Open to Senior GRC Roles — Internal Audit, Cyber Engineering, Governance

Turning regulatory complexity into control that holds.

For the past 1.5 years, I've been at Protos Labs, a cyber agentic AI startup, in a blended customer success and GRC role - leading internal audits, owning our ISMS end-to-end, and driving our expansion from ISO 27001 into SOC 2 and CTM Level 3, including closing real gaps like implementing and re-testing controls. I have worked across a diverse client base including government, critical infrastructure, defense and intelligence, and private sector clients like finance and FMCG. I am known for being reliable and taking strong ownership of what I am entrusted with. Before this, I led growth at Crypto.com for about 4 years, then ran my own e-commerce business while transitioning into cybersecurity. Now I am seeking a new GRC role where I can keep building on my ISO and SOC2 experience across new markets and industries.

Christabel Lum
Christabel Lum
Cyber Engineering & GRC Lead · Singapore
CurrentlyCyber Engineering & GRC Lead, Protos Labs
LocationSingapore
StatusOpen to senior GRC roles
CertificationsCRISC & CISA — Dec 2026
Reach out

About

A mid-career move from growth into governance, risk, and compliance — bringing an operator's eye to audit and control work.

My career started in growth and marketing — over six years building and leading growth and operations functions, including scaling Crypto.com's Growth team from scratch to 20+ members and helping grow the app from 5M to 10M users in four months. That background in cross-functional leadership and operating at scale now underpins how I run compliance programs.

I made a deliberate mid-career switch into cybersecurity and GRC, bringing a self-starter mindset and a track record of adapting fast in high-growth environments. At Protos Labs, a Singapore-based Cyber AI company, I own audit readiness end to end — control implementation, policy development, evidence collection, and vendor/third-party risk assessment — while leading the shift from manual compliance tracking to automated GRC tooling (Sprinto) and scaling from one framework to several.

Alongside GRC, I manage vendor-side security questionnaires and risk assessments for enterprise clients, produce cyber threat intelligence reports, and contribute hands-on as a forward-deployed engineer. I'm on track to add ISACA's CRISC and CISA certifications by December 2026.

93
controls maintained through ISO 27001 surveillance audit — zero non-conformities
6+
years building growth & operations functions before the switch into GRC
4
multi-framework program: ISO 27001, SOC 2, ISO 42001 (AI), Cyber Trust Mark
2
in-progress tools shown below as live demos

Close the Gap (Whack-a-Mole)

Click the gaps before they slip through. 30 seconds — see how many you can close.

A mole pops up in a random square — click it before it ducks back down.

0
Closed
30
Seconds left
0
Best