Job Description
You will assess how emerging technologies, evolving attack techniques and threat actors may impact the Bank's control environment and provide independent, forward-looking insights on emerging cyber risks, identify potential control gaps, and recommend measures to strengthen the Bank's cyber resilience and preparedness against an increasingly complex threat landscape.
Job Responsibilities
- Emerging Threat Intelligence and Risk Assessment *Monitor the global cyber threat landscape and identify new and emerging threats that may impact the Bank. *Conduct horizon scanning and identify risks before they materialise into security incidents. *Assess risks associated with, but not limited to AI-enabled cyber attacks, Generative AI and Large Language Models (LLMs), Deepfake and synthetic identity fraud, Software supply chain compromises, Cloud-native threats, Quantum computing developments, Ransomware and advanced threat actor techniques, Zero-day vulnerabilities and emerging attack vectors. *Assess the relevance and potential impact of new threat vectors on the Bank's technology and security environment. *Translate emerging threats into practical risk scenarios, control requirements and remediation recommendations. B. Cyber Threat Assurance *Conduct independent assessments of the Bank's preparedness against emerging cyber threats. *Evaluate whether existing security controls remain effective against evolving attack techniques. *Identify control gaps, systemic weaknesses, and areas requiring heightened monitoring. *Perform thematic reviews across key cybersecurity and technology risk domains. C. Risk Scenario Development *Apply adversarial thinking techniques to assess how emerging threat actors may exploit weaknesses in the Bank's controls, processes and technology architecture. *Develop plausible attack narratives and future-state cyber risk scenarios. *Assess implications of emerging threats against MAS Notice FSM-N06 Cyber Hygiene, MAS Technology Risk Management (TRM) Guidelines, operational risk requirements and other relevant regulatory expectations. *Provide recommendations to strengthen preventative, detective, and responsive security capabilities. D. Independent Challenge & Reporting *Provide independent challenge to risk assessments, remediation plans, and control design decisions. *Present findings and recommendations to senior stakeholders and governance committees. *Produce high-quality reports highlighting emerging risks, assurance outcomes, and strategic recommendations. E. Reporting & Governance *Develop executive-level threat intelligence and emerging risk reports for senior management and governance committees. *Communicate complex cyber risks in business and operational resilience terms. *Present emerging threat assessments and control implications to relevant stakeholders. *Support escalation of significant risks, control gaps and thematic findings. *Track management actions and validate remediation effectiveness. F. Strategic Cyber Risk Advisory *Partner with cyber security, technology and risk teams to strengthen cyber resilience. *Provide advisory input on emerging technologies, AI adoption, cloud transformation and evolving threat landscapes. *Contribute to the development of assurance methodologies, threat assessment frameworks and operating procedures for the new function.
Job Skills
- Cyber-Threat-Intelligence
- Threat-Hunting
- Cyber-Risk-Management
- Mitre-Att&ck-Framework
- Cloud-Security
Job Requirements
- Degree in Cyber Security, Information Security, Computer Science, Information Technology or related discipline with 4 to 10 years of experience in two or more of the following: - Cyber Threat Intelligence - Cyber Defence / SOC Operations - Threat Hunting - Cyber Risk Management - Security Architecture - Cyber Assurance / Audit - Penetration Testing / Red Teaming - Technology Risk Consulting *Experience within banking, financial services, consulting or highly regulated industries is advantageous. Required Skills:- *Are naturally curious about emerging cyber threats, technologies and evolving attack techniques. *Apply critical thinking and are willing to challenge conventional assumptions and established practices. *Possess strong analytical, investigative and problem-solving capabilities. *Can translate complex technical concepts into clear, business-relevant insights and recommendations. *Are confident engaging senior stakeholders and influencing risk and security decisions. *Thrive in dynamic environments, navigate ambiguity effectively, and enjoy solving complex cyber risk challenges. Preferred Skills:- *Strong understanding of the following: - Modern cyber attack techniques and threat actor methodologies - MITRE ATT&CK framework, Attack path analysis, Cyber kill chain concepts - Threat intelligence platforms and intelligence lifecycle - Security controls and cyber defence strategies - Cloud security and modern technology architectures - Vulnerability management and attack surface management - Cybersecurity frameworks (NIST, ISO 27001, CIS Controls) - AI Security frameworks - AI and emerging technology security risks. Professional Certifications (Preferred):- - CISSP - CISM - CRISC - GCTI - GCIH - CEH - SANS Certifications Only shortlisted candidate(s) will be notified.