
Search by job, company or skills
Here's your opportunity to take on a strategic leadership role, working closely with senior management to drive technology, cybersecurity, and digital innovation within a MAS-licensed Major Payment Institution.
We are seeking a highly driven and hands-on IT Head who goes beyond traditional infrastructure management - someone who can lead technology strategy, strengthen cybersecurity posture, and enable scalable payment solutions in a regulated fintech environment.
This role is ideal for a candidate who is equally comfortable:
Designing and overseeing secure, resilient IT architecture
Driving MAS TRM and Cyber Hygiene compliance frameworks
Leading system innovation and payment platform scalability
Partnering with business and risk stakeholders to embed technology risk governance
You will work closely with senior leadership, gaining direct exposure to regulatory expectations, strategic decision-making, and business expansion initiatives, while serving as the technology gatekeeper of the Company.
The Head of Information Technology is responsible for the overall technology strategy, IT governance, cybersecurity posture, and operational resilience of Overcross Pte. Ltd. as a MAS-licensed Major Payment Institution (MPI).
The role ensures that all IT systems, infrastructure, and processes are:
Secure, resilient, and scalable
Fully compliant with MAS Technology Risk Management (TRM) Guidelines, PSN01, and other applicable regulatory requirements
Aligned with business objectives and cross-border payment operations
Develop and implement the Company's IT strategy and roadmap, aligned with business growth and regulatory expectations
Establish and maintain a robust IT governance framework, including policies, procedures, and controls
Ensure alignment with:
MAS TRM Guidelines
MAS Cyber Hygiene Notice
Payment Services Act (PSA) requirements
Report IT risk posture and incidents to Senior Management and the Board
Design and maintain a comprehensive cybersecurity framework, including:
Network security
Endpoint protection
Data encryption
Identity and access management (IAM)
Implement defence-in-depth strategies and continuous monitoring controls
Conduct:
Vulnerability assessments (VA)
Penetration testing (PT)
Security audits
Ensure timely remediation of identified vulnerabilities
Ensure full compliance with:
MAS TRM Guidelines
MAS Notice on Cyber Hygiene
MAS Outsourcing Guidelines (where applicable)
Maintain proper documentation for:
System architecture
Security controls
Incident logs
Audit trails
Support regulatory inspections and audits (internal and external)
Oversee daily IT operations, including:
Core payment systems
Infrastructure (cloud/on-premise)
Networks and databases
Ensure high system availability and uptime (≥99.9%)
Implement capacity planning and performance monitoring
Develop and maintain:
Business Continuity Plan (BCP)
Disaster Recovery (DR) framework
Ensure systems meet Recovery Time Objective (RTO) and Recovery Point Objective (RPO) requirements
Conduct regular BCP/DR testing and scenario simulations
Oversee all technology vendors and outsourced service providers
Ensure compliance with MAS Outsourcing Guidelines, including:
Due diligence assessments
Risk assessments (material outsourcing)
Service level monitoring
Maintain outsourcing register and reporting
Ensure compliance with Personal Data Protection Act (PDPA)
Implement strong data classification, retention, and protection controls
Oversee secure handling of customer and transaction data
Establish and manage IT incident response framework
Ensure:
Timely detection and escalation of incidents
Proper root cause analysis (RCA)
Regulatory reporting to MAS where required
Maintain incident logs and post-incident review documentation
Work closely with:
Compliance (AML/CFT systems, screening tools)
Risk Management (technology risk assessments)
Support implementation of:
Transaction monitoring systems
Sanctions screening systems
Fraud detection tools
Lead and manage the IT team, including:
Infrastructure engineers
Security specialists
Developers (if applicable)
Build a strong risk-aware and security-first culture
Provide training on cybersecurity awareness and IT controls
100% compliance with MAS TRM and Cyber Hygiene requirements
Zero major cybersecurity breaches
System uptime ≥ 99.9%
Timely closure of audit findings
Successful completion of regulatory inspections
Effective BCP/DR testing outcomes
Bachelor's degree in Information Technology, Computer Science, or related field
Relevant certifications preferred:
CISSP / CISM / CISA
ISO 27001 Lead Implementer/Auditor
Minimum 8-12 years of IT experience, with at least 5 years in a leadership role
Experience in:
Fintech / Payments / Banking environment
MAS-regulated institutions (preferred)
Strong familiarity with:
MAS TRM Guidelines
Cybersecurity frameworks (NIST, ISO 27001)
Cloud platforms (AWS, Azure, GCP)
Network security and architecture
Database and system administration
Cybersecurity tools and monitoring systems
API and payment system integrations
Strong stakeholder management and communication skills
High level of integrity and accountability
Ability to operate in a regulated and fast-paced fintech environment
Strategic thinking with hands-on execution capability
The candidate must:
Meet MAS Fit and Proper Criteria (FSG-G01)
Demonstrate sound integrity, competence, and financial standing
Have no adverse regulatory or criminal records
This role is considered a critical function under MAS expectations
Subject to internal governance approval and possible regulatory review
Required to support MAS inspections, audits, and regulatory submissions
Job ID: 144617129