Chief Information Security Officer, Director
Confidential · Singapore, Singapore
Apply & track with Apply EdgeA leading regional financial institution is seeking an experienced, high-caliber Chief Information Security Officer (CISO) to lead the enterprise cybersecurity and technology risk management function.This executive position is responsible for setting the strategic security vision, safeguarding digital assets, and driving the end-to-end framework for information security, cyber defense, and technology risk governance. The CISO will manage a multidisciplinary organization covering both operational security capabilities and second-line risk governance, serving as the trusted advisor to executive leadership and the Board.
Key Responsibilities
Responsible for developing and driving the Bank’s technology risk governance, cyber resilience and operational risk frameworks to safeguard company’s information assets and businesses from cyber threats and operational lapses. Provide guidance and response leadership during a cyber crisis and significant operational risk events including coordination with relevant internal and external stakeholders. Obtain Board and Management Committee support in formulating effective risk frameworks and policies, standards and procedures, in line with the business goals, risk appetite and prevailing regulatory obligations. Foster a culture of diligence across all stakeholders in understanding technology, cyber and operational risk assessment and risk acceptance processes. Oversee periodic testing of operational, technology risk and cybersecurity controls to evaluate efficacy and effectiveness of implemented controls. Oversee KRI and KCI reporting on technology, operational and cyber risk governance to relevant management committees and Board. Keep abreast of the cyber threat landscape to proactively identify applicable cyber risks to the Bank Provide governance and ensure alignment and consolidation of KRI/KCI reporting at group level. Collaborate with the Bank’s regional teams to evaluate and embed group-level policy controls and security requirements across products, online services and infrastructure.
Requirements
Minimum 12 years of cyber, technology risk management; Strong experience in running large-scale technology risk or cyber security programmes in financial institutions, with a demonstrable track record in driving positive behavioral changes and risk reduction. Strong domain-level experience in cloud technologies including microservices and containers and cloud deployment and delivery models.Ability to work with cross-functional, multi-disciplined teams to formulate, institute and monitor adoption of security policies and procedures. Solid understanding and experience with using Generative Artificial Intelligence (GenAI) to solve problem statements and use cases in non-financial risk management. Good understanding of how Governance, Risk and Control (GRC) systems are designed and implemented in a financial institution, and experience with automated reporting and testing of key controls. Good understanding of both technology and business processes and the relationship between them. Proven track record of building inclusive and high quality security organizations, and successfully executing programs that meet the objectives of the business. Strong interpersonal and stakeholder management skills. Excellent verbal and written communication skills. Experience working in a fast-paced, fluid company. Singapore work experience is a plus. Certified Information Systems Security Professional (“CISSP”), Certified Information Security Manager (“CISM”), GIAC Security Essentials Certification (“GSEC”) and other relevant qualifications is a plus.