Employment Type: Permanent
We are seeking an experienced and visionary Cybersecurity Lead to head our cybersecurity vertical and drive enterprise-wide security strategy, governance, and operations. This is a senior leadership role responsible for building, leading, and evolving a comprehensive cybersecurity program to safeguard critical assets, infrastructure, and data across the organization.
Key Responsibilities:
Strategic Leadership
- Define and own the cybersecurity strategy, roadmap, and budget to align with organizational objectives.
- Advise executive management on emerging threats, regulatory requirements, and industry best practices.
- Serve as the primary point of contact for all cybersecurity-related matters.
Cybersecurity Operations
- Oversee security operations, including threat detection, incident response, vulnerability management, and risk assessments.
- Drive the implementation of Zero Trust architecture, cloud security frameworks, and modern security tooling.
- Establish and maintain robust security monitoring, SIEM, and SOC processes.
Governance, Risk & Compliance (GRC)
- Ensure compliance with relevant regulations, standards, and frameworks (ISO 27001, NIST, CIS, PDPA, MAS TRM, etc.).
- Lead security audits, risk assessments, and policy development.
- Work closely with internal stakeholders to embed security into business processes and technology initiatives.
Team Leadership & Collaboration
- Build, mentor, and lead a high-performing cybersecurity team.
- Collaborate with IT, product, engineering, and business units to ensure secure-by-design solutions.
- Drive security awareness training across the organization to foster a security-first culture.
Innovation & Continuous Improvement
- Stay ahead of the evolving threat landscape and proactively recommend technology and process improvements.
- Evaluate and implement cutting-edge security solutions, including AI/ML-driven security analytics.
Requirements:
- 10-15 years of experience in cybersecurity, with at least 5 years in a leadership or managerial role.
- Proven track record of designing and leading enterprise security programs across hybrid cloud and on-premises environments.
- Deep knowledge of security architecture, incident response, identity & access management, data protection, and network security.
- Familiarity with industry regulations and compliance frameworks (ISO, NIST, CIS, SOC 2, MAS TRM, PDPA).
- Strong stakeholder management and communication skills, with the ability to influence CxO-level decisions.
- Professional certifications preferred (CISSP, CISM, CISA, CCSP, CEH, etc.).