jobs in BIPO

BIPO Hiring! Full Time Information Security Specialist in - Ricebowl

Information Security Specialist

BIPO

Singapore

Share
Save

Working Location

  • Singapore

Job Description

Responsibilities

About this Role

This role works closely with the Deputy Director of Information Security in managing information security governance, compliance and security operations across BIPO’s global operations. The position has a primary focus on ISO 27001 ISMS, security audits and assurance, risk management and security awareness, while also supporting security operations including security monitoring, incident response and vulnerability management. The candidate should have strong hands-on experience in operating and maintaining an ISO 27001 ISMS, together with sufficient technical security knowledge to interpret security findings, coordinate remediation and support security operations when required.


Key Responsibilities

  • Maintain and continually improve BIPO’s ISO 27001 Information Security Management System (ISMS), including policies and procedures, risk register, risk treatment actions, ISMS records, security objectives and audit readiness.
  • Lead and coordinate information security audit and assurance activities, including ISO 27001, SOC 2, OSPAR and client security audits and assessments; coordinate gap assessments, evidence collection, remediation of identified gaps, audit activities and follow-up of findings with relevant stakeholders.
  • Act as the Singapore ISMS Representative and serve as backup for the Global ISMS Management Representative when required.
  • Coordinate information security risk assessments, maintain the risk register and track risk treatment actions through to closure.
  • Manage security awareness activities, including employee training, phishing simulations, role-based training and completion tracking.
  • Lead and facilitate cybersecurity incident response tabletop exercises, and support actual incident response, post-incident reviews and corrective-action tracking.
  • Coordinate client security assurance activities, including security questionnaires, due-diligence requests, security requirements in contracts and client security audits.
  • Prepare regular information security management reporting, covering security risks, audit and compliance status, vulnerabilities and remediation, security posture, awareness and significant security issues.
  • Support security operations when required, including security alert review, incident investigation, vulnerability management, penetration testing coordination and remediation follow-up, working with IT, R&D and external security service providers.


Requirements

  • Bachelor’s degree in information security, Cybersecurity, Computer Science or a related field, or equivalent relevant professional experience.
  • At least 4 years of relevant information security experience, with strong exposure to information security governance, risk and compliance.
  • Strong hands-on experience in operating and maintaining an ISO 27001 ISMS, including risk management, policies and procedures, audit preparation, findings management and remediation follow-up.
  • Experience coordinating information security audits or assurance activities such as ISO 27001, SOC 2, OSPAR or client security audits.
  • Good understanding of information security risk assessment, risk treatment and control implementation.
  • Good working knowledge of security operations, including vulnerability management, security monitoring and incident response.
  • Sufficient technical understanding of identity and access management, endpoint security, network security and cloud security to assess security issues and coordinate remediation with technical teams.
  • Good written and verbal communication skills, with the ability to work with technical teams, business stakeholders, auditors and customers.
  • Relevant certifications such as ISO 27001 Lead Implementer/Lead Auditor, CISM, CISA, CRISC or CISSP are an advantage.


Important Information

Never provide your bank or credit card details when applying for jobs. Do not transfer any money or complete unrelated online surveys. If you see something suspicious, Report this Job ad.

Learn More