This position reports to the Chief Compliance Officer in
Kris+ and is a functional member of the Group Information Security
Team (Infosec) responsible for ensuring compliance readiness with
PCI DSS and MAS TRM standards for the SIA
group.
This role requires creating, maintaining,
and executing compliance programs while monitoring business
activities to maintain the organization's PCI compliance
certification.
Key
Responsibilities :
operations and ensure compliance to regulatory IT
requirements.
an assurance program ensuring full compliance
with :
certifications
standards
including associated planning and testing
Define scope and review the results of security tests, reviews and
audits to ensure PCI DSS and MAS TRM assurance is
achieved
align operations and safeguards for the protection of payment
information
to operations, processes and activities to ensure PCI DSS and MAS
TRM compliance for the organisation
recommend amendments in the Group policy to align PCI DSS and MAS
TRM controls
PCI DSS, MAS TRM and other related information security standards
(ISO / IEC 27001, NIST CSF 2.0, SOC 2 Type II) and assess the impact
of such changes on organization
date on emerging security threats and vulnerabilities for SIA
Group
guidance, expertise, solutioning and education on PCI DSS and MAS
TRM compliance matters
program priorities, deadlines and deliverables
Support Infosec's efforts in other information security standards
compliance like NIST CSF 2.0
initiatives in improving infosec process (business critical
assessments and risk management) and supporting
systems
Infosec improvements
information Security duties
This is an
individual contributor
role.
Requirements :in IT or related fields
of experience in information security
3 to 4 years of experience in PCI DSS and MAS TRM audit or internal
compliance
Certifications :
Professional experience as PCI QSA / ISA, MAS TRM, ISO27001
preferred
in Information Security (CISSP, CISA) and auditing
preferred
Technical
Knowledge :
international security standards (ISO27001, NIST, SOC 2 Type
II)
security areas : network design, cloud, zero trust, Internet of
Things, cryptography, AI, etc.
knowledge of secure application development
techniques
data security principles, system and application
security
Soft Skills :
Strong oral, written, and interpersonal communication skills with
ability to communicate at all levels
attitude with drive, initiative, enthusiasm, and urgency in
resolving high-priority issues
independently and collaboratively in a team environment
Compliance Officer • Singapore