The Information Security Analyst will be reporting to the APAC Information Security Manager and will work as part of the UPS AsiaPac Information Security Assurance and Risk Management Team in our corporate office in Singapore, playing a major role in managing risk and security vulnerabilities across the APAC region.
As the Lead Information Security Analyst, the individual is expected to:
Conduct security risk assessments in strategic IT systems, third party vendors, and review and negotiate Information Security agreements with vendors and customers.
Prepare and initiate assessments based on enterprise InfoSec Risk Management Frameworks, Policies and Standards, and provide executive reports on IT Risks and risk reduction strategies.
Determine a system or vendor's Information Security compliance posture based on the contractual agreement and the regional data protection regulations.
Provide Information Security recommendations on effective security controls and processes, innovate processes, streamline methodologies, and increase vendor audit effectiveness and information security compliance.
Coordinate and analyze regional cyber security regulations and formulate impact assessments and action plans.
Manage reporting and status tracking for all Information Security-related tasks and any other tasks as required.
Requirements
Possess a Degree in Information Technology or related fields.
Possess at least 3 years of similar Information Security Assurance, Compliance, or Audit experience at a large organization, with at least 1 year of experience working with Third Party/Vendor Assurance.
Demonstrate experience in the Information Security and Data Protection field, using risk management and security control frameworks (ISO27001), auditing, and GRC tools and technologies.
Display good verbal and written communication skills.
Able to work well independently as well as within teams.
Having any of these certifications (CISSP, CISA, CRISC, CISM, CCSP, CTPRP, GSNA) is preferred.