Cybersecurity Risk Specialist
Job Description
The Cybersecurity Risk Specialist is responsible for executing the organization’s cybersecurity risk management strategy, overseeing the cybersecurity risk acceptance process and supporting tools, conducting enterprise-wide cybersecurity maturity assessments, and evaluating third-party cybersecurity risks. This role is critical in maintaining the organization’s cyber risk posture, enhancing risk governance, and supporting data-driven, risk-informed decision-making by senior management and the Board. The specialist also plays a key role in ensuring compliance with internal policies and regulatory requirements while driving continuous improvement in cybersecurity risk practices.
Responsibilities
-
Perform in-depth assessments of both existing and emerging cybersecurity risks affecting internal systems, applications, and infrastructure, ensuring alignment with the enterprise risk management framework and compliance standards adopted by Celcomdigi
-
Monitor and maintain the Cybersecurity Risk Register, tracking mitigation strategies, treatment plans, and control effectiveness to ensure timely remediation of the identified risks.
-
Produce periodic cybersecurity risk reports for senior management and Board Risk Committee, highlighting key risk trends, evolving threat landscapes, and significant changes in risk ratings requiring executive attention.
-
Manage Cybersecurity Risk Acceptance process, including the evaluation of non-compliance exceptions and documentation of informed business decisions to accept residual risks.
-
Facilitate enterprise-wide awareness initiatives to strengthen understanding and adoption of cybersecurity risk acceptance process across business and technical stakeholders.
-
Champion the automation and digitalisation of risk management and risk acceptance workflows by enhancing GRC platforms and tools (e.g., ServiceNow, Power Apps).
-
Conduct enterprise-wide Cybersecurity Maturity Assessments to evaluate current state, identify gaps, and support roadmap development for improved cyber resilience
Requirements
-
Bachelor's degree in Cybersecurity, Risk Management, Information Technology, or a related field.
-
Minimum 3–5 years of experience in cybersecurity risk management, GRC, or related functions.
-
Strong understanding of cybersecurity frameworks and regulatory standards (e.g., ISO 27001, NIST CSF, ).
-
Experience using GRC Tool and workflow platforms e.g ServiceNow, .
-
Demonstrated ability to communicate cybersecurity risks clearly to technical and non-technical stakeholders, including senior management.
-
Strong analytical skills, attention to detail, and stakeholder engagement capability.
-
Preferred certifications: CRISC, CISA, CISSP, or ISO 27001 Lead Auditor/Implementer.
Job Description
The Cybersecurity Risk Specialist is responsible for executing the organization’s cybersecurity risk management strategy, overseeing the cybersecurity risk acceptance process and supporting tools, conducting enterprise-wide cybersecurity maturity assessments, and evaluating third-party cybersecurity risks. This role is critical in maintaining the organization’s cyber risk posture, enhancing risk governance, and supporting data-driven, risk-informed decision-making by senior management and the Board. The specialist also plays a key role in ensuring compliance with internal policies and regulatory requirements while driving continuous improvement in cybersecurity risk practices.
Responsibilities
-
Perform in-depth assessments of both existing and emerging cybersecurity risks affecting internal systems, applications, and infrastructure, ensuring alignment with the enterprise risk management framework and compliance standards adopted by Celcomdigi
-
Monitor and maintain the Cybersecurity Risk Register, tracking mitigation strategies, treatment plans, and control effectiveness to ensure timely remediation of the identified risks.
-
Produce periodic cybersecurity risk reports for senior management and Board Risk Committee, highlighting key risk trends, evolving threat landscapes, and significant changes in risk ratings requiring executive attention.
-
Manage Cybersecurity Risk Acceptance process, including the evaluation of non-compliance exceptions and documentation of informed business decisions to accept residual risks.
-
Facilitate enterprise-wide awareness initiatives to strengthen understanding and adoption of cybersecurity risk acceptance process across business and technical stakeholders.
-
Champion the automation and digitalisation of risk management and risk acceptance workflows by enhancing GRC platforms and tools (e.g., ServiceNow, Power Apps).
-
Conduct enterprise-wide Cybersecurity Maturity Assessments to evaluate current state, identify gaps, and support roadmap development for improved cyber resilience
Requirements
-
Bachelor's degree in Cybersecurity, Risk Management, Information Technology, or a related field.
-
Minimum 3–5 years of experience in cybersecurity risk management, GRC, or related functions.
-
Strong understanding of cybersecurity frameworks and regulatory standards (e.g., ISO 27001, NIST CSF, ).
-
Experience using GRC Tool and workflow platforms e.g ServiceNow, .
-
Demonstrated ability to communicate cybersecurity risks clearly to technical and non-technical stakeholders, including senior management.
-
Strong analytical skills, attention to detail, and stakeholder engagement capability.
-
Preferred certifications: CRISC, CISA, CISSP, or ISO 27001 Lead Auditor/Implementer.
Screen readers cannot read the following searchable map.
Follow this link to reach our Job Search page to search for available jobs in a more accessible format.
Job Segment:
Compliance, Risk Management, Cyber Security, Law, Legal, Finance, Security