GRC Application Security Specialist (Contract)

Reposted 4 Days Ago
Be an Early Applicant
Budynek, Aleksandrów, Piotrkowski, Łódzkie, POL
In-Office
Senior level
Agency • Information Technology • Professional Services
The Role
Lead GRC and application security efforts: develop ICT security governance, review policies, run compliance checks, conduct audits, identify and remediate application vulnerabilities, integrate security into SDLC and DevOps, automate security scans, support remediation tracking, and present risk reporting and recommendations to stakeholders.
Summary Generated by Built In

[What the role is]

As a Governance Risk and Compliance Specialist & Application Security Engineer, this role is crucial in developing and maintaining a robust culture of technology and cybersecurity risk governance across our organization.

[What you will be working on]

Governance, Risk and Compliance (GRC)

• Develop and promote a culture of technology risk governance and management across the organisation, ensuring proper accountability in managing, tracking, and reporting technology and cyber risks

• Provide subject matter expertise to internal stakeholders on cybersecurity requirements, including compliance with MAS internal policies and standards, as well as policies from GovTech and Cyber Security Agency of Singapore

• Review and establish ICT policies and process controls, conducting regular compliance checks to ensure adherence

• Track and monitor technology projects and initiatives to meet compliance requirements, including Key Risk Indicators and Control Self-Assessment as part of the technology governance framework

• Monitor incident reporting processes, reviewing and reporting on corrective measures and improvement areas

• Participate in consultations and conduct gap analysis against new or revised regulatory requirements

• Assess and seek waiver approvals for deviations and develop risk treatment strategies

• Organise risk forums and monitor action plans, coordinate and facilitate IT and cybersecurity audits

• Track remediation plans to address audit findings and follow up on remediation actions with stakeholders, project managers, and application managers


Application Security

• Establish clear guidelines and best practices for secure coding, vulnerability management, and incident response across development teams

• Serve as Subject Matter Expert in application security for enterprise projects during development phases, providing information security consulting and recommendations

• Discover security vulnerabilities and devise mitigation strategies, reporting and resolving technical debt effectively

• Track and address security issues with timely remediation and patching processes

• Integrate security tools and processes into DevOps pipelines, automating security scans and tests

• Collaborate with developers and software teams to ensure security integration at every stage of software development

• Work with development teams to remediate application security vulnerabilities and prevent future incidents

• Implement and promote secure coding practices throughout the organisation


Strategic and Operational Excellence

• Recommend re-engineering and streamlining of processes to enhance control effectiveness

• Present management reporting to stakeholders with data analysis, trend identification, and strategic recommendations

• Enhance training materials and documentation in ICT risk management, developing case studies and best practices

• Stay updated on latest security threats, trends, and emerging technologies

• Identify opportunities for incorporating AI assistant tools into development processes and analyse efficacy of potential use cases


This integrated role ensures comprehensive security coverage from governance oversight through to technical implementation, creating a robust security posture across the organisation's technology landscape.

[What we are looking for]

  • At least 5 years relevant experience in ICT cybersecurity, data security, audit management, governance, risk and compliance management,  security engineer or security architect role
  • Relevant certifications in IT governance, IT audit, cyber or data security (e.g. CISSP, CISM, CISA, etc.) preferred.
  • Ability to work with cross-functional, multi-disciplined team to operationalise monitor security policies and procedures.
  • Knowledge of Instruction Manual 8 and CSA Cybersecurity Code of Practice preferred.
  • Technical knowledge of security vulnerabilities, validation of remediations and risk assessments.
  • Experience in performing penetration testing, secure code review, static, dynamic and manual source code review.
  • Experience in identifying and remediating common web application vulnerabilities such as OWASP Top 10
  • Hands-on experience with Web Application Scanning Tools
  • Proven experience in secure coding practices, vulnerability assessment, and penetration testing
  • Relevant experience in data visualisation and analytics.

     

      Skillset:

  • Strong analytical, reasoning and problem-solving skills. 
  • Meticulous with an eye for detail.
  • Good oral and written communication skills
  • Ability to work independently and assume responsibility for project deliverables.
  • Team player who is proactive and collaborative 
  • Experience in reporting and dashboard using JIRA is preferred.

As part of the shortlisting process for this role, you may be required to complete a medical declaration and/or undergo further assessment.


This is a 2-Year Contract. All applicants will be notified on whether they are shortlisted or not within 4 weeks of the closing date of this job posting.

Skills Required

  • At least 5 years relevant experience in ICT cybersecurity, data security, audit management, governance and risk compliance management
  • Subject-matter expertise in application security, secure coding practices, vulnerability assessment and remediation
  • Experience performing penetration testing, secure code review, static, dynamic and manual source code review
  • Hands-on experience with Web Application Scanning Tools
  • Experience identifying and remediating common web application vulnerabilities such as OWASP Top 10
  • Technical knowledge of security vulnerabilities, validation of remediations and risk assessments
  • Ability to work with cross-functional, multi-disciplined teams to operationalise and monitor security policies and procedures
  • Relevant certifications in IT governance, IT audit, cyber or data security (e.g., CISSP, CISM, CISA)
  • Knowledge of Instruction Manual 8 and CSA Cybersecurity Code of Practice
  • Relevant experience in data visualisation and analytics
  • Experience in reporting and dashboard using JIRA
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Singapore

What We Do

The Singapore Economic Development Board (EDB) is a government agency responsible for strategies that enhance Singapore’s position as a global centre for business, innovation, and talent. It undertakes investment promotion and industry development.

Similar Jobs

Samsara Logo Samsara

Senior Software Engineer

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
Poland
4000 Employees
638K-751K Annually

Samsara Logo Samsara

Software Engineer

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
Poland
4000 Employees
301K-354K Annually

Takeda Logo Takeda

GCM Transition Lead - Human Resources

Healthtech • Software • Analytics • Biotech • Pharmaceutical • Manufacturing
Hybrid
Łódź, Łódzkie, POL
50000 Employees
328K-451K Annually

Benchling Logo Benchling

Account Executive

Cloud • Healthtech • Social Impact • Software • Biotech
Remote or Hybrid
27 Locations
605 Employees

Similar Companies Hiring

Axle Health Thumbnail
Artificial Intelligence • Healthtech • Information Technology • Logistics
Santa Monica, CA
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account