Routiqo

Senior Manager, Security Operations and Assurance, Information Technology

City Developments Limited

  • Singapore
  • Full-time

Job description

Job Responsibilities:

  • Support the development, implementation and review of cybersecurity policies, standards, procedures and technical guidelines across the organisation and subsidiaries. Monitor compliance, support audits and assurance activities, prepare technical risk updates, and escalate material control gaps through the Group governance process.
  • Lead internal security analysts and manage the external Security Operations Centre provider to deliver continuous monitoring, threat detection, incident investigation and response. Review significant alerts, incidents and service performance, and escalate material risks in accordance with the Cyber Incident Response Plan.
  • Operate, maintain and improve the Group’s security technologies stack across endpoint, identity, email, cloud, network, web, privileged access, data protection and digital environments. Work with IT teams and service providers to ensure security controls are effectively implemented and monitored.
  • Lead vulnerability management, security assessments and technical risk reviews for critical systems, applications, cloud services and subsidiaries. Scope and coordinate external vulnerability assessments, penetration tests and red-team exercises; validate findings, provide remediation advice and track actions to closure.
  • Conduct technical security due diligence for critical vendors, outsourced IT services, cloud providers and digital solutions. Define security assurance requirements for external partners and assess and report on compliance with agreed security obligations.
  • Provide technical security advice for new solutions, major changes and AI use cases. Assess security risks relating to data, access, integration, third-party services and monitoring, and escalate material risks through the established security and AI governance process.
  • Support cybersecurity awareness training and phishing simulations by providing relevant threat insights, technical content and follow-up advice. Help improve security awareness and safe practices across the organisation and subsidiaries.

Job Requirements:

  • Degree in Cybersecurity, Information Security, Computer Science, Information Technology or a related discipline; equivalent relevant experience may be considered.
  • At least 8–12 years of experience in cybersecurity, security operations, security engineering, security assessment or IT risk.
  • At least three years’ experience leading security analysts, managed security providers or technical security vendors.
  • Experience leading internal security analysts and managing an external SOC, managed security service provider or security-testing partner.
  • Strong technical knowledge of SIEM and security monitoring, incident response, vulnerability management, cloud security, identity and access management, endpoint, email, network and data-security controls.
  • Experience scoping and managing vulnerability assessments and penetration-testing engagements, and validating findings and remediation plans.
  • Exposure to application security testing, including static and dynamic analysis (SAST/DAST), software composition analysis (SCA), and penetration testing of web and mobile applications.
  • Working knowledge of security standards and applicable requirements, including ISO/IEC 27001, NIST Cybersecurity Framework, PDPA, Cybersecurity Act, PCI DSS and SWIFT Customer Security Controls Framework, where applicable.
  • Working knowledge of AI security risks and security assessment requirements for AI solutions and third-party AI services.
  • CISSP, CISM, CRISC, CCSP or relevant GIAC certifications are preferred.

Requirements

City Developments Limited (CDL) is committed to fostering an inclusive culture that respects the diversity of its employees and stakeholders. As a signatory of the Employers Pledge for Fair Employment with TAFEP since 2008, CDL’s recruitment process adheres to strict guidelines on non-discrimination and fairness, regardless of gender, ethnicity, religion, or age.

Skills

  • Ai
  • Cybersecurity
  • Iam
  • Recruitment
  • Risk assessment
  • Security engineering