Key Responsibilities
1. Governance & Strategy
- Develop, maintain, and oversee the information security function, strategy and frameworks - in alignment with applicable standards such ISO 27001, NIST, etc.
- Establish, maintain and enforce security policies, standards, and procedures;
- Key subject matter expert on information security, provide relevant information security advise to senior management
- Reporting of security posture/KPIs to senior management
- Ensure alignment and adherence to group Ant International security policies and standards
- Collaborate and work with Ant International security team on relevant security risk assessments, security testings, and governance activities
2. Industry & Regulatory Standards
- Ensure compliance with applicable information security standards where required (e.g. PCI DSS, ISO27001, etc.)
- Primary liaison on information security for external auditors, external assessors, regulators (where relevant)
3. Risk Management
- Execute information security risk management program
- Ensure proper implementation of information security controls to mitigate security threats/risks
- Ensure proper monitoring of security risks, vulnerabilities, findings - and ensure timely & effective remediation
4. Security incident response & recovery
- Own and manage the end-to-end response to security incidents and data breaches, including coordination, escalation, investigation, containment, and reporting - in collaboration with required stakeholders
5. Lead security operations and implementation of relevant security domains.
- Able to lead and execute security engineering initiatives
- Plan and develop security architecture & framework,
- Lead and execute security operations (required to be hands on technically)
- Security operations including (but not limited to):
- Infrastructure/Network/Cybersecurity
- SOC Security Monitoring and Security Incident Response
- Security Engineering
- Application Security (including Application Security Testings, VAPT, Vulnerability Management)
- Cloud Security,
- Data & Endpoint Security (including EDR, DLP)
- Identification & Access Management
- Information security governance, risk management, compliance operations
- Third Party Security Risk Management
6.Security Culture & Awareness
- Deliver security awareness programs and foster a security-conscious culture.
- Security trainings and examinations for relevant stakeholders
Candidate Profile
Experience & Background
- 10 years in information security / cyber security operation, and risk management
- Previous experience as information security lead or similar roles
- Familiarity with relevant technology/cybersecurity regulatory requirements and standards will be beneficial (e.g. BNM RMiT, MAS TRM, ISO27001, PCI DSS, NIST, etc.)
- Experience leading implementation and operations of security domains will be a plus
- Strong technical foundation in cybersecurity, application security, data security, and incident response
Certifications
Skills & Competencies
- Strong communication skills
- Able to independently strategise, plan and execute information security programs
- Technically apt for security operations, security engineering, security architecture hands-on work
- Fluent in written/spoken English. Mandarin is a plus.
- Project & Risk Management: Demonstrated ability to lead complex security projects, handle incident response, and information security initiatives in regulated environments.