Risk Exception Processing: Review, evaluate, and track Digital Security Policy exception requests (DTAP/policy waivers), ensuring business justifications are valid and compensating controls are properly established.
Compensating Controls Validation: Collaborate with engineering and operations teams to define, validate, and monitor effective compensating controls for accepted risks and policy deviations.
Risk Mapping & Register Maintenance: Feed risk analysis findings and approved risk exceptions into the enterprise D&IT risk register, ensuring visibility and periodic re-evaluation....
Track technology vulnerabilities, patch compliance status, remediation activities, and security control implementation across infrastructure, platforms, and applications.
Maintain oversight of technology assets reaching End-of-Support (EOS), End-of-Life (EOL), End-of-Service-Life (EOSL), or End-of-Vendor-Support status, ensuring timely remediation, upgrades, or replacement planning.
Support technology compliance assessments, audits, and regulatory reviews by coordinating evidence collection, documentation validation, and remediation tracking....
Report the Group's security posture, incident trends, risk exposure, and improvement progress to the Group IDT Director and senior management.
Manage security tooling and managed-security-service vendors at the operational level, including service quality, licence utilisation, and cost.
Operate and continuously improve Group security monitoring, covering SIEM use cases, log sources, detection rules, and alert triage across endpoints, servers, network, and cloud services....
Identifies and addresses legal and customer security requirements within the region
Supports the implementation of the global Information Security Management System (ISMS) and global business continuity standards within the region
Implements the global risk-based approach to protecting information and other assets within his/her region and performs vulnerability management related tasks...
Troubleshooting s Risk Mitigation: Identify and resolve technical bottlenecks during migration/deployment phases, ensuring minimal disruption to client operations.
Documentation s Handoff: Build standard operating procedures (SOPs), Project As-Builts, Low-Level Diagram(LLD), system architecture diagrams, and detailed handover documentation for ongoing support teams.
Process Optimization: Continuously refine deployment scripts, templates, and rollout checklists to improve implementation speed and consistency....
Provide guidance to internal stakeholders and suppliers on procurement processes, policies, systems, and workflow requirements
Investigate and resolve procurement and P2P exceptions, including PR-to-PO issues, supplier registration queries, approval workflow delays, and system-related concerns.
Coordinate with Procurement Operations, Accounts Payable, Vendor Management, and technical support teams to ensure timely issue resolution and escalation management....
Coordinate with customers and internal technical teams, including Development, Quality Assurance, Infrastructure, and other stakeholders, to escalate complex issues, provide detailed analysis and reproduction steps, and test and validate fixes, patches, and software updates.
Maintain and monitor IT systems and infrastructure by installing and configuring hardware, operating systems, and applications; monitoring system and network performance; and supporting product deployment, migration, integration, and connectivity requirements.
Support system updates and product readiness by setting up items, bundles, and promotions; performing quality assurance testing; validating new configurations in production; monitoring product availability; and raising concerns or issues requiring resolution....
Meticulous in maintaining site IT forecast, accrual, spending tracking, procurement/receiving process, maintaining MA, Contractors, Communication billing, asset/inventory
Should be willing to work extended hours or modified schedule to meet deadlines
Ensure performance meets stipulated KPIs/SLAs at all...
A challenging and rewarding advisory environment with the opportunity to directly impact the resilience of prominent regional organizations.
About the Role:
We are seeking a results-oriented GRC & IT Security Audit Consultant to join our team. This role focuses entirely on the compliance, framework, and process controls side of IT Security. If you excel at designing risk strategies, leading compliance frameworks, and conducting comprehensive IT security audits, this position offers an excellent opportunity to manage client engagements with a high degree of autonomy....
Analyse and identify key risks and develop appropriate review programmes and tests for superior’s review and approval
Conduct preliminary assessment of reviewable areas, interview appropriate personnel, determine data requirement; accumulate, verify and analyse data, observe actual practices and evaluate operational function
To perform analysis using CAATs such as ACL etc...