SMRT

Manager, Risk Management

SMRT
Public Transport & Rail OperationsSingapore, SGOnsitePosted 2 weeks ago

About the role

AI summarised

Deliver Operational Technology (OT) cybersecurity and cyber resilience for SMRT, providing strong oversight of cybersecurity risk management and compliance with both regulatory and in-house requirements. This role is critical in ensuring adherence to cybersecurity regulations, policies, and standards while enhancing the organization's overall security posture.

TransportOnsite

Key Responsibilities

  • Ensure organizational compliance with stipulated security standards including CSA Cybersecurity Act, CCoP, LTA Code of Practice for Cyber Security in MRT Systems (CP8), and CSA publications.
  • Oversee cybersecurity risk management, including implementing risk control measures and monitoring follow-up actions to mitigate identified risks.
  • Manage contracts and deliverables for regulatory audits (CCoP/CP8, Risk Assessment, Vulnerability Assessment) and support audit activities.
  • Manage processes such as waiver request submissions, reviews, and monitoring follow-up actions from audits and assessments.
  • Support the Policy & Governance team in developing and implementing policies, standards, and guidelines for managing cybersecurity risks to OT systems.
  • Gatekeep submissions of Material Change Form and corresponding CII Information Record (S10) Form within specified timelines.
  • Report on the status of OT Cybersecurity to Authority and/or Management.
  • Support cybersecurity training and competency development programs to build awareness and culture in SMRT.
  • Provide guidance to the OT Cybersecurity Operations team on managing asset information, security baselines, Identity Management, and Access Control technical solutions.

Requirements

  • Degree in Electrical & Electronics Engineering, Computer Science, or equivalent.
  • At least 7 to 8 years of working experience in the engineering field.
  • Good knowledge of cybersecurity regulations, principles, standards, and processes.
  • Good knowledge of cybersecurity risk assessment and vulnerability assessment.
  • Strong strategizing, planning, and organizing skills.
  • Leadership ability.
  • Effective communication skills.