Skip to content

Open nowPosted 8 days ago

Cyber Assurance Analyst

MyCareersFuture94,028 open roles

Pay
SGD 7,000 – SGD 11,000 a month
Where
Central, Singapore
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowCyber Assurance AnalystMyCareersFuture · Central, Singapore
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on MyCareersFuture's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.7% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.3%3 days
  3. 7.7%7 days
  4. 14.0%14 days
  5. 33.7%30 days
This job: posted 8 days ago

The posting

Join Maybank Singapore as a Cyber Assurance Analyst and help strengthen the Bank's cyber resilience in an increasingly complex threat environment. As part of our newly established Cyber Assurance & Emerging Threats Team, you will independently assess cyber and technology controls, identify emerging risk exposures, and provide objective challenge and assurance to support informed risk management and continuous improvement across the Bank.

As a Cyber Assurance Analyst, you will play a crucial role in enhancing the Bank's cyber resilience by assessing controls and identifying risks.

Responsibilities:-

A. Thematic Risk Assurance

  • Plan and execute thematic assurance reviews across key cyber and technology risk domains, including, but not limited to cyber hygiene, identity and access management, vulnerability management, third-party security risk management, technology governance, cloud security, operational resilience, as well as other priority risk areas identified by management
  • Design and execute evidence-based validation activities to assess control design and operating effectiveness through walkthroughs, document and configuration reviews, sampling and targeted controls testing against regulatory, industry and internal standards
  • Identify systemic control weaknesses, recurring risk themes, and underlying root causes that may expose the Bank to elevated cyber or technology risks
  • Develop and operationalise AI-enabled continuous monitoring use cases to automate control testing, detect control deviations and emerging risk indicators, and provide timely risk intelligence to management and governance committees
  • Support continuous identification of control gaps, improvement opportunities, and emerging areas of concern.

B. Emerging Threat-Informed Assurance

  • Assess whether existing controls remain effective against evolving threat actor tactics, emerging attack techniques and new technology risks
  • Incorporate relevant cyber threat intelligence, industry incidents and regulatory developments into thematic assurance reviews
  • Evaluate the Bank's preparedness against emerging risks including AI-enabled threats, third-party ecosystem attacks, cloud-native threats and identity-based attacks.

C. Independent Challenge and Validation

  • Challenge assumptions in risk assessments, control evaluations, residual risk decisions and remediation strategies, while identifying blind spots and alternative risk perspectives
  • Review responses to audit findings, regulatory observations and risk assessments; validate that action plans address the risk exposure and that completed remediation is effective and sustainable
  • Assess whether accepted risks remain within the Bank's risk appetite and escalate significant or unresolved exposures through appropriate governance channels.

D. Root Cause and Systemic Risk Analysis

  • Identify recurring findings and systemic weaknesses across technology domains and determine underlying root causes
  • Assess whether recurring issues indicate broader governance, process, capability or cultural weaknesses.

E. Assurance Reporting, Governance & Remediation Oversight

  • Produce concise, risk-focused and evidence-based assurance reports, dashboards and control health metrics, and present findings and thematic observations to senior management and governance committees
  • Track management commitments and remediation activities through to closure
  • Validate remediation effectiveness and sustainability
  • Identify recurring issues and escalate significant concerns through governance channels.

F. Stakeholder Engagement

  • Collaborate with Technology, Cyber Security, Control and Prevention, Risk Management, Internal Audit, Compliance, and business teams
  • Promote a culture of strong risk management, continuous improvement, and cyber resilience.

Requirements:-

  • Degree in Cyber Security, Information Security, Computer Science, Information Technology or a related discipline
  • 4 to 10 years of experience in two or more of the following: Cyber Security Assurance, Threat Intelligence or Threat Hunting, Security Operations (SOC), Penetration Testing or Red Teaming, Security Architecture, Vulnerability Management, Information Security Governance, Cyber Risk Management, Incident Response, Cloud Security
  • Proven experience assessing security control effectiveness, identifying control weaknesses, and providing independent challenge on cyber risk and remediation activities
  • Experience within banking, financial services, critical infrastructure, or other highly regulated industries will be an advantage
  • Strong risk and control mindset, with the ability to apply risk-based thinking in assessing control effectiveness and prioritising assurance activities
  • Ability to provide constructive independent challenge while maintaining effective stakeholder relationships
  • Strong analytical, investigative and problem-solving capabilities
  • Excellent report writing, presentation and communication skills, with the ability to articulate complex technical and risk issues to both technical and non-technical audiences
  • Highly organised, detail-oriented and evidence-driven, with a structured approach to assurance and risk assessment
  • Self-motivated and able to thrive in environments requiring critical thinking, objectivity and sound judgement.

Preferred Skills

Strong understanding of the following: Cyber security control frameworks and best practices, including but not limited to:

  • MAS Notice FSM-N06 Cyber Hygiene
  • MAS Technology Risk Management Guidelines
  • NIST Cybersecurity Framework
  • CIS Controls
  • ISO 27001
  • COBIT
  • Control Testing and Assurance Methodologies
  • Regulatory Expectations within Financial Services
  • Technology risk management principles
  • Information security governance and control assurance
  • Attack surface management
  • Vulnerability management programmes
  • Identity and access management controls
  • Third-party risk management practices
  • Security monitoring and incident management processes
  • Cloud security and emerging technology risks.

Only shortlisted candidates will be notified.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against MyCareersFuture's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on MyCareersFuture's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    MyCareersFuture's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.