VP, Security Governance & Assurance
Date: 27 Aug 2026
Location: Braddell, SG
Company: Network For Electronic Transfers (S)
The NETS Group is a leading payments services group, enabling digital payments for merchants, consumers and banks across the entire payments value chain.
The Group operates Singapore’s national debit scheme enabling customers of DBS Bank/POSB, HSBC, Maybank, OCBC Bank, Standard Chartered Bank and UOB to make payments using their ATM cards or mobile devices at more than 130,000 acceptance points in the country as well as online payments.
Key Responsibilities
-
Information Security Governance & Compliance
- Support the development, review, and enforcement of Information Security policies, standards, and procedures.
- Monitor compliance with regulatory requirements and industry standards (e.g. MAS TRM, Cyber Hygiene, ISO 27001, PCI DSS).
- Conduct security risk assessments, control reviews, and gap assessments, and track remediation activities.
- Provide cybersecurity governance and compliance advisory to stakeholders.
- Prepare security governance reports, KRI metrics, and updates for management and governance committees.
- Drive security awareness and promote a strong security culture across the organization.
Information Security Risk & Audit Management
- Manage Information Security audit activities, including internal, external, regulatory, and certification audits.
- Coordinate audit requests, review findings, facilitate remediation plans, and track issues to closure.
- Support security risk management activities, including risk assessments, risk registers, and exception management.
- Act as a liaison between Information Security, Risk, Compliance, auditors, and regulators.
Requirements
-
- Degree in Computer Science, Engineering or any other related disciplines with at least 10 years of experience in Information security, including experience in security policy development, risk assessment, compliance implementation & monitoring and governance function (preferably from financial/banking/payment industry).
- Good working knowledge of enterprise security risk management methods and techniques to successfully deliver the security risk management and assessment outcome.
- Prior experience in implementing a program which includes the collation, management and reporting of security metrics (KRI) such as vulnerability management, open software security vulnerabilities, penetration testing findings, security alerts and incidents
- Strong knowledge of regulatory requirements and industry practices (e.g. NIST framework, MAS TRM Guidelines, MAS Cyber Hygiene, ISO 27001 standard)
- Ability to work in a team environment and work independently and produce results that meet standards of quality, timeliness and acceptability
- Strong writing, communication and inter‐personal skills
- Attention to details, with the ability to thoroughly and accurately review IT policies, process and audit responses.
- Excellent problem-solving skills and ability to prioritize and manage multiple tasks
Network for Electronic Transfers (Singapore) Pte Ltd.