Lead Risk Assessor
Role
Summary
Senior cyber security risk professional responsible
for leading risk assessments, providing strategic risk guidance, and
influencing business decisions through clear communication of cyber security
risks and opportunities.
Key
Accountabilities
· Lead cyber security risk
assessments across projects, products, and technology initiatives.
· Collaborate with project teams
to identify, assess, and address security gaps and control deficiencies.
· Communicate complex technical
risks in clear business terms, including to executive stakeholders through risk
decision-making processes.
· Make informed risk-based
decisions and manage stakeholder expectations effectively.
· Lead the uplift of team
processes, documentation, and engagement models.
Additional
Responsibilities
· Collaborate with business
stakeholders, engineers, delivery teams, product vendors, partners, and cyber
assurance teams to understand and communicate cyber risk.
· Define and maintain reusable
assets including standardised findings, templates, and process improvements.
· Contribute to the creation and
governance of security strategy, standards, frameworks, and policies.
· Identify and communicate
security risks in a timely manner while incorporating insights from privacy,
legal, engineering, and operational stakeholders.
· Develop strategic relationships
across industry and technology vendors to anticipate emerging threats and
opportunities.
· Mentor and coach risk assessors
and secondees through guidance, feedback, and knowledge sharing.
· Manage complex initiatives
while simplifying outcomes to support effective delivery and execution.
Qualifications
and Experience
· Minimum 15 years of experience
within Cyber Security.
· At least 8 years of experience
in a Governance, Risk and Compliance (GRC) or Risk Management function.
· Practical experience conducting
technical risk assessments.
· Knowledge of industry
frameworks and standards including ISO 27001, PCI-DSS, NIST, and enterprise
security frameworks.
· Strong stakeholder engagement
and communication skills with the ability to translate technical risks into
business insights.
· Experience working within large
and complex enterprise environments.
Highly
Desirable
· Previous experience in a
non-cyber risk or GRC role.
· Industry certifications such as
CRISC, CISSP, CISM, or SABSA.
· Experience working within Agile
and DevOps environments.
Copyright © 2026 Grabjobs Pte.Ltd. All Rights Reserved.