Cybersecurity Assurance Specialist

We are seeking a detail-oriented and risk-focused Security Assurance Specialist to strengthen the organisation’s cybersecurity governance, risk, and compliance posture.
This role will be responsible for providing independent oversight and assurance over security controls, regulatory compliance, risk assessments, and remediation tracking. The incumbent will work closely with technology, security operations, risk, audit, and business stakeholders to ensure that security controls are effective, sustainable, and aligned with regulatory and industry best practices.
Responsibilities:
Security Control Assurance
Review and assess the design and operating effectiveness of cybersecurity controls across infrastructure, applications, cloud, and third-party environments.
Conduct control testing, thematic reviews, and deep-dive assessments to identify gaps and improvement areas.
Validate remediation plans and ensure sustainable closure of findings.
Regulatory & Compliance Oversight
Support compliance with applicable regulations and frameworks (e.g., MAS TRM, ISO 27001, NIST, CIS, PDPA, etc.).
Coordinate and manage responses to internal audits, external audits, and regulatory inspections.
Track and report regulatory commitments and remediation status to senior management.
Risk Assessment & Monitoring
Perform risk assessments on critical systems, projects, and third-party engagements.
Facilitate Risk and Control Self-Assessments (RCSA) and monitor Key Risk Indicators (KRIs).
Identify emerging cyber risks and escalate where appropriate.
Incident & Issue Governance
Review security incidents from a governance perspective and ensure proper documentation, root cause analysis, and control improvements.
Monitor recurring issues and identify systemic weaknesses requiring control uplift.
Policy & Framework Management
Develop, review, and maintain security policies, standards, and procedures.
Ensure alignment with enterprise risk appetite and industry best practices.
Drive awareness of policy requirements across stakeholders.
Reporting & Stakeholder Engagement
Prepare periodic security assurance and risk reports for management committees.
Provide advisory guidance to first-line technology and business teams on control design and compliance obligations.
Act as a liaison between first, second, and third lines of defence.
Continuous Improvement & Automation
Identify opportunities to enhance assurance processes through automation and data analytics.
Improve governance workflows, dashboards, and tracking mechanisms.
Requirements
Minimum 5-8 years of experience in cybersecurity assurance, IT governance, risk management, audit, or compliance.
Strong knowledge of cybersecurity frameworks (e.g., ISO 27001, NIST, CIS Controls).
Experience managing audits and regulatory inspections.
To apply:
If you’re interested to apply or find out more, please share across your CV or reach out to Chen Yi at cy@kerryconsulting.com for a discussion. Due to anticipated high volume of applications, we regret to inform that only shortlisted candidates will be notified.
Reg: R1876389
Lic: 16S8060
![]()
