We are seeking an experienced Cybersecurity Consultant specialising in Governance, Risk and
Compliance (GRC) to support the delivery of ISO/IEC 27001, CSA Cyber Essentials Mark
(CEM), CSA Cyber Trust Mark (CTM), Data Protection Trustmark (DPTM)/ SS 714, Threat
and Risk Assessment (TRA), and regulatory compliance engagements.
Reporting to the GRC Lead, you will work with clients to strengthen their cybersecurity
governance, prepare for audits and certifications, meet regulatory requirements, and develop
sustainable security capabilities.
You will collaborate closely with clients’ management and IT teams, as well as Stone
Cybersecurity’s penetration testing, Security Operations Centre (SOC), cloud security, and
security architecture teams.
Key Responsibilities
- GRC and Regulatory Compliance
- Support and deliver readiness, implementation, and certification engagements for
ISO/IEC 27001, the CSA Cyber Essentials Mark, and the CSA Cyber Trust Mark.
- Conduct compliance gap assessments and cybersecurity maturity evaluations against
applicable standards, frameworks, and regulations, including MAS Technology Risk
Management (TRM) Guidelines, Singapore’s Personal Data Protection Act (PDPA), the
NIST Cybersecurity Framework, and the General Data Protection Regulation (GDPR).
- Develop audit-ready Information Security Management System (ISMS) documentation,
including policies, procedures, Statements of Applicability, risk registers, control
mappings, and risk treatment plans.
- Support clients during internal audits, external certification audits, and regulatory
assessments.
- Track audit and assessment findings and work with client stakeholders to support the
timely completion of remediation activities.
- Threat and Risk Assessments and Cyber Exercises
- Conduct cybersecurity Threat and Risk Assessments for cloud, enterprise, and regulated
environments.
- Identify critical assets, threats, vulnerabilities, business impacts, and cybersecurity risks,
and recommend appropriate risk treatment and mitigation measures.
- Produce clear and comprehensive assessment reports aligned with applicable CSA, NIST,
and ISO methodologies.
- Design, facilitate, and document tabletop exercises, incident response simulations, and
cyber crisis exercises under the guidance of the GRC Lead.
- Assess clients’ incident response preparedness and recommend improvements to their
response plans, procedures, and capabilities.
- Security Governance and Advisory
- Develop and enhance cybersecurity policies, incident response plans, governance
frameworks, and risk management processes.
- Review enterprise systems, cloud environments, and business processes from a
governance, risk, and compliance perspective.
- Assess security areas such as identity and access management, logging and monitoring,
encryption, network security, data protection, and data flows.
- Provide practical, risk-based recommendations that balance cybersecurity, regulatory
compliance, operational requirements, and business objectives.
- Deliver cybersecurity awareness briefings and support clients’ wider security governance
initiatives.
- Project Delivery and Stakeholder Engagement
- Manage assigned project activities and workstreams under the direction of the GRC Lead.
- Support the management of project timelines, deliverables, risks, dependencies, and
stakeholder expectations.
- Collaborate with penetration testing, SOC, cloud security, and security architecture teams
to translate technical findings into business and compliance risks.
- Prepare and present assessment findings, risk positions, and recommendations to client
stakeholders, including management and technical teams.
- Escalate material risks, project issues, delays, and compliance concerns to the GRC Lead
in a timely manner.
- Provide regular progress updates and contribute to the successful delivery and closure of
client engagements.
Prerequisie Requirements
- Technical Skillset and Competency
- Relevant certifications such as ISO 27001/27701 LA/LI, CISSP, CISA, CISM, CRISC,
CCSP, Practitioner Certificate in Personal Data Protection, or equivalent.
- Proven experience in GRC, cybersecurity consulting, or risk management.
- Hands-on experience implementing ISO/IEC 27001 and/ or 27701.
- Strong understanding of Risk Management framework and Methodology
- Excellent stakeholder engagement, communication, and presentation skills
- Outspoken personality and advanced interpersonal skills
REPORTING LINE
This position reports directly to the GRC Lead.