CYBERSECURITY RISK SPECIALIST
CD Level (For CDT Posting Only)
Job Description
The Cybersecurity Risk Specialist is responsible for executing the organization’s cybersecurity risk management strategy, overseeing the cybersecurity risk acceptance process and supporting tools, conducting enterprise-wide cybersecurity maturity assessments, and evaluating third-party cybersecurity risks. This role is critical in maintaining the organization’s cyber risk posture, enhancing risk governance, and supporting data-driven, risk-informed decision-making by senior management and the Board. The specialist also plays a key role in ensuring compliance with internal policies and regulatory requirements while driving continuous improvement in cybersecurity risk practices.
Responsibilities
- Perform in-depth assessments of both existing and emerging cybersecurity risks affecting internal systems, applications, and infrastructure, ensuring alignment with the enterprise risk management framework and compliance standards adopted by Celcomdigi
- Monitor and maintain the Cybersecurity Risk Register, tracking mitigation strategies, treatment plans, and control effectiveness to ensure timely remediation of the identified risks.
- Produce periodic cybersecurity risk reports for senior management and Board Risk Committee, highlighting key risk trends, evolving threat landscapes, and significant changes in risk ratings requiring executive attention.
- Manage Cybersecurity Risk Acceptance process, including the evaluation of non-compliance exceptions and documentation of informed business decisions to accept residual risks.
- Facilitate enterprise-wide awareness initiatives to strengthen understanding and adoption of cybersecurity risk acceptance process across business and technical stakeholders.
- Champion the automation and digitalisation of risk management and risk acceptance workflows by enhancing GRC platforms and tools (e.g., ServiceNow, Power Apps).
- Conduct enterprise-wide Cybersecurity Maturity Assessments to evaluate current state, identify gaps, and support roadmap development for improved cyber resilience
Requirements
- Bachelor's degree in Cybersecurity Domain, exposure in Risk Management, Information Technology, or a related field.
- Minimum 1–3 years of experience in cybersecurity risk management, GRC, or related functions.
- Strong understanding of cybersecurity frameworks and regulatory standards (e.g., ISO 27001, NIST CSF, ).
- Experience using GRC Tool and workflow platforms e.g ServiceNow, .
- Demonstrated ability to communicate cybersecurity risks clearly to technical and non-technical stakeholders, including senior management.
- Strong analytical skills, attention to detail, and stakeholder engagement capability.
- Preferred certifications: CRISC, CISA, CISSP, ISO31000 Risk Manager or ISO 27001 Lead Auditor/Implementer.
CD Level (For CDT Posting Only)
Job Description
The Cybersecurity Risk Specialist is responsible for executing the organization’s cybersecurity risk management strategy, overseeing the cybersecurity risk acceptance process and supporting tools, conducting enterprise-wide cybersecurity maturity assessments, and evaluating third-party cybersecurity risks. This role is critical in maintaining the organization’s cyber risk posture, enhancing risk governance, and supporting data-driven, risk-informed decision-making by senior management and the Board. The specialist also plays a key role in ensuring compliance with internal policies and regulatory requirements while driving continuous improvement in cybersecurity risk practices.
Responsibilities
- Perform in-depth assessments of both existing and emerging cybersecurity risks affecting internal systems, applications, and infrastructure, ensuring alignment with the enterprise risk management framework and compliance standards adopted by Celcomdigi
- Monitor and maintain the Cybersecurity Risk Register, tracking mitigation strategies, treatment plans, and control effectiveness to ensure timely remediation of the identified risks.
- Produce periodic cybersecurity risk reports for senior management and Board Risk Committee, highlighting key risk trends, evolving threat landscapes, and significant changes in risk ratings requiring executive attention.
- Manage Cybersecurity Risk Acceptance process, including the evaluation of non-compliance exceptions and documentation of informed business decisions to accept residual risks.
- Facilitate enterprise-wide awareness initiatives to strengthen understanding and adoption of cybersecurity risk acceptance process across business and technical stakeholders.
- Champion the automation and digitalisation of risk management and risk acceptance workflows by enhancing GRC platforms and tools (e.g., ServiceNow, Power Apps).
- Conduct enterprise-wide Cybersecurity Maturity Assessments to evaluate current state, identify gaps, and support roadmap development for improved cyber resilience
Requirements
- Bachelor's degree in Cybersecurity Domain, exposure in Risk Management, Information Technology, or a related field.
- Minimum 1–3 years of experience in cybersecurity risk management, GRC, or related functions.
- Strong understanding of cybersecurity frameworks and regulatory standards (e.g., ISO 27001, NIST CSF, ).
- Experience using GRC Tool and workflow platforms e.g ServiceNow, .
- Demonstrated ability to communicate cybersecurity risks clearly to technical and non-technical stakeholders, including senior management.
- Strong analytical skills, attention to detail, and stakeholder engagement capability.
- Preferred certifications: CRISC, CISA, CISSP, ISO31000 Risk Manager or ISO 27001 Lead Auditor/Implementer.
Screen readers cannot read the following searchable map.
Follow this link to reach our Job Search page to search for available jobs in a more accessible format.
Job Segment:
Risk Management, Compliance, Cyber Security, Law, Finance, Legal, Security