About this role
Key Responsibilities
Cybersecurity Leadership & Governance
- Develop and execute the enterprise cybersecurity strategy and roadmap
- Establish security governance, policies, and control frameworks.
- Lead cybersecurity transformation initiatives and continuous improvement programs.
- Provide strategic direction for security technologies, and cybersecurity capabilities.
- Establish and promote a cybersecurity awareness program across the organisation, including security training, phishing simulations, and awareness campaigns.
- Present cybersecurity strategy, risk posture, and key initiatives to senior management, risk committees, and the Board where applicable.
Technology Risk Management
- Establish and maintain the technology risk management framework.
- Oversee technology risk and control assessments
- Manage technology risk committees, risk reporting and Key Risk Indicators (KRIs).
- Oversee IT exemption management and risk acceptance processes.
- Manage IT audits, regulatory reviews, and other assessment engagements, and oversee the implementation of remediation programs.
- Drive continuous improvement initiatives to enhance technology risk management and governance practices.
- Lead and coordinate security drills and cyber resilience exercises.
Security Operations & Incident Response
- Provide executive oversight of Security Operations Centre (SOC) functions.
- Ensure effective 24x7 monitoring, threat detection, investigation, and incident response.
- Oversee security incident management, forensic investigations, root cause analysis, containment, and recovery activities.
- Direct threat intelligence, threat hunting, alert management, and use case development activities.
- Ensure timely management reporting on security events and operational effectiveness.
Security Engineering
- Lead the implementation of security engineering to deploy new security tools and processes.
- Ensure secure implementation of infrastructure security controls including firewalls, VPNs, endpoint security, and network security.
- Conduct the security assessment for new initiatives
- Oversee the operation of application security including DevSecOps, API security, container security, and CI/CD security.
- Govern security tool implementation and optimization including SIEM, EDR, SOAR, DLP, and vulnerability management technologies.
- Drive security automation, orchestration, and hardening initiatives.
- Oversee vulnerability assessment, penetration testing and security validation
- Provide security advisory
Identity & Access Management (IAM)
- Establish IAM governance, strategy, and operational controls.
- Oversee identity lifecycle management, authentication services, privileged access management, and access recertification programs.
- Manage the administration of privileged accounts to ensure they’re secured.
- Conduct day-to-day operation for user accounts including provisioning/deprovisioning, recertification, dormant ID management, etc
- Ensure segregation of duties controls are effectively implemented and monitored.
- Oversee key and certificate management operations.
- Lead IAM transformation and integration initiatives across the enterprise.
Third-Party Security Management
- Conduct the third-party cybersecurity assessment for key service providers.
- Oversee security assessments of vendors and external service providers.
- Monitor third-party security risks and remediation activities
Secured Room Management
- Manage the operation and administration of physical access controls for secured rooms.
- Conduct periodic security reviews to verify compliance with physical security requirements for secured rooms.
- Develop and enhance automated workflow for physical access request, approval, provisioning, and revocation processes.
Qualifications & Experience
Education
- Degree in Computer Science, Information Systems and Technology, or related discipline.
Experience
- 8+ years of information security and technology risk management experience.
- 10+ years in a senior leadership role managing multi-disciplinary technology teams.
- Proven experience leading Security Operations, Security Engineering, IAM, and Technology Risk functions.
- Experience reporting cybersecurity risk posture to senior executives and risk committees.
- Proven track record in cybersecurity transformation and security program leadership.
- Experience within financial services, government, or highly regulated environments is highly desirable.