Job Description
We are seeking an experienced Security Consultant with a minimum of 5 years of professional experience in information security, cybersecurity consulting, or governance, risk, and compliance (GRC). The ideal candidate will have a strong background in conducting security assessments, security audits, and risk evaluations, particularly within the public sector. Experience supporting government agencies, such as the Ministry of Home Affairs (MHA) or other government organizations, will be highly advantageous.
The Security Consultant will work closely with clients and project teams to assess security risks, ensure compliance with applicable security standards and regulatory requirements, and provide practical recommendations to strengthen cybersecurity posture.
Position Summary
We are seeking an experienced Security Consultant with a minimum of 5 years of professional experience in information security, cybersecurity consulting, or governance, risk, and compliance (GRC). The ideal candidate will have a strong background in conducting security assessments, security audits, and risk evaluations, particularly within the public sector. Experience supporting government agencies, such as the Ministry of Home Affairs (MHA) or other government organizations, will be highly advantageous.
The Security Consultant will work closely with clients and project teams to assess security risks, ensure compliance with applicable security standards and regulatory requirements, and provide practical recommendations to strengthen cybersecurity posture.
Key Responsibilities
- Conduct comprehensive security assessments, including technical and governance-based security reviews, to identify risks and security gaps.
- Plan and execute security audits against organizational policies, regulatory requirements, and industry best practices.
- Perform cybersecurity risk assessments and develop risk treatment recommendations aligned with business and regulatory objectives.
- Review security architectures, system designs, and technology implementations to ensure compliance with security requirements.
- Develop security assessment reports, audit findings, executive summaries, and remediation recommendations for stakeholders.
- Support clients in implementing security controls and improving their overall security governance framework.
- Provide advisory services on cybersecurity policies, standards, and security best practices.
- Collaborate with project managers, technical teams, and client stakeholders throughout the project lifecycle to ensure security requirements are incorporated into solution delivery.
- Participate in security compliance initiatives, including readiness assessments and certification exercises where applicable.
- Stay updated on emerging cybersecurity threats, regulatory changes, and industry standards to provide informed recommendations.
Mandatory
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related discipline.
- Minimum 5 years of relevant experience in cybersecurity consulting, information security, or GRC.
- Proven experience conducting:
- Security assessments
- Security audits
- Cybersecurity risk assessments
- Security compliance reviews
- Experience working on public sector or government projects, preferably with agencies such as the Ministry of Home Affairs (MHA) or other government organizations.
- Strong understanding of information security frameworks and standards such as:
- ISO/IEC 27001
- NIST Cybersecurity Framework
- CIS Controls
- Government security standards and compliance requirements
- Strong analytical, documentation, and report-writing skills.
- Excellent communication and stakeholder management abilities.
Preferred
- Professional certifications such as:
- Certified Information Security Manager (CISM)
- Certified Information Systems Auditor (CISA)
- Certified in Risk and Information Systems Control (CRISC)
- Experience supporting government cybersecurity compliance programmes and security governance initiatives.
- Familiarity with cloud security assessments and modern enterprise security architectures.
- Experience working in consulting or professional services environments.
- Key Competencies
- Information Security Governance
- Security Risk Assessment
- Security Auditing
- Security Compliance
- Cybersecurity Advisory
- Security Architecture Review
- Risk Management
- Stakeholder Engagement
- Report Writing and Presentation
- Problem Solving and Critical Thinking
Preferred Candidate Profile
The successful candidate is a proactive cybersecurity professional with strong consulting and client engagement skills. They possess practical experience delivering security assessments and audits for public sector organizations, can effectively communicate security risks to both technical and non-technical stakeholders, and are capable of providing actionable recommendations that enhance clients' security posture while meeting regulatory and compliance requirements.