jobs in Progression Search

Progression Search Hiring! Full Time Security Compliance Manager in - Ricebowl

Security Compliance Manager

Progression Search

Undisclosed

Singapore

Share
Save

Working Location

  • Singapore

Job Description

Responsibilities

JOB OVERVIEW


The Security & Compliance Manager is responsible for the governance of Service Provider infrastructure-layer security operations and the Customer's regulatory and audit evidence pipeline under the Managed Services Statement of Work.


The role serves as the primary point of accountability for translating security operations, compliance, audit, and regulatory support requirements into a consistent, defensible, and auditable operating model.


The role will work closely with the Customer's security, risk, audit, and compliance functions to ensure operational security controls are effectively delivered, monitored, evidenced, and reviewed.

The Service Provider is responsible for operational execution and governance within its scope. Security risk acceptance, cyber incident ownership, security policy decisions, and regulatory accountability remain with the Customer's designated security function.


RESPONSIBILITIES


Security, Compliance & Governance

  • Own delivery of the Compliance and Audit Support Tower, including operational evidence such as logs, service-level reports, change records, backup/restore evidence, DR test reports, and vulnerability remediation records.
  • Support compliance with MAS Technology Risk Management requirements and other applicable APAC regulatory and outsourcing frameworks.
  • Act as the Service Provider's primary point of contact for Customer and regulatory audits and inspections, including routine and ad hoc audits.
  • Chair or co-chair Security Reviews and PKI/PAM Governance Reviews, and represent security and compliance matters at Quarterly Business Reviews and Disaster Recovery Readiness Reviews.
  • Maintain the personnel-vetting register and segregation-of-duties matrix, ensuring required pre-employment checks are completed before production access is granted.
  • Oversee subcontractor/offshore resource disclosures and outsourced-service-provider control reviews covering security, network, backup, and DR.
  • Maintain required security certifications for personnel delivering Managed Services and support security enablement and knowledge-transfer activities.
  • Provide operational input into the Customer's annual Information Security Policy review.


Privileged Access & Identity Management

  • Own the operational administration and governance of the CyberArk or equivalent PAM platform, including PSM/CPM health checks, credential reconciliation, access changes, audit-log reviews, incident/change management, backup/restore, DR testing, capacity and performance monitoring, and vendor coordination.
  • Coordinate daily, weekly, monthly, quarterly, and annual PAM operational activities, including privileged-access reviews and recertification support.
  • Administer HSM Security/Crypto Officer role assignments, RBAC configuration, and privileged-access review support in accordance with the Customer-approved access model.
  • Perform day-to-day Azure AD/Entra ID administration, including user and role administration, identity governance, conditional-access implementation, and identity-security-score remediation.
  • Support Customer-led security investigations and access governance activities.


PKI, HSM & Cryptographic Operations

  • Administer the Microsoft Internal Certificate Authority (AD CS) environment, including Root CA, Issuing CA, certificate issuance, renewal, revocation, CRL/AIA publication, monitoring, backup/restore, DR, patching, and incident management.
  • Manage certificate lifecycle activities and provide certificate-expiry, CA-health, and audit reporting.
  • Coordinate the logical and cryptographic operation of HSM and key-management systems.
  • Execute the Thales KMS/HSM key lifecycle, including generation, import/export, rotation, activation/deactivation, suspension/revocation, archival, and destruction under Customer-approved policy and quorum controls.
  • Perform HSM/KMS platform administration, HA/failover testing, capacity monitoring, application onboarding, backup/DR, and operational incident management.


Security Monitoring & Vulnerability Management

  • Ensure SIEM log forwarding is maintained for all agreed devices and manage infrastructure-layer log integration and alert correlation.
  • Perform scheduled Tenable or equivalent vulnerability scans, track approved remediation items to closure, and maintain the vulnerability remediation/exception register.
  • Apply approved OS and device-level patches according to agreed severity thresholds and maintenance windows.
  • Operate Microsoft Defender or equivalent endpoint security/antivirus agents, monitoring agent health and signature currency.
  • Coordinate quarterly privileged-access and firewall-rule reviews.
  • Maintain required security, vulnerability, backup, restore, and DR evidence.


REQUIREMENTS


  • Strong experience in security and compliance governance within an enterprise, outsourced, or managed-services environment.
  • Strong understanding of MAS Technology Risk Management requirements and experience supporting regulatory, customer, or third-party audits.
  • Hands-on experience with CyberArk PAM, preferably including PSM/CPM administration and operational governance.
  • Strong working knowledge of PKI, Microsoft Active Directory Certificate Services (AD CS), certificate lifecycle management, HSM/KMS, and cryptographic key management.
  • Hands-on experience with Thales KMS/HSM or equivalent enterprise cryptographic platforms.
  • Working knowledge of Azure AD/Entra ID, identity governance, conditional access, and privileged identity administration.
  • Experience with SIEM integration/log forwarding and vulnerability management tools such as Tenable.
  • Familiarity with Microsoft Defender or equivalent endpoint security solutions.
  • Experience establishing and maintaining segregation-of-duties, personnel-vetting, privileged-access, and audit controls.
  • Strong stakeholder management and governance skills, with the ability to work across Customer, Service Provider, security, risk, audit, and compliance teams.
  • Strong documentation, reporting, and audit-evidence management skills.
  • Relevant professional certification such as CISSP, CISM, CISA, or equivalent.


GOOD TO HAVE


  • Experience working with financial institutions, banking, or other highly regulated industries.
  • Experience with APAC regulatory and outsourcing frameworks such as BNM, HKMA, or equivalent.
  • Experience managing regulator-led audits or on-site inspections.
  • Experience in large-scale managed services, cloud, data centre, or outsourced IT environments.
  • Experience with CyberArk EPV/PVWA, Microsoft AD CS, Thales HSM/KMS, Tenable, SIEM, and Microsoft Defender in complex enterprise environments.
  • Experience with disaster recovery, business continuity, backup/restore testing, and operational resilience.
  • Knowledge of security frameworks and standards such as ISO 27001, NIST, or similar.
  • Additional relevant certifications such as CRISC, CCSP, ISO 27001 Lead Implementer/Auditor, or equivalent.


Important Information

Never provide your bank or credit card details when applying for jobs. Do not transfer any money or complete unrelated online surveys. If you see something suspicious, Report this Job ad.

Learn More