Deputy Director (Tech Risk Management)
Job Description
What You'll Do
- Conduct and lead cybersecurity, AI, supply chain, and compliance risk assessments for IT and OT systems and services, identifying security risks, evaluating their business impact, and providing risk-based recommendations to support informed decision-making and alignment with enterprise objectives.
- Ensure key security requirements are defined and incorporated into system designs, implemented in line with security-by-design principles, and compliant with prevailing SP Group policies and standards.
- Review tender and project-specific security specifications, ensuring alignment with assessed risks, security requirements, and internal policies.
- Collaborate with IT/OT and AI stakeholders, project teams, and outsourced vendors to ensure security objectives are met throughout the project and system lifecycle.
- Participate in the scoping of security tests, reviews, and audits, and assess their results to ensure appropriate security assurance is achieved.
- Conduct cybersecurity risk assessments for AI, IT/OT systems, and work with system owners to agree on remediation plans.
- Partner with IT/OT and AI teams to co-design and implement security controls in accordance with the Security by Design framework.
- Stay current with emerging security technologies and trends, particularly in AI, cloud, and on-premises systems.
- Monitor and report on cybersecurity risks across AI, IT, and OT systems, ensuring emerging threats, vulnerabilities, control gaps, and regulatory changes are identified, assessed, escalated, and managed in accordance with organisational risk management requirements.
What You'll Need:
- Degree in Computer or Technology related disciplines
- Information Security Certification such as Certified Information Systems Security Professional (CISSP), Certified Cloud Security Professional (CCSP), Certified Information Security Manager (CISM) Certified Risk and Information Systems Control (CRISC), Advanced in AI Security Management (AAISM) would be an added advantage.
- At least 8-10 years of experience covering the following areas:
- Proven experience in cybersecurity risk assessment and security advisory across AI, IT, and OT environments, with a strong understanding of vulnerabilities, threat landscapes, security principles, and industry best practices, and the ability to translate these into practical, risk-based recommendations.
- Direct experience in conducting risk assessments for cloud services and IT or OT systems.
- Hands-on experience applying governance frameworks, standards, and best practices such as ISO 27001/27002, PDPA, PCI-DSS, NIST, CSA-STAR, SOC 2, ISO42001 etc.
- Broad knowledge across various information security technologies in large enterprise environments, including but not limited to: firewalls, intrusion detection, encryption, Linux/Windows OS, databases, antivirus, patch management, vulnerability scanning, backup, logging and monitoring, remote access, application and network security, and change management.
- Proficient in recommending efficient IT/OT and AI security controls throughout the SDLC, with added advantage for familiarity with Agile development frameworks.
- Demonstrated track record of balancing business needs and operational priorities against cybersecurity risks, while enabling informed risk-based decision-making.
- Singaporeans and Permanent Residents preferred.
Thank you for your interest in SP Group. You will be directed to our chatbot to complete the application after you click apply!
We regret to inform that only shortlisted candidates will be notified.
More Info
Key Skills
PDPA
cybersecurity risk assessment
SOC 2
Agile development frameworks
security advisory
logging and monitoring
OT systems
governance frameworks
PCI-DSS
CSA-STAR
ISO42001
Antivirus
