Lead Consultant - Cybersecurity (GRC)
ACCESS PEOPLE (SINGAPORE) PTE. LTD.
On behalf of our client, an established technology consulting firm, we are seeking a Lead Consultant to join its Cyber Security Governance, Risk and Compliance team. The role covers policy and control framework development, regulatory mapping, risk and maturity assessments, and remediation planning for clients across regulated industries and the public sector.
Responsibilities
Develop, review and implement cybersecurity policies, standards, procedures and control frameworks for client organisations.
Translate regulatory and compliance obligations into practical governance processes, control statements and operating procedures that clients can adopt and evidence.
Own engagement deliverables end to end, including current state assessments, control gap analyses, risk registers, remediation roadmaps and executive reporting.
Map control sets across ISO 27001, NIST CSF and regional regulatory requirements such as MAS TRM and Cyber Hygiene, identifying overlaps, gaps and remediation priorities.
Conduct cyber risk assessments, maturity assessments and compliance reviews, including IM8, CCOP and ISO aligned reviews.
Work within GRC platforms such as Archer, ServiceNow GRC or OneTrust to operationalise control libraries, assessment workflows and reporting.
Facilitate workshops, stakeholder interviews and executive presentations, articulating risk exposure and recommendations to both technical and business audiences.
Manage multiple stakeholder groups across concurrent engagements and support quality review of junior colleagues' work.
Requirements
Experience in cyber security governance, risk and compliance, gained in consulting, advisory or an in house second line function.
Demonstrable track record of authoring policies, standards, control frameworks and client ready assessment deliverables, rather than executing audits alone.
Working knowledge of ISO 27001 and NIST CSF, with practical exposure to regional regulatory requirements such as MAS TRM and Cyber Hygiene.
Ability to interpret a regulatory requirement and express it as a specific, testable control, and to advise on remediation sequencing and priority.
Hands on experience with at least one GRC platform such as Archer, ServiceNow GRC, OneTrust or a comparable solution.
Experience conducting cyber risk assessments, maturity assessments and compliance reviews; exposure to IM8 and CCOP reviews is advantageous.
Confident communication and facilitation skills across workshops, stakeholder interviews and executive level presentations.
Relevant certifications such as CISSP, CISM, CRISC, CISA or ISO 27001 Lead Auditor / Lead Implementer are advantageous.
Reg No
R1981018 · EA Licence 14S7084