Free with a WorkJio account: we compare your profile with this job and show what you already meet.
Share with a friend
Start
Not stated
Work mode
On-site
Experience
Experienced
About the role
A senior information security role within the Group Technology function of a bank, serving as the first line of defence for cybersecurity risk management. The position drives regulatory compliance, governance, awareness and training, and data protection across the organisation, working closely with technology, risk and regional security teams. It suits an experienced information security professional with a background in financial or technology environments.
What you'll do
Develop cybersecurity standards and guidelines
Assess and validate cyber risks and controls
Report and provide assurance on the cybersecurity programme to risk committees
Review and assess the cybersecurity policy architecture against new and emerging legislation, regulations and policies
Review and update information security standards to meet regulatory requirements
Monitor new cybersecurity legislation and regulations with regional security teams and assess impact on the bank's security policy architecture
Work with Line of Business Technology units to drive change management for regulatory compliance
Manage material changes to critical systems and conduct risk control self assessments
Conduct annual cybersecurity risk assessments for key bank systems
Engage external auditors and certification bodies for audits under Cyber Trust Mark, ISO27000, SOC2 and the Cybersecurity Act
Act as focal point for international centres on information security matters
Develop and maintain security metrics and visualisation for reporting to senior management and the Board
Automate extraction, transformation and loading of raw security events for metrics and graphs
Establish a framework to organise, manage and archive security data
Generate quarterly reports and insights on security trends
Conduct regular phishing exercises and disseminate cybersecurity content
Develop targeted training content with control functions
Drive the annual cybersecurity awareness campaign
Design and implement data protection controls across web, email, network and endpoint channels
Work with Line of Business Technology on technology enablers for secure data handling
Review and investigate data loss events and refer substantiated cases to HR
Continuously enhance data protection controls
Provide management reporting on data loss matters to risk committees
Drive implementation of data analytics and machine learning to prioritise data loss events
Identify suspicious activities and misuse of applications and customer data
Oversee inhouse development of machine learning models and the investigation platform
Drive development of data visualisation techniques for review and investigation
Enhance the investigation platform to meet user needs
Good to know
Location: Singapore - East
Full time position
Requirements
At least 15 years of information security experience
Background in a financial or technology environment
Experience implementing a programme for collating, managing and reporting security metrics such as vulnerabilities, penetration testing findings, alerts and incidents
Familiarity with information security frameworks including ISO27000 and NIST800-53
Knowledge of regulations such as the Cybersecurity Act, Technology Risk Management Guidelines and Personal Data Protection Act
Jio can write this application for you
Jio reads this job and your profile, then writes a short letter in your words. You read it, change anything, and send it yourself. Nothing is sent until you say so.