About this role
[What the role is]
[LTA-PT] MANAGER/DEPUTY MANAGER, TICKETING SYSTEM & GOVERNANCE (GOVERNANCE, RISK & COMPLIANCE)
[What you will be working on]
Become a catalyst for effective system ownership, operations and governance as a Ticketing System and Governance officer!
Are you passionate about optimising public service delivery and making a difference? Join our team and take a lead role in maintaining, enhancing and governing the public transport ticketing system to strengthen people-centric service delivery and ensure a future-ready public transport network that connects communities and places.
Responsibilities:
Governance Framework
• Oversee and govern transit ticketing system to ensure commuter satisfaction, operational stability and compliance with the governance framework and regulatory requirements.
• Maintain governance framework and ensure operationalization by overseeing process, metrics, audit and risk management.
Cybersecurity and Data Protection Governance:
• As ticketing system owner, you will oversee and enforce cybersecurity and data protection policies, standards, and procedures aligned with ISO 27001, NIST, PCI-DSS, PDPA and other relevant standards.
• Collaborate with internal technical cyber security team and contractors to monitor the effectiveness of cybersecurity and privacy controls of IT infrastructure, cloud services, networks and applications in ticketing system.
• Establish key metrics (KPIs) on cyber security and data protection and periodically report to senior management.
Compliance and Risk Management:
• Support internal and external audits and assessments related to cybersecurity and data protection.
• Maintain a register of risks related to information security and data protection, and track mitigation plans.
• Collaborate with technical cyber security teams to ensure internal delivery teams and third-party service providers meet security and privacy requirements for ticketing system.
• Oversee data protection measures and access controls of ticketing system.
Incident Management:
• Manage cybersecurity and data protection incidents including detection, analysis, containment, eradication, and recovery.
• Drive root cause analysis and ensure implementation of corrective/preventive actions.
• Review incident management report and post-incident reports.
• Coordinate with required stakeholders for incident response, business continuity and disaster recovery.
Awareness and Training:
• Collaborate with technical cyber security team to implement cybersecurity and data privacy awareness programs, including phishing simulations and incident response tabletop exercises.
• Support staff training on cyber security, secure data handling, breach prevention, and compliance obligations.
[What we are looking for]
- Knowledge in computer science, engineering or information technology, cyber security.
- Candidates with proven experience in managing cyber security and data protection operations and incident management.
- Strong understanding of information security and data protection principles, ISO 27001, PDPA, PCI-DSS Security Standards and cloud security standards.
- Preference will be given for cyber security and/or data protection recognised certifications such as CISSP, CISA, CISM, ISO27001, CIPP.
- Strong incident response, good communication, situational awareness and stakeholder management skills.
- Ability to analyse complex problems and recommend practical solutions.
As part of the shortlisting process for the role, you may be required to complete a medical declaration and / or undergo further assessment.