundations
Cyber Risk Management
Compliance, Assurance & Audit Readiness
GRC Tooling & Process Enablement
Third-Party & Operational Risk Governance
Stakeholder Engagement & Change Enablement
Requirements:
To apply:
If you're interested to apply or find out more, please share across your CV or reach out to Chen Yi at [Confidential Information] for a discussion. Due to anticipated high volume of applications, we regret to inform that only shortlisted candidates will be notified.
Reg: R1876389
Lic: 16S8060
Job ID: 138934277
Skills:
Penetration Testing, Iso 27001, Vulnerability Management, MAS TRM Guidelines, Cyber Hygiene, NIST Framework, Governance, Risk Assessment, Regulatory Requirements, Compliance, security policy development
Skills:
Pci Dss, cloud security, Vulnerability Management, Soc, DevSecOps, Iso 27001, Siem, automation, PDPA, Ai, CIS, threat detection and response, continuous control monitoring, nist
Skills:
Itil, MAS CCOP regulations, Industry practices, Governance risk management, CI CD, DevSecOps methodologies, Cybersecurity frameworks, Cyber and IT standards, Hybrid cloud environments, Regulatory and legal requirements, Audit execution, Policy review oversight, Cobit, Payment Services Act, Architecture of secure scalable and resilient solutions, Risk management methodologies, Emerging security standards and solutions
Skills:
network security, Identity And Access Management, automation, Data Protection, ISO IEC 27001, cybersecurity governance, NIST CSF, agentic AI, risk management, CIS Controls, control frameworks, cloud platforms