Associate/Senior Associate (12 months contract), IT Auditor (AI, Cybersecurity controls)
Temasek Singapore, Singapore
Financial Services · 501-1,000 employees
About the role
The candidate will independently plan and execute risk-based audits covering IT, data, AI, and cybersecurity domains. They are responsible for identifying control gaps, assessing root causes, and producing management-ready audit reports with practical recommendations.
What they look for
Requirements
The role requires 3-5+ years of experience in IT audit, technology risk, or cybersecurity with strong hands-on execution skills. Candidates should be familiar with frameworks like ISO 27001 or NIST and possess relevant professional certifications such as CISA or CISSP.
Full description
Temasek is a global investment company headquartered in Singapore, with a net portfolio value of S$518 billion (US$401b, €350b, £304b, RMB2.77t) as at 31 March 2026. Our Purpose “So Every Generation Prospers” guides us to make a difference for today’s and future generations. We seek to build a resilient and forward-looking portfolio that will deliver good sustainable returns over the long term.
We have 13 offices in 9 countries around the world: Beijing, Hanoi, Mumbai, Shanghai, Shenzhen, and Singapore in Asia; and Brussels, London, Mexico City, New York, Paris, San Francisco, and Washington, DC outside Asia.
For more information on Temasek, please visit www.temasek.com.sg For Temasek Review 2026, please visit www.temasekreview.com.sg For Sustainability Report 2026, please visit www.temasek.com.sg/SR2026
Introduction
Role Purpose: We are seeking an experienced IT Auditor on a contract basis to support the execution of risk-based technology, data, AI, and cybersecurity audits. The role is hands-on, execution-focused, and suited to a candidate who can work independently with minimal supervision.
Scope of Role: Audit assignments will vary depending on the annual audit plan and emerging risk priorities, and may include personal data protection, data governance and security, AI governance and security, application security, infrastructure, and network security.
Responsibilities
Audit Execution and Assurance
- Independently plan and execute risk‑based IT, data, AI, and cybersecurity audits across business processes, applications, platforms, and infrastructure.
- Support integrated and thematic audits that cut across business, data, technology, and security domains.
- Perform walkthroughs, control design reviews, and operating effectiveness testing.
- Identify control gaps, assess root causes, and evaluate residual and systemic risks.
- Develop clear, defensible audit workpapers in line with internal audit standards and professional practices.
Technology, Data and Security Risk Coverage
The role may include assessing controls and risks across the following areas:
- Personal Data & Privacy
- Data lifecycle management (collection, use, disclosure, retention, disposal)
- Data protection impact assessments (DPIAs)
- Access controls, encryption, logging, and monitoring
- Data Governance & Security
- Data governance and accountability frameworks
- Data classification and secure handling
- Data access governance across platforms
- Data quality, lineage, and integrity
- Data leakage prevention and monitoring
- GenAI data governance, including training data controls and usage safeguards
- AI Governance & Application Security
- AI governance, oversight, and use‑case lifecycle management
- Security and technology risk controls over AI and GenAI systems
- AI application security testing, including:
- Review of model access controls, APIs, and integrations
- Identification of risks such as prompt injection, data leakage, insecure model access, and third‑party dependency risks
- Alignment with secure SDLC practices, architectural guardrails, and third‑party AI governance
- Infrastructure, Network & External Exposure Security
- Network and wireless security
- Host configuration, hardening, and patch management
- Firewalls, segmentation, and security monitoring
- Security reviews of corporate websites and externally exposed services
Reporting and Stakeholder Engagement
- Produce concise, management‑ready audit reports with practical, risk‑focused recommendations.
- Communicate complex technology, data, and AI risks in clear business terms.
- Work effectively with IT, data, security, and business stakeholders while maintaining auditor independence.
- Track remediation actions and validate closure of audit issues.
Requirements
- 3–5+ years experience in IT audit, technology risk, cybersecurity, or related roles.
- Strong hands‑on audit execution experience across data, AI, applications, and cybersecurity controls.
- Comfortable working in changing audit scopes and emerging risk areas.
- Familiarity with recognised frameworks (e.g. ISO 27001, NIST, data protection and security standards).
- Professional certifications (CISA, CISSP, CISM, CRISC, privacy or cloud certifications) preferred.
- Strong analytical skills, professional judgment, and written communication.
Similar roles
-
Senior Security Engineer - DevSecOps
carsales Sydney, New South Wales, Australia
-
Lead Cloud Security Engineer (DevSecOps)
Bilue Taguig, National Capital District, Philippines
-
Senior Security Engineer - Detection Engineering
LinkedIn United States · $129K–$212K/yr
-
Security Engineer
AlertMedia Austin, Texas, United States
-
F-35 Air Systems Information System Security Engineer | Active Secret clearance
General Dynamics Information Technology Eglin AFB, Florida, United States · $128K–$172K/yr
-
Full-Stack Engineers (Cybersecurity): Feedback On CI/CD Workflows
Terac United States · $218K/yr