Deskripsi Pekerjaan
Are you a seasoned cybersecurity professional passionate about building resilient digital ecosystems? Foodpanda, a leader in the tech-driven delivery space, is seeking a strategic Security Governance, Risk & Compliance (GRC) Lead to join our high-performing security team in Singapore.
In this pivotal role, you will act as the architect of our security posture, bridging the gap between complex technical requirements and business objectives. You will lead the charge in establishing, scaling, and maintaining robust security governance frameworks, ensuring that our rapid innovation remains secure and compliant with regional and global standards. This is a unique opportunity to shape the risk culture of a fast-paced, industry-leading platform while working with cutting-edge technologies.
You will collaborate across departments to champion risk-based decision-making, manage audit engagements, and drive continuous improvement across our information security programs. If you are a proactive leader with a vision for secure growth, we want to hear from you.
Tanggung Jawab
- Develop, implement, and maintain comprehensive information security governance frameworks and policies aligned with industry standards (ISO 27001, SOC2, NIST).
- Lead enterprise-wide risk assessment initiatives, identifying vulnerabilities and recommending mitigation strategies to protect business assets.
- Manage end-to-end internal and external security audits, ensuring compliance with regulatory requirements and contractual obligations.
- Oversee third-party risk management (TPRM) programs, conducting thorough security assessments of vendors and partners.
- Facilitate cross-functional collaboration to integrate security best practices into software development lifecycles (SDLC) and infrastructure operations.
- Develop and track key risk and performance indicators (KRIs/KPIs) to report the security maturity posture to executive leadership.
- Drive security awareness initiatives to cultivate a security-first culture throughout the organization.
Kualifikasi
- Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or a related field.
- Minimum 5-7 years of professional experience in Information Security, specifically within GRC, Risk Management, or Audit roles.
- Solid understanding of international security frameworks such as ISO 27001, SOC2, PCI-DSS, and GDPR/PDPA.
- Professional certifications such as CISA, CISM, CRISC, or CISSP are highly preferred.
- Proven ability to translate complex technical risks into understandable business insights for stakeholders.
- Strong project management skills with a history of driving compliance projects to successful completion.
- Exceptional communication skills and the ability to influence cross-functional teams in a fast-paced environment.