IT Governance, Risk and Compliance Asst Manager/Manager (2 year contract)

<p>We are looking for an <strong>IT Governance, Risk and Compliance Asst Manager/Manager</strong>, who will be based in Singapore, and supporting the Singapore and Malaysia teams. </p><p><br></p><p>This role is vital in establishing, implementing and strengthening the organisation’s technology governance, risk, compliance and operational resilience across our shared services teams. The incumbent will shape and drive a robust agenda to ensure that IT processes, systems, and controls comply with regulatory requirements, corporate policies, and industry best practices while supporting business objectives in a fast-moving technology landscape.</p><p><br></p><p>As a trusted partner to business and technology leaders, the incumbent will lead IT audit and assurance activities, strengthen risk management practices, drive compliance initiatives and coordinate incident response, business continuity and disaster recovery readiness. Through strong stakeholder engagement and practical governance, this role will help build a culture of accountability, resilience, security awareness and continuous improvement across the organisation.</p><p><br></p><p><strong>Responsibilities include but are not limited to the following:</strong></p><p><strong>Cybersecurity Analysis </strong></p><ul><li>Conduct assessments (including third party security) and design processes to support controls and compliance, supporting control remediation efforts, and drive continuous improvement.</li><li>Analyze legal and regulatory requirements, develop and implement control testing, manage policies and procedures, and provide governance support, while coordinating programme activities.</li></ul><p><br></p><p><strong>Governance & Compliance</strong></p><ul><li>Develop, implement, and maintain the organization's IT Governance, Risk and Compliance (GRC) framework, policies, standards, and procedures.</li><li>Ensure compliance with applicable regulatory requirements, corporate policies, and industry standards such as ISO 27001, PCI DSS, NIST, and related frameworks.</li><li>Establish and monitor key compliance controls, metrics, and reporting mechanisms to measure effectiveness and identify areas for improvement.</li><li>Provide subject matter expertise and guidance to stakeholders on governance, compliance, and risk management best practices.</li></ul><p><br></p><p><strong>Audit & Assurance</strong></p><ul><li>Lead internal and external IT audit engagements, assessments, and certification activities.</li><li>Coordinate audit readiness initiatives and ensure the timely completion of audit requirements.</li><li>Own and track remediation plans for audit findings, control weaknesses, and compliance gaps to closure.</li><li>Prepare management reports and dashboards highlighting audit status, key risks and compliance performance.</li></ul><p><br></p><p><strong>Risk Management</strong></p><ul><li>Establish and maintain IT risk management processes, including risk identification, assessment, evaluation, treatment, and monitoring.</li><li>Conduct periodic technology, cybersecurity, operational, and third-party risk assessments.</li><li>Partner with business and IT stakeholders to develop and implement effective mitigation strategies for identified risks.</li><li>Facilitate risk governance reviews and provide recommendations to management on emerging and strategic risks.</li></ul><p><br></p><p><strong>Incident Management & Resilience</strong></p><ul><li>Lead and coordinate cross-functional incident response activities to ensure effective management of technology and security incidents.</li><li>Drive root cause analysis and corrective action initiatives following major incidents.</li><li>Develop, maintain, and test Business Continuity Plans (BCP), Disaster Recovery Plans (DRP), and Business Impact Analyses (BIA).</li><li>Promote operational resilience by ensuring critical business services can recover effectively from disruptions.</li></ul><p><br></p><p><strong>Stakeholder Management & Awareness</strong></p><ul><li>Conduct compliance, governance, and security awareness training programs for employees and stakeholders.</li><li>Collaborate with business leaders, technology teams, vendors, and external auditors to ensure alignment with compliance and risk objectives.</li><li>Stay current with changes in regulatory requirements, emerging threats, and industry best practices, and assess their impact on the organization.</li><li>Foster a culture of governance, accountability, risk awareness, and continuous improvement across the organization.</li></ul><p><br></p><p><strong>Knowledge, Skills and Abilities</strong></p><ul><li>Degree in Computer Science, Engineering or equivalent.</li><li>3-4 years of relevant experience in IT governance, risk & compliance.</li><li>Certification in IT governance, risk, compliance or security frameworks (e.g., CISM, CIPP, CISSP) is preferred.</li><li>Strong understanding of IT systems, networks, and security.</li><li>Experience with cloud-based technologies and compliance frameworks.</li><li>Knowledge of data privacy and protection laws.</li><li>Goal driven, highly motivated, with a desire to take the lead and learn new skills.</li><li>Proficient in multitasking and managing multiple projects, with the ability to meet target completion dates.</li><li>Excellent analytical and problem-solving skills.</li><li>Strong communication and interpersonal skills.</li><li>Ability to work independently and as part of a team.</li><li>Strong technical writing skills.</li></ul><p><br></p><p><br></p><p><strong>About Maxim's</strong></p><p>Founded in 1956, Maxim’s group is one of Asia’s leading food and beverage companies, operating Chinese, Western, Japanese and Southeast Asian restaurants, quick service outlets, bakery shops and cafes, and an institutional catering service. Maxim's group also produces a range of festive products, including the award-winning Hong Kong MX mooncakes, and is a licensee of Starbucks Coffee, Genki Sushi, Ippudo, the Cheesecake Factory and Shake Shack in various territories.</p><p><br></p><p>Altogether, the group has over 80 brands, 2,000 outlets and 40,000 employees in Asia. Proud of our heritage and humbled by our success, we are committed to a sustainable and innovative future. To learn more about Maxim’s, visit www.maxims.com.hk.</p><p><br></p><p><br></p><p>We are excited to learn more about you and appreciate the time you've taken to apply for the role. While we review every application carefully, only shortlisted candidates will be contacted due to the volume of applications received.</p>

Back to blog

Other Jobs To Apply

No other job posts for this day.

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...