Lead and manage the organization's Cyber Incident Response Team, including hands-on participation in incident response and recovery activities.
Oversee the Governance, Risk, and Compliance (GRC) function to support both internal operations and external client engagements.
Collaborate with IT infrastructure teams on the design, assessment, implementation, and review of security solutions and initiatives.
Evaluate, test, implement, and maintain enterprise cybersecurity tools and systems, ensuring they align with organizational needs and threat landscapes.
Develop, maintain, and review cybersecurity policies, procedures, standards, and frameworks to ensure compliance with relevant regulations and certifications (e.g. Cyber Trust Mark, Data Protection Trust Mark, PDPA).
Support the CDTO in preparing materials and reports for senior leadership, including participation in Audit and Risk Committee (ARC) meetings.
Drive periodic risk assessment exercises, maintain risk registers, and ensure timely reporting of cybersecurity risks and mitigation actions.
Requirements:
Experience: Minimum of 5 years in cybersecurity, including at least 1 years in a managerial or leadership role.
Certifications: Professional certifications such as CISSP, CISM, CRISC, or CISA are required. Additional credentials (e.g. GSEC, GIAC, ISO Lead Implementer) are advantageous.
Framework Knowledge: Familiarity with security and privacy standards and frameworks such as ISO/IEC 27001, ISO/IEC 27701, NIST Cybersecurity Framework, and PDPA requirements.
Technical Proficiency:
Hands-on experience with cybersecurity tools such as Tenable, KnowBe4, enterprise-grade EDR, DLP, and SIEM platforms.
Good understanding of IT infrastructure domains including endpoints, servers, databases, applications, and networking.
Exposure to cloud environments (especially AWS) and cloud security principles is an added advantage.
Soft Skills: Strong stakeholder engagement, written and verbal communication skills, and ability to present cybersecurity matters to senior leadership and board-level stakeholders.