New

Cybersecurity Consultant - Advisory (GRC)

Singapore

Bitdefender is a cybersecurity leader delivering best-in-class threat prevention, detection, and response solutions worldwide. Guardian over millions of consumer, enterprise, and government environments, Bitdefender is one of the industry’s most trusted experts for eliminating threats, protecting privacy, digital identity and data, and enabling cyber resilience. With deep investments in research and development, Bitdefender Labs discovers hundreds of new threats each minute and validates billions of threat queries daily. The company has pioneered breakthrough innovations in antimalware, IoT security, behavioral analytics, and artificial intelligence and its technology is licensed by more than 180 of the world’s most recognized technology brands. Founded in 2001, Bitdefender has customers in 170+ countries with offices around the world. For more information, visit https://www.bitdefender.com

About the Role & Team / Project:

As a Cybersecurity Consultant specializing in Governance Risk & Compliance, you will join the Cybersecurity Advisory team, part of Bitdefender’s Cybersecurity Services, the group that delivers Bitdefender’s expert-led services alongside the GravityZone, EDR/XDR and MDR product portfolio.

Bitdefender Cybersecurity Advisory Services is a suite of expert-led offerings that helps organisations tackle modern cybersecurity and compliance challenges across people, processes and technology, whether or not they use Bitdefender technology. The team has experiences delivering large variety of services, including compliance to such emerging frameworks like NIS 2 and CCSS, for small and large organizations, as well as serving a large pool of government agencies.

In this role you will lead and deliver client engagements across Singapore and the wider region, and support global projects in Europe and the US. You will work directly with client CISOs, security managers and executive stakeholders, and closely with colleagues across Offensive Security, MDR, Product, Sales and Partner teams. Singapore remains the team’s strongest stream of advisory projects, so you will see a high volume of varied, hands-on work.

This is a growing, globally distributed team. You will have real scope to shape how services are scoped, packaged and delivered — not just to execute an existing playbook.

Key Responsibilities:

Client delivery

  • Plan, scope and deliver GRC engagements end to end — Cybersecurity Reviews, ISO/IEC 27001 internal audits, compliance readiness assessments, risk assessments and policy framework development.
  • Design and facilitate Incident Response Tabletop Exercises: build tailored scenarios reflecting each client’s real risks, run live injections and artefacts, and guide technical and non-technical stakeholders through high-pressure decision-making.
  • Conduct interviews, walkthroughs and documentation reviews; analyse findings against recognised frameworks; and produce clear, risk-rated reports with practical remediation roadmaps.
  • Present findings and executive briefings to senior leadership and boards, translating technical detail into business risk and investment priorities.
  • Act as a trusted advisor on retainer engagements, adapting to shifting client priorities across strategic and operational work.

Team and practice growth

  • Provide quality oversight and mentoring to associate consultants, and contribute to peer review of deliverables.
  • Help shape the direction of the practice — improving methodologies, templates and delivery standards, and developing new service propositions.
  • Share knowledge through internal enablement sessions, reflection workshops and thought leadership.

Collaboration with Product and Go-To-Market

  • Partner with Product teams to build synergy between Bitdefender’s technology and advisory services.
  • Support pre-sales scoping, proposals, tenders and RFPs with technical and commercial input.
  • Contribute to company-wide go-to-market activity: partner enablement, webinars, datasheets, case studies and speaking at industry events.

Qualifications & Skills:

Must-have:

  • 3–4 years of experience in a GRC consulting role, delivering client-facing advisory or assessment engagements.
  • Demonstrated experience designing and delivering incident response tabletop exercises.
  • Demonstrated experience conducting ISO/IEC 27001 internal audits.
  • ISO/IEC 27001 Lead Auditor certification.
  • Fluent English and Chinese, for client-facing communication with regional and global stakeholders.
  • Willingness to work flexible hours — occasional early mornings or late evenings — to support clients and colleagues across European and US time zones.
  • Strong report writing and presentation skills, with the ability to communicate risk clearly to both technical teams and executives.

Nice-to-have:

  • Additional certifications such as CISM, CISSP, CCISO, CRISC, CCSK, CCSP or ISO/IEC 27001 Lead Implementer.
  • Familiarity with NIST CSF 2.0, CIS Controls, SOC 2, NIS 2, DORA, CCSS, or Singapore-specific schemes such as the CSA Cyber Trust Mark, IMDA and MAS-TRM.
  • Experience with third-party and supply chain risk management frameworks.
  • Exposure to cloud security assessment, DevSecOps or security architecture review.
  • Experience supporting pre-sales, proposals or tender responses.
  • Experience mentoring or coaching junior consultants.

Why Bitdefender Cybersecurity Advisory?

A fast-growing global team. The Cybersecurity Advisory practice is expanding across APAC, Europe and the US, with consultants based in Singapore, Indonesia and Romania serving clients in 170+ countries. Joining now means real influence over how the team grows and where it goes next.

Genuine variety of work. One month you might run an ISO 27001 internal audit for a regional insurer, the next facilitate a board-level ransomware simulation, then help a fast-scaling robotics company through certification. Our clients span aviation, financial services, government-linked organisations, education and technology.

Product and services under one roof. You will work alongside Product, Engineering, MDR and Offensive Security teams and contribute to the company-wide go-to-market that brings product and security services together — a perspective consultancies alone cannot offer.

Flexible ways of working. Hybrid onsite and remote working, with flexibility around the hours you need to support global engagements.

Learn from recognised practitioners. Our consultants hold credentials including CCISO, CISSP, CISM, CSSLP, CCSK and ISO/IEC 27001 Lead Auditor, and represent Bitdefender at conferences such as GovWare, GovInsider and ISACA events.

A mission-driven company. Launched in 2001, Bitdefender is a global cybersecurity leader protecting millions of consumer, business and government environments, with technology licensed by more than 180 of the world’s most recognised technology brands. We foster a culture of innovation, ownership and continuous learning.

 

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...

Describe a tabletop exercise you designed or facilitated. Please cover: the scenario and why you chose it, who participated (technical teams, leadership, or both), how you introduced pressure or complications during the session, and one gap the exercise surfaced that the client acted on.

How many ISO/IEC 27001 internal audits have you led, and in what capacity (lead auditor, team member, or supporting)? Pick one and briefly describe the scope, a significant non-conformity you raised, and how you handled disagreement from the auditee.

Please indicate your current salary & expected monthly salary in (GROSS & in SGD)

Please indicate any relevant certification that you have