Singapore Infocomm Talent Portal




Search


Information Risk Consultant

Occupation Description
Primary Purpose
Responsible for performing regular risk assessments, developing risk mitigation strategies which are pertaining to information risk management

Responsibilities
  1. Plan and prepare for information risk assessments.
  2. Review and perform regular and ad-hoc information risk assessment.
  3. Provide risk assessment reports.
  4. Maintain defined policies and standards, with emphasis on information risk management, update them and define new policies as and when required.
  5. Identify common and specific threats and vulnerabilities of the systems and databases under review.
  6. Develop and update the Threats and Vulnerabilities databases and the control database.
  7. Perform detailed threat and vulnerability impact assessment, assign impact ratings and make adjustments in the overall risk ratings for the systems and databases being assessed.
  8. Identify the impact of the new threats and vulnerabilities on various assets.
  9. Identify the owners and key users of the area or process under review and provide input to the supervisor for overall planning.
  10. Identify risk mitigation options available, evaluate and analyse feasibility, effectiveness, efficiency and cost of risk mitigation options/controls and propose the most appropriate controls for the systems and databases being assessed.
  11. Keep a tab on new technologies and risk areas within them
  12. Function as a point of escalation for Security Related incidents.
  13. Maintenance of all relevant IT Risk documentation.
Requirements
  • At least 3 years of related experience
  • Degree in engineering, science, business or other numerate discipline.
  • Possess basic to intermediate knowledge and understanding of information security concepts and technologies
  • Experience of working in information risk management projects and exposure to project management techniques.
  • Proven ability to coordinate distributed projects with multiple stakeholders within organisation
  • Coding experience and database build security review experience preferred.

 

 
Infocomm @ Work
Securing the World
Information Risk Consultant
Security Consultant
Security Auditor
Security Administrator
Security Architect
Security Audit Manager
Chief Information Security Officer
Information Security Director
Powering the World
Entertaining the World
Connecting the World
Course Listings
IT Personality Quiz
Career Tools
Infocomm Champions Say I.T.
 
Share