jobs in GTS Consulting

GTS Consulting Hiring! Full Time GRC, Senior Security Consultant in - Ricebowl

GRC, Senior Security Consultant

GTS Consulting

Singapore

Share
Save

Working Location

  • Singapore

Job Description

Responsibilities

We are seeking an experienced Cybersecurity Consultant specialising in Governance, Risk and

Compliance (GRC) to support the delivery of ISO/IEC 27001, CSA Cyber Essentials Mark

(CEM), CSA Cyber Trust Mark (CTM), Data Protection Trustmark (DPTM)/ SS 714, Threat

and Risk Assessment (TRA), and regulatory compliance engagements.

Reporting to the GRC Lead, you will work with clients to strengthen their cybersecurity

governance, prepare for audits and certifications, meet regulatory requirements, and develop

sustainable security capabilities.

You will collaborate closely with clients’ management and IT teams, as well as Stone

Cybersecurity’s penetration testing, Security Operations Centre (SOC), cloud security, and

security architecture teams.

Key Responsibilities

  • GRC and Regulatory Compliance
  • Support and deliver readiness, implementation, and certification engagements for

ISO/IEC 27001, the CSA Cyber Essentials Mark, and the CSA Cyber Trust Mark.

  • Conduct compliance gap assessments and cybersecurity maturity evaluations against

applicable standards, frameworks, and regulations, including MAS Technology Risk

Management (TRM) Guidelines, Singapore’s Personal Data Protection Act (PDPA), the

NIST Cybersecurity Framework, and the General Data Protection Regulation (GDPR).

  • Develop audit-ready Information Security Management System (ISMS) documentation,

including policies, procedures, Statements of Applicability, risk registers, control

mappings, and risk treatment plans.

  • Support clients during internal audits, external certification audits, and regulatory

assessments.

  • Track audit and assessment findings and work with client stakeholders to support the

timely completion of remediation activities.

  • Threat and Risk Assessments and Cyber Exercises
  • Conduct cybersecurity Threat and Risk Assessments for cloud, enterprise, and regulated

environments.

  • Identify critical assets, threats, vulnerabilities, business impacts, and cybersecurity risks,

and recommend appropriate risk treatment and mitigation measures.

  • Produce clear and comprehensive assessment reports aligned with applicable CSA, NIST,

and ISO methodologies.

  • Design, facilitate, and document tabletop exercises, incident response simulations, and

cyber crisis exercises under the guidance of the GRC Lead.

  • Assess clients’ incident response preparedness and recommend improvements to their

response plans, procedures, and capabilities.

  • Security Governance and Advisory
  • Develop and enhance cybersecurity policies, incident response plans, governance

frameworks, and risk management processes.

  • Review enterprise systems, cloud environments, and business processes from a

governance, risk, and compliance perspective.

  • Assess security areas such as identity and access management, logging and monitoring,

encryption, network security, data protection, and data flows.

  • Provide practical, risk-based recommendations that balance cybersecurity, regulatory

compliance, operational requirements, and business objectives.

  • Deliver cybersecurity awareness briefings and support clients’ wider security governance

initiatives.

  • Project Delivery and Stakeholder Engagement
  • Manage assigned project activities and workstreams under the direction of the GRC Lead.
  • Support the management of project timelines, deliverables, risks, dependencies, and

stakeholder expectations.

  • Collaborate with penetration testing, SOC, cloud security, and security architecture teams

to translate technical findings into business and compliance risks.

  • Prepare and present assessment findings, risk positions, and recommendations to client

stakeholders, including management and technical teams.

  • Escalate material risks, project issues, delays, and compliance concerns to the GRC Lead

in a timely manner.

  • Provide regular progress updates and contribute to the successful delivery and closure of

client engagements.

Prerequisie Requirements

  • Technical Skillset and Competency
  • Relevant certifications such as ISO 27001/27701 LA/LI, CISSP, CISA, CISM, CRISC,

CCSP, Practitioner Certificate in Personal Data Protection, or equivalent.

  • Proven experience in GRC, cybersecurity consulting, or risk management.
  • Hands-on experience implementing ISO/IEC 27001 and/ or 27701.
  • Strong understanding of Risk Management framework and Methodology
  • Excellent stakeholder engagement, communication, and presentation skills
  • Outspoken personality and advanced interpersonal skills

REPORTING LINE

This position reports directly to the GRC Lead.

Important Information

Never provide your bank or credit card details when applying for jobs. Do not transfer any money or complete unrelated online surveys. If you see something suspicious, Report this Job ad.

Learn More