We are looking for an experienced cybersecurity leader to lead our Group Cybersecurity & Technology Governance (GCTG) function, providing strategic leadership and independent oversight of cybersecurity, technology risk and governance across IOI Properties Group.
What You'll Do
- Lead the Group's cybersecurity strategy, technology governance framework, policies and standards, ensuring alignment with business priorities, regulatory requirements and risk appetite.
- Provide independent oversight and challenge over cybersecurity and technology risks across infrastructure, applications, cloud, digital solutions, automation, AI, data and emerging technologies.
- Establish and oversee enterprise-wide technology risk, cyber risk and control frameworks, including risk monitoring, remediation and escalation of material issues.
- Provide governance and oversight of cybersecurity incidents, threat monitoring, resilience and recovery, including crisis simulations and post-incident reviews.
- Partner closely with Group Infrastructure & Network (GIN) and Group Digital Solutions, Automation & AI (GDSA) to embed cybersecurity and technology governance requirements while maintaining clear accountability between governance and technology operations.
- Advise senior management and relevant Board/Management Committees on material cyber risks, emerging threats, incidents, regulatory developments and investment priorities.
- Lead and develop the GCTG team while strengthening cybersecurity awareness and risk culture across the Group.
What We're Looking For
- Bachelor's Degree in Cybersecurity, Computer Science, Information Technology, Information Systems, Engineering or related discipline.
- Minimum 12 years of relevant experience in cybersecurity, information security, technology risk or IT governance, with significant senior leadership or enterprise-wide governance experience.
- Strong experience across cybersecurity strategy, governance, risk management, incident response, technology resilience and risk oversight.
- Good understanding of infrastructure, cloud, enterprise applications, AI, data security, IAM, vulnerability management, OT/IoT and third-party technology risks.
- Strong ability to engage and influence senior management, Boards, auditors, regulators and technology stakeholders.
- Professional certifications such as CISSP, CISM, CRISC or CISA would be an advantage.
- Experience within property, real estate, retail, hospitality, infrastructure, smart buildings or other asset-intensive industries would be advantageous.