Apply Edge Start your job search

Head of Cyber Security

Yoma Bank · Yangon, Myanmar

Apply & track with Apply Edge

ROLE PURPOSEThe Executive Vice President of Cybersecurity leads the Bank’s enterprise Cybersecurity strategy, architecture, defence, assurance, and resilience. The role sets security direction, standards, and maturity roadmap to protect the Bank’s customers, data, technology, and digital services. As the senior Cybersecurity, the role provides strategic direction and independent challenge across major technology and digital initiatives. The role partners with Technology and Technology GRC to ensure cyber risks are understood, security is embedded into solutions, and controls remain effective. The role also provides expert advice and clear risk insights to support informed business decisions and strengthen the Bank’s overall cyber resilience.KEY RESPONSIBILITIESCybersecurity Strategy and Executive LeadershipDevelop and lead the Bank’s enterprise Cybersecurity strategy, multi-year roadmap and maturity priorities.Align Cybersecurity priorities with business objectives, risk appetite, regulatory expectations and technology transformation.Advise the CIO and senior management on cyber risks, emerging threats, capability gaps and investment needs.Set Cybersecurity performance measures, maturity targets and continuous-improvement priorities.Set the strategy, target capability, control objectives and investment priorities for designated enterprise Cybersecurity platforms, and oversee their coverage, effectiveness, maturity and lifecycle risks.Board, Regulatory and Stakeholder EngagementReport cyber posture, material risks, major incidents, control effectiveness and investment priorities in clear business language.Translate complex technical risks into business impact, management choices and recommended actions.Support the CIO in discussions with executives, Board-level committees, regulators, auditors and external assessors.Escalate material cyber risks, control weaknesses, overdue remediation and significant incidents through appropriate governance channels.Security Architecture and Security-by-DesignEstablish enterprise security architecture principles, standards, patterns and secure-design requirements.Act as the senior Cybersecurity design authority for material technology and digital initiatives.Embed security early into architecture, development, procurement, testing, deployment and change activities.Provide risk-based approval, conditional approval, recommendations or escalation for material security decisions.Ensure security exceptions and residual cyber risks are documented, accepted where appropriate and visible to relevant governance forums.Application, Cloud, Infrastructure and Platform SecurityOversee application security and DevSecOps practices across the software development lifecycle.Define secure coding, application and API security, software supply chain security and risk-based testing requirements.Set security requirements for infrastructure, network, endpoint, identity, cloud, container, data and enterprise-platform environments.Work with Infrastructure & Security Engineering and Platform Reliability & Engineering on control design, coverage and effectiveness.Promote appropriate automation and AI-enabled security capabilities without assigning routine administration to the EVP role.Cyber Defence, Incident Response and ResilienceSet the strategic direction for cyber defence, monitoring, detection, investigation, threat hunting and response capabilities.Lead the Cybersecurity response to material cyber incidents and guide escalation, containment, recovery and communication.Oversee vulnerability exposure, threat-led testing, security exercises and remediation of material cyber weaknesses.Lead cyber simulations, scenario exercises and crisis-response testing with relevant Technology, Risk, Legal, Compliance, Communications and Business Continuity stakeholders.Own Cybersecurity requirements and the cyber-incident dimension of resilience, while designated owners remain accountable for enterprise business continuity, disaster recovery and operational resilience.Security Assurance, Risk and Third-Party SecurityDefine Cybersecurity risk and control frameworks, policies, standards, baselines and technical requirements.Oversee risk assessments, security assessments, design reviews and technical assurance activities.Monitor material cyber risks, control weaknesses, exceptions and remediation progress.Set Cybersecurity requirements for material vendors, cloud providers, fintech partners and technology suppliers, including due diligence, procurement and contract input.Provide technical Cybersecurity expertise and evidence to Technology GRC without owning the broader Technology GRC framework.AI and Emerging Technology SecurityDefine Cybersecurity requirements for AI, generative AI, AI agents, automation, APIs, cloud-native technologies and other emerging capabilities.Assess material risks involving model access, data exposure, insecure integration, excessive permissions, secrets and third-party dependencies.Provide Cybersecurity review for AI-enabled use cases and platforms, and promote responsible use of AI and automation within Cybersecurity.Work with AI Governance, Data, Architecture, Platform, Development and Technology GRC stakeholders.Leadership and Capability ManagementLead and develop a high-performing Cybersecurity function with clear accountability across architecture, application security, cyber defence, technical assurance and cyber resilience.Build technical depth, leadership strength and succession capability across critical Cybersecurity roles.Manage Cybersecurity budgets, investments, vendors and strategic initiatives.Maintain appropriate separation between security design, implementation, operation, review, approval and independent Technology GRC assurance.Knowledge and SkillsEnterprise Cybersecurity strategy, security architecture, security-by-design and capability roadmap development.Cyber defence, security operations, cyber incident response, vulnerability exposure and cyber resilience.Application security, DevSecOps, cloud, infrastructure, platform, identity, data and third-party security.Cybersecurity risk assessment, control assurance, policies, standards and technical security requirements.AI, automation and emerging technology security.Executive communication, Board-level reporting, regulatory engagement and audit support.Strong leadership, stakeholder influence and ability to balance security, business delivery, resilience and cost.Education and Special TrainingBachelor's Degree in Computer Science, Cybersecurity, Information Technology, Engineering or a related discipline.Master's Degree in Cybersecurity, Information Technology, Business Administration or a related field is preferred.ExperienceMinimum 12 years of relevant experience across Cybersecurity, information security, security architecture, cyber defence, application security, cloud security or related technology leadership roles.Minimum 5 years of senior leadership experience managing Cybersecurity or information security functions.Proven experience developing enterprise Cybersecurity strategies, roadmaps, maturity plans and capability transformation.Strong practical experience across applications, infrastructure, cloud-native environments, enterprise platforms, security operations and emerging technologies.Experience in acting as a senior Cybersecurity design authority or security assurance leader for complex technology solutions.Experience in leading cyber incident response, security assurance, third-party security and cyber resilience activities.Experience in operating in a regulated industry, preferably banking, financial services, telecommunications or other critical-service environments.Experience in engaging with executives, Board-level forums, regulators, auditors, vendors and external assessors.LanguageMyanmar/EnglishProfessional CertificationsCISSP, CISM, CCSP or GIAC certifications.ISO 27001 Lead Implementer or Lead Auditor.Relevant security architecture, application security, incident response or offensive security certifications.CRISC or COBIT knowledge is advantageous but not mandatory