CybersecurityJobs.io
← Back to all jobs

Job Description

Lead FM's global cybersecurity regulatory compliance program by assessing requirements and translating them into actionable controls while collaborating across security, technology, risk, legal, and business teams to ensure regulatory alignment.

Responsibilities

  • Oversee the full spectrum of the cybersecurity regulatory compliance function, including governance, processes, tools, and reporting.
  • Coordinate responses to regulatory examinations, client security questionnaires, and other external information requests; work with Information Security, IT, Risk, Legal, and business stakeholders to collect, validate, and deliver accurate, audit-ready responses aligned to FM's control environment.
  • Monitor global cybersecurity regulations, standards, and guidance; conduct impact assessments to determine applicability and required changes to FM's controls.
  • Lead regulatory gap analyses and control evaluations; partner with technical and business teams to define remediation actions, track progress, validate closures, and escalate risks as needed.
  • Develop and maintain metrics, dashboards, and reporting on compliance posture, risk, and trends; provide concise updates to senior leadership and governance committees.
  • Serve as a trusted advisor on regulatory and compliance matters across IT, security, and business units; guide control design, risk treatment, and regulatory alignment to FM’s risk appetite.
  • Identify opportunities to improve program efficiency, automation, and maturity; implement leading practices in regulatory compliance, controls management, and assurance.
  • Lead complex initiatives and direct cross-functional contributors; promote accountability, transparency, and continuous improvement.

Requirements

  • Minimum 8 years in cybersecurity, information security, cyber risk, audit, or regulatory compliance; global experience preferred.
  • Experience applying frameworks such as NIST CSF 2.0 and CIS v8.1, including mapping controls to regulations and using a risk-based approach to solve problems.
  • Hands-on experience responding to regulatory exams, audits, or client security assessments, including evidence collection, control mapping, and response coordination.
  • Experience supporting IT general controls (ITGC) or cybersecurity control audits; understanding audit expectations, testing approaches, and evidence requirements.
  • Familiarity with global regulatory requirements across regions (APAC, EU, US) and regulatory bodies like APRA, IRDAI, OFSI, MAS.
  • Proven ability to identify control gaps, assess compliance, and support remediation tracking.
  • Strong problem-solving and analytical abilities to interpret regulatory requirements and apply them in a practical, risk-based manner.
  • Ability to develop and maintain clear, accurate, audit-ready control documentation and supporting evidence.
  • Outstanding stakeholder management and collaboration across Information Security & Risk Management, IT, Risk, Legal, and business teams.
  • Excellent verbal and written communication skills; translate technical security concepts into clear responses for regulators, clients, and business stakeholders.
  • Strong organizational and time management skills; manage multiple concurrent requests and deadlines.
  • Ability to work independently, prioritize competing demands, and deliver high-quality outputs with minimal supervision.
  • Bachelor's degree in information security, computer science, information technology, or a related field; consideration given to relevant experience.
  • Certifications such as CISA or CISM are preferred.

Technologies

Technologies used: NIST CSF 2.0, CIS v8.1.

Benefits

  • Incentive plan
  • Medical, dental, and vision insurance
  • Life and disability insurance
  • Well-being programs
  • 401(k) and pension plan
  • Career development opportunities
  • Tuition reimbursement
  • Flexible work
  • Time off, including vacation and sick time

Schedule & Location

  • On-site work is required one day per week at the Corporate Headquarters, with flexibility to be on-site as needed by business demands.
  • Relocation is not offered for this position.

Similar Jobs