Head of Business Information Security & Cyber Risk
Kerry Consulting- Posted 8 hours ago
- Be among the first 10 applicants
Job Description
Our client is a leading multinational organisation with an established presence globally. As part of its continued investment in cybersecurity, the organisation is looking for an experienced security leader to oversee cybersecurity risk, governance and assurance across its regional businesses.
This is a senior role partnering closely with technology, risk and business leadership across multiple markets, providing strategic oversight of cybersecurity risk and security programmes across regional businesses.
You will work closely with senior stakeholders across Technology, Risk, Operations and the business to ensure cybersecurity risks are appropriately identified, managed and communicated. You will also lead a team of information security professionals supporting individual markets.
Key responsibilities:
- Oversee the implementation and effectiveness of cybersecurity programmes and controls across multiple regional markets.
- Assess cybersecurity risks and control effectiveness, identifying gaps and driving appropriate remediation.
- Provide security governance and assurance across major technology initiatives, including security assessments, vulnerability management and penetration testing.
- Monitor the regional cyber threat landscape and advise senior leadership on emerging risks and priorities.
- Coordinate with security operations, technology, privacy, legal and risk teams during significant cybersecurity incidents.
- Oversee cybersecurity regulatory requirements and support regulatory reviews, audits and related enquiries across the region.
- Establish meaningful cyber risk metrics and reporting for senior management, risk committees and other governance forums.
- Provide cybersecurity advice for major transformation initiatives, technology changes and corporate transactions.
- Oversee third-party cybersecurity risk and security policy exceptions where appropriate.
- Strengthen cybersecurity awareness and accountability across regional businesses.
- Build strong relationships with senior technology and business leaders, translating technical security matters into clear business risks and priorities.
- Lead, coach and develop a team of cybersecurity professionals.
Requirements:
- Approximately 15+ years of experience across cybersecurity, information security, technology risk or related disciplines.
- Strong experience leading cybersecurity programmes across multiple countries or business units within a large, complex organisation.
- Broad understanding of cybersecurity governance, risk management, security assurance and technical security controls.
- Good knowledge of recognised cybersecurity frameworks and standards.
- Experience working with cybersecurity regulatory requirements across Asia Pacific.
- Strong understanding of areas including application security, infrastructure security, vulnerability management and cyber incident management.
- Proven ability to engage senior executives and communicate cybersecurity risks to non-technical stakeholders.
- Previous experience presenting to senior management, risk committees and/or Boards would be advantageous.
- Experience within financial services or another highly regulated industry would be preferred.
- Relevant certifications such as CISSP, CISM or equivalent would be advantageous.
- Strong leadership, stakeholder management and influencing capabilities.
To apply:
If you're interested to apply or find out more, please share across your CV or reach out to Chen Yi at [Confidential Information] for a discussion. Due to anticipated high volume of applications, we regret to inform that only shortlisted candidates will be notified.
Reg: R1876389
Lic: 16S8060
More Info
Key Skills
cybersecurity regulatory requirements
cybersecurity frameworks and standards
technical security controls
cybersecurity governance
