To deliver Operational Technology (OT) cybersecurity and cyber resilience in SMRT, strong oversight of cybersecurity risk and compliance with both regulatory and in-house requirements is critical.
To achieve the above, the Manager, Risk Management is to ensure the organisation's adherence to cybersecurity regulations, policies and standards, oversee the conduct of cybersecurity risk management, including risk control measures, monitor follow-up measures until completion, and implement strategies to enhance the organisation's overall security posture. He/she will also provide support for cybersecurity training and competency to build a strong awareness, ownership and culture.
1. Ensure the organisation’s compliance with the security standards and guidelines stipulated in:
2. Oversee the conduct of cybersecurity risk management, including risk control measures, monitor follow-up actions to mitigate the identified risks until completion and provide regular updates to Management.
3. Manage contracts and deliverables for regulatory CCoP and CP8 audits (2-yearly), Risk Assessment (annually), Vulnerability Assessment (2-yearly) for CII and other contracts as required, and support the conduct of these activities, where required. Note: CP8 includes important non-CII system.
4. Manage processes such as waiver request submissions and reviews, and monitor follow-up actions arising from audits, Risk Assessment and Vulnerability Assessment.
5. Support Policy & Governance team in developing and implementing policies, standards and/or guidelines for managing cybersecurity risks and protecting OT systems against cybersecurity threats.
6. Gatekeep submissions of Material Change Form and corresponding CII Information Record (S10) Form within the specified timeline.
7. Report on the status of OT Cybersecurity status for submission tor Authority and/or Management.
8. Support for cybersecurity training and competency development programme to build up strong cybersecurity awareness, ownership and culture in SMRT.
9. Support the conduct of Cybersecurity Management meetings.
10. Provide guidance to the OT Cybersecurity Operations team in managing CII and Non-CII Asset Information & Security baselines, Identity Management, Authentication and Access Control Technical security solutions to ensure the security and resilience of systems and assets, consistent with related policies, procedures, and agreements.
11. Collaborate with the SMRT Risk Management, Internal Audit and Legal Teams on risk and compliance matters.
12. Where required, support the conduct of validation checks to ensure that security control measures are maintained.
13. Where required, support the conduct of cybersecurity exercises such as Table-Top Exercise for CII.
SMRT Trains Ltd was incorporated in 1987 and operates Singapore’s first mass rapid transit system. Today, we manage and operate train services on the North-South Line, East-West Line, the Circle Line, the Thomson-East Coast Line, and the Bukit Panjang Light Rail Transit. With over 5,000 employees, more than 250 trains, and 141 km of rail tracks across 108 stations, we serve millions of commuters daily.
Sign in to browse authentic reviews, anonymous ratings and salary data before you apply.