We are looking for an experienced Cybersecurity & Technology Risk Manager to lead the organisation's security, technology risk and resilience agenda across enterprise technology, digital platforms and third-party environments.
This is a broad security lead role combining strategy, governance and hands-on oversight. The successful candidate will work closely with Technology and business stakeholders to strengthen cyber resilience, manage technology risks and enable secure digital innovation. This is an individual contributor role.
Key Responsibilities:
- Develop and execute the cybersecurity and technology risk strategy, ensuring alignment with business priorities and broader enterprise security standards.
- Establish and enhance security policies, frameworks and controls aligned with NIST, ISO 27001, CIS and other relevant industry standards.
- Oversee security operations across SIEM/SOC, threat detection and response, vulnerability management, endpoint, network and cloud security.
- Manage technology and cyber risk assessments, remediation programmes and control assurance activities.
- Ensure compliance with relevant regulatory and data protection requirements, including PDPA and PCI DSS.
- Lead cyber incident response, crisis management, business continuity and disaster recovery readiness.
- Establish and maintain third-party cybersecurity risk management, including security assessments, due diligence and ongoing monitoring.
- Strengthen security across cloud, SaaS, APIs, mobile applications, digital platforms and end-user environments.
- Drive security-by-design and DevSecOps practices across technology and application initiatives.
- Define security KRIs, KPIs and control metrics, providing clear reporting on cyber risk and security posture to senior management.
- Leverage automation, AI and continuous control monitoring to improve security operations and assurance.
- Partner with regional/global security teams and local stakeholders to ensure enterprise security standards are appropriately implemented.
- Drive security awareness and promote a strong risk and security culture across the organisation.
Requirements:
- Bachelor's degree in Information Security, Computer Science, Engineering or a related discipline.
- Approximately 6-12 years of experience across cybersecurity, technology risk or information security
- Broad understanding of security operations, cloud security, technology risk, incident response, vulnerability management, data protection and third-party risk.
- Experience managing security within complex, customer-facing or operationally intensive environments.
- Good understanding of PDPA, PCI DSS, NIST, ISO 27001 and CIS Controls.
- Experience supporting digital transformation and applying security-by-design principles to applications and technology platforms.
- Ability to translate technical security risks into clear business impact and practical remediation actions.
- Strong stakeholder management and communication skills, with the ability to influence senior Technology and business leaders.
- Certifications such as CISSP, CISM, CRISC, CCSP, ISO 27001 or equivalent would be advantageous.
To apply:
If you're interested to apply or find out more, please share across your CV or reach out to Chen Yi at [Confidential Information] for a discussion. Due to anticipated high volume of applications, we regret to inform that only shortlisted candidates will be notified.
Reg: R1876389
Lic: 16S8060