Responsibilities:
Cybersecurity & Risk Management
- Support the development, implementation, and continuous enhancement of the organisation’s cyber defence strategy and capabilities.
- Develop, implement, and maintain cybersecurity policies, standards, procedures, and operational guidelines to support a strong and resilient security posture.
- Lead and participate in ISO 27001 audits, cybersecurity audits, cyber exercises, risk assessments and a full range of assessment activities.
- Monitor, analyse, and identify cybersecurity threats, security events, and anomalous activities through continuous security monitoring, threat intelligence, and detection capabilities to enable timely threat detection and escalation.
- Manage and coordinate the response to cybersecurity incidents, vulnerabilities, and cyber-physical security issues, ensuring timely analysis, containment, remediation and implementation of corrective measures.
- Drive organisational compliance with cybersecurity regulations, industry standards, and regulatory requirements, while actively engaging with relevant government agencies, regulators, and external stakeholders to support cybersecurity governance and security objectives.
Asset Reliability & Life Cycle Management
- Plan, review and execute cybersecurity lifecycle management programmes for OT/ICS, network, server, workstation and security infrastructure assets in accordance with regulatory requirements, cybersecurity standards, OEM recommendations and industry best practices.
- Develop and manage cybersecurity asset inventories, software licensing, patch management and hardware refresh strategies to ensure system availability, security compliance and lifecycle sustainability.
- Maintain and periodically review cybersecurity related asset registers, technical documentation, standard operating procedures, disaster recovery documentation and audit reports
- Provide technical expertise and cybersecurity support to Operations, and Maintenance teams to ensure the secure, reliable and resilient operation of plant OT and ICS
- Assess and manage cybersecurity risks associated with asset obsolescence, unsupported software, legacy control systems and end-of-life infrastructure and develop mitigation or replacement plans.
Stakeholder Engagement & Knowledge Sharing
- Collaborate closely with cross-functional teams and/or external vendors.
- Deliver technical guidance, training, and knowledge-sharing sessions to enhance cybersecurity awareness and competencies across the organisation.
- Support continuous improvement initiatives and contribute to the development of a strong cybersecurity culture.
Requirements:
- Degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related discipline, preferably recognised by the Professional Engineers Board (PEB), Singapore.