IT Security Governance and Assurance Lead

Date: 4 Aug 2026

Location: Braddell, SG

Company: Network For Electronic Transfers (S)

BCS is NETS’ wholly owned subsidiary, and is an entity within the NETS Group. It manages and operates clearing and payment infrastructure for the Singapore Automated Clearing House, including Fast And Secure Transfers (FAST), Inter-bank GIRO (IBG), Cheque Truncation System (CTS), and provides services for PayNow and SGQR Central Repository.

About BCS

BCS, a wholly owned subsidiary of NETS and part of the NETS Group, manages and operates the clearing and payment infrastructure for the Singapore Automated Clearing House. This includes services such as Fast and Secure Transfers (FAST), Inter-bank GIRO (IBG), and the Cheque Truncation System (CTS). BCS also supports PayNow and the SGQR Central Repository, among other services.

Team and Position Summary

The IT Security Team at BCS ensures the security, availability and resilience of BCS systems, protecting data and mitigating emerging cyber threats in alignment with regulatory requirements.

The Security Governance and Assurance (SGA) unit is a key function within IT Security, responsible to drive cybersecurity governance, oversee cybersecurity risk assessments, manage audits, and ensure robust security compliance monitoring across BCS.

The SGA lead reports directly to the BCS CISO and serves as a subject matter expert in cybersecurity technologies and governance. The role is responsible for managing a team of Security GRC specialists and carrying out proactive oversight and monitoring of BCS’ compliance with the cyber risk management policies and standards.

Key Responsibilities

Leadership and Strategy

  • Design, implement, and continually update BCS’ cybersecurity policies, standards, guidelines, and processes to meet evolving business and regulatory requirements.
  • Recruit, train, and retain security governance, risk and compliance specialists skilled in cybersecurity frameworks and IT standards.
  • Identify and implement automation and process improvements to optimise the efficiency in security monitoring and risk management by Security Governance and Assurance.
  • Assist the CISO with budgeting, procurement, and resource allocation as needed.

Risk Management

  • Conduct risk assessments to monitor BCS’ compliance with cybersecurity policies and security controls, including review of security deviations and risk acceptance submissions from business units to recommend appropriate remediations.
  • Leverage knowledge and assess emerging security technologies and risks to recommend effective solutions and controls to enhance overall operational efficiency and security enforcement across BCS.
  • Drive the assessment of BCS cybersecurity vulnerabilities, mitigation of findings and implementation of cybersecurity controls for BCS systems and the underlying IT infrastructure.
  • Review security breaches and vulnerabilities, ensuring that they are promptly and thoroughly investigated so potential cyber threats are addressed effectively and efficiently.

Compliance Monitoring

  • Stay current with emerging security regulations (e.g., Cyber Security Act, MAS Notices) assess its impact and ensure BCS’ compliance.
  • Monitor cybersecurity assurance activities, including Vulnerability Assessment and Penetration Testing (VAPT), red teaming, and table-top exercises, to ensure adherence to internal policies and proactively address any gaps in compliance or security posture.
  • Oversee and maintain BCS’ Risk Management framework, including the tracking of security gaps, audit findings, and other security risk-related initiatives. Ensure policies and processes are in place, monitor their effectiveness, and assess the impact on BCS.

Audit Management

  • Coordinate and manage IT-security related audits, including collecting and submitting required artifacts, facilitating audit reviews, and ensuring timely responses to audit inquiries.
  • Drive remediation efforts for identified gaps by advising on risk assessments, ensuring completeness of corrective actions, and providing IT security subject matter expertise to support informed decision-making.

Metrics and Reporting

  • Develop and report on IT Security metrics and KRIs to provide insights into security performance, risks, and vulnerabilities across the enterprise. Present findings in internal risk committee meetings and external forums in alignment with BCS’ risk posture. 

Requirements

Education and Experience

  • Bachelor’s or Master’s in Computer Science, Computer Engineering, Information Security, or related fields.
  • Minimum of 10 years in IT governance, risk, or compliance management, preferably within the financial services or payment systems industry.

Skills and Knowledge

  • Strong knowledge of Cybersecurity frameworks (risk management methodologies, regulatory and legal requirements, and industry practices)
  • Ability to demonstrate deep technical expertise/knowledge in in cyber and IT standards and policy review, oversight and governance, risk management and audit execution.
  • Familiarity with MAS & CCOP regulations, COBIT, ITIL, Personal Data Protection and Payment Services Acts, and emerging security standards and solutions.
  • Proficiency in architecture of secure, scalable, and resilient solutions within hybrid cloud environments, along with a strong grasp of CI/CD and DevSecOps methodologies.
  • Strong understanding of various audit standards, with the ability to interpret contracts and technical documents, ensuring alignment with process controls and requirements.
  • Excellent written and oral communication skills, with strong interpersonal abilities to collaborate and foster constructive relationships across all organisational levels.
  • Skilled at managing stakeholder groups, influencing decision-making in IT risk management, balancing diplomacy and assertiveness, and adapting to a rapidly changing environment.
  • Demonstrated leadership skills, with proven ability to foster a collaborative, high-performance team culture.
  • Ability to make informed decisions under pressure and effectively manage crisis situations.
  • Excellent communication, analytical, and problem-solving skills, with the ability to engage effectively with stakeholders at all levels.

Professional Certifications

  • Preferred certifications include Certified Information Security Manager (CISM), Certified Secure Software Practitioner (CSSP), Certified in the Governance of Enterprise IT (CGEIT), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), or any relevant certification in governance, risk, and compliance.

Banking Computer Services Pte Ltd (a subsidiary of Network for Electronic Transfers (Singapore) Pte Ltd)