Principal Engineer, Cybersecurity GRC - Singapore - StarHub

    StarHub
    StarHub Singapore

    3 days ago

    Telecommunications
    Description
    Job Description

    Job Description

    As a Principal Engineer (GRC), you will execute and own day‑to‑day cybersecurity governance, risk and compliance activities across StarHub's business units. You will ensure our digital assets and projects comply with internal security policies and Singapore telco regulatory obligations (e.g., IMDA, CSA, TCS, BCS, CCoPv2) while uplifting our detection and response capabilities. You will collaborate with internal teams, our MSSP, and external consultants to deliver security reviews, exercises, and remediation on time and to a high standard.

    Key Responsibilities:
    • Regulatory Compliance & Governance (Execution)Maintain Cybersecurity Management (CSM) documentation and contribute to 5G policy development to align with regulatory obligations and deadlines.Plan and execute—together with appointed consultants and internal stakeholders—the following annual/biennial activities, including drafting and socialising reports and tracking remediation to closure:Bi‑Annual Host Configuration Reviews for CII and CII‑supporting assetsAnnual Table‑Top Exercises (TTX) across major stakeholdersBiennial external audits with auditors and key business unitsMaintain audit‑ready artefacts and ensure submissions meet expected timelines and quality.
    • Security Engineering & OperationsPartner with the MSSP and platform owners to ensure comprehensive 24×7 log ingestion and monitoring coverage; onboard new log sources and use cases.Tune SIEM/SOAR detections and playbooks; develop runbooks to reduce mean time to detect/respond.Track and drive vulnerability remediation for assigned systems; ensure adherence to SLA (e.g., critical within 14 days) and report status to stakeholders.Support incident response (IR): triage, containment coordination, evidence preservation, and post‑incident reviews; facilitate lessons learned and control improvements.Develop or enhance automation (e.g., scripts/dashboards) for evidence collection, risk tracking, and compliance reporting.
    • Risk Management & AssurancePerform risk assessments and threat modelling for new/changed business solutions; define security requirements and validate they are tested before go‑live.Maintain accurate risk register entries for owned domains; ensure risks have clear owners, treatments, and review cadences.Evaluate new security solutions/approaches and contribute to policies, standards, and guidelines.

    Qualifications

    Qualifications

    Requirements:

    Bachelor's degree in Computer Science, Computer Engineering, Information Technology, or related field.5–8 years' hands‑on experience in cybersecurity engineering and/or GRC within a telco or similarly regulated environment.

    Familiarity with Singapore regulatory landscape (IMDA, CSA, CII requirements) and enterprise frameworks (e.g., NIST CSF, ISO/IEC

    Demonstrated experience in one or more of: identity & access management (RBAC, MFA, PAM), cryptographic controls, vulnerability management, firewall policy reviews, log analysis, packet/stream analysis, SIEM/SOAR tuning, and incident handling.

    Strong written and verbal communication skills; ability to prepare reports for technical and senior, non‑technical stakeholders.Able to participate in on‑call/after‑hours support during critical cybersecurity incidents.

    Preferred Certifications (nice‑to‑have): GCIH, GCFA, CISA, CISSP (or equivalent).

  • Work in company

    Principal Engineer, Cybersecurity GRC

    Only for registered members

    Principal Engineer (GRC) executes day-to-day cybersecurity governance activities across StarHub's business units ensuring digital assets comply with internal security policies and regulatory obligations. · ...

    Singapore

    2 weeks ago

  • Work in company

    Principal Engineer, Cybersecurity GRC

    Only for registered members

    As a Principal Engineer (GRC), you will execute and own day-to-day cybersecurity governance, risk and compliance activities across StarHub's business units. · ...

    Singapore

    1 month ago

  • Work in company

    Security Governance, Risk and Compliance

    Only for registered members

    The GRC Lead is a newly created role responsible for building and operationalising the organisation's cybersecurity governance, risk, and compliance capabilities from the ground up.This role will define foundational policies, frameworks, and risk management processes while enabli ...

    Singapore

    1 month ago

  • Work in company

    Cybersecurity Manager

    Only for registered members

    A cybersecurity practitioner coming from an IT Audit/Consultancy background with strong cybersecurity experience and technical knowledge is needed to plan, manage and execute governance and compliance initiatives for the infocomm sector so as to improve reliability in Singapore. ...

    Singapore

    1 month ago

  • Work in company

    Cybersecurity Manager

    Only for registered members

    A cybersecurity practitioner coming from an IT Audit/Consultancy background with strong cybersecurity experience and technical knowledge is needed to plan, manage and execute governance and compliance initiatives for the infocomm and media sector so as to improve the reliability ...

    Singapore

    2 weeks ago

  • Work in company

    Cybersecurity Engineer

    Only for registered members

    This role involves developing user training programs to promote cybersecurity best practices. · Develops and delivers user training and awareness programs. · Assists in implementing Governance, Risk, and Compliance frameworks. · ...

    Singapore

    1 week ago

  • Work in company

    IT Security Governance Intern

    Only for registered members

    The IT Security Governance Intern will involve in conducting and managing Risk Assessments meetings, reviewing and identifying potential gaps during Risk Assessment, implementing GRC solution, gaining experience in identifying, assessing, and mitigating cybersecurity risks. · - I ...

    Singapore $40,000 - $60,000 (USD) per year

    1 week ago

  • Work in company

    Security Consultant

    Only for registered members

    Company Description · NTT is a global leader in technology innovation, delivering a wide range of services to individuals, businesses, and organizations. We specialize in business consulting, AI-powered solutions, cybersecurity, global networks, data center management, and edge c ...

    Singapore $90,000 - $160,000 (SGD) per year

    2 days ago

  • Work in company

    Assistant Manager, Program Management

    Only for registered members

    As an Assistant Manager in the Governance Risk and Compliance team you will track manage and report on the risk management and governance of ICT and Smart Systems at Sentosa Development Corporation. · ...

    Singapore

    1 month ago

  • Work in company

    Director, Cyber Gov, Risk and Compliance

    Only for registered members

    The Group Cyber Governance Risk Compliance Director is a senior leadership role accountable for setting maintaining enforcing Singtel Groups cyber security policies standards compliance posture. · ...

    Singapore

    1 month ago

  • Work in company

    Governance, Risk and Compliance Specialist

    Only for registered members

    We are looking for experienced Governance, Risk, and Compliance (GRC) Specialists to join our team.Bachelor's degree in Information Technology, Cybersecurity, or a related field. · Minimum of 5 years of relevant experience in ICT cybersecurity, data security, audit management, go ...

    Singapore

    1 week ago

  • Work in company

    Assistant Manager, Program Management

    Sentosa Development Corporation

    [What the role is] · As an Assistant Manager in the Governance, Risk and Compliance (GRC) team in the Security, Process and Governance department, Digital Technology Transformation division, you will track, manage and report on the risk management and governance of ICT and Smart ...

    Singapore

    3 days ago

  • A leading Investment Bank is looking for a senior Technology Risk & Cybersecurity professional to take ownership of risk governance across APAC. · ...

    Singapore

    1 month ago

  • An empowering career at Singtel begins with a Hello. Our purpose, to Empower Every Generation, connects people to the possibilities they need to excel. Every "hello" at Singtel opens doors to new initiatives, growth, and BIG possibilities that takes your career to new heights. So ...

    Singapore

    3 days ago

  • Work in company

    Cybersecurity Risk

    Only for registered members

    We are seeking a Lead/Senior Cybersecurity Governance Specialist to join the CISO Office responsible for shaping and driving enterprise-wide cybersecurity governance risk management and security architecture standards across a large complex organisation. · 10–12 years of experien ...

    Singapore

    1 month ago

  • Work in company

    Cybersecurity Risk

    Only for registered members

    We are seeking a Lead / Senior Cybersecurity Governance Specialist to join the CISO Office, · Mandatory Skill-set10–12 years of experience in Cybersecurity GRC, · Strong knowledge of security governance frameworks, · Deep understanding of Zero Trust Architecture (ZTA), · ...

    Singapore

    1 week ago

  • Work in company

    IT Security Officer

    confidential

    Job Title: IT Security Officer (ITSO) / Security Consultant · Contract Duration: 1 Year (Renewable, subject to client approval) · Work Location: Singapore · Role Overview · We are seeking an experienced IT Security Officer (ITSO) to oversee governance, risk, and compliance activi ...

    Singapore $52,000 - $90,000 (SGD) per year

    1 day ago

  • Work in company

    Strategic Account Manager, Cyber APAC

    Only for registered members

    Role Overview: · LRQA continues to achieve significant growth and is therefore looking to appoint a Strategic Account Manager to support further expansion in APAC, primarily focussed on pan-SEA countries. While the role primarily targets Cantonese, Korean and Japanese speaking ma ...

    Singapore

    1 day ago

  • Work in company

    IT Security Officer

    Only for registered members

    We are seeking an experienced IT Security Officer (ITSO) for our esteemed client. · Develop cybersecurity Standards and Policies · ...

    Singapore

    1 month ago

  • Work in company

    it security specialist

    Only for registered members

    This is an IT security specialist role. Incident & Threat Management Vulnerability & Product Management Monitoring & Analysis Compliance & Audit Security Architecture & Integration are the key responsibilities. · ...

    Singapore

    1 month ago

Jobs
>
Singapore