Senior Director IT,Information Security

2 weeks ago


Singapore APL LOGISTICS LTD Full time
Roles & Responsibilities

The Senior Director IT is responsible for establishing and maintaining the information security program to ensure that information assets and associated technology, applications, systems, infrastructure and processes are adequately protected in the digital ecosystem in which we operate. The individual is responsible for identifying, evaluating and reporting on legal and regulatory, compliance, IT and cybersecurity risk to information assets, while supporting and advancing business objectives.


Description

Establish Governance and Build Knowledge

  • Facilitate an information security governance structure through the implementation of a hierarchical governance program, including the formation of an information security steering committee or advisory board.
  • Provide regular reporting on the current status of the information security program to enterprise risk teams and senior business leaders
  • Work with the vendor management office to ensure that information security requirements are included in contracts by liaising with vendor management and procurement organizations.
  • Create and manage a targeted information security awareness training program for all employees, contractors and approved system users, and establish metrics to measure the effectiveness of this security training program for the different audiences.
  • Understand and interact with related disciplines through committees to ensure the consistent application of policies and standards across all technology projects, systems and services, including privacy, risk management, compliance and business continuity management.
  • Provide clear risk mitigating directives for projects with components in IT, including the mandatory application of controls.

Develop the Frameworks

  • Develop and enhance an up-to-date information security management framework based on one of the following: International Organization for Standardization (ISO) 2700X, ITIL, ENISA, ISA-62443, COBIT/Risk IT and National Institute of Standards and Technology (NIST) Cybersecurity Framework.
  • Create and manage a unified and flexible control framework to integrate and normalize the wide variety and ever-changing requirements resulting from global laws, standards and regulations.
  • Develop and maintain a document framework of continuously up-to-date information security policies, standards and guidelines. Oversee the approval and publication of these information security policies and practices.
  • Create a framework for roles and responsibilities with regard to information ownership, classification, accountability and protection of information assets.
  • Facilitate a metrics and reporting framework to measure the efficiency and effectiveness of the program, facilitate appropriate resource allocation, and increase the maturity of the information security, and review it with stakeholders at the executive and board levels.

Architecture/Engineering Support

  • Work with IT staff to ensure that security is factored into the evaluation, selection, installation and configuration of hardware, applications and software.
  • Recommend and coordinate the implementation of technical controls to support and enforce defined security policies.
  • Research, evaluate, design, test, recommend or plan the implementation of new or updated information security hardware or software, and analyze its impact on the existing environment; provide technical and managerial expertise for the administration of security tools.
  • Work with the enterprise architecture team to ensure that there is a convergence of business, technical and security requirements; liaise with IT management to align existing technical installed base and skills with future architectural requirements.

Operational Execution

  • Coordinate, measure and report on the technical aspects of security management.
  • Manage outsourced vendors that provide information security functions for compliance with contracted service-level agreements.
  • Manage and coordinate operational components of incident management, including detection, response and reporting.
  • Maintain a knowledgebase comprising a technical reference library, security advisories and alerts, information on security trends and practices, and laws and regulations.
  • Manage the day-to-day activities of threat and vulnerability management, identify risk tolerances, recommend treatment plans and communicate information about residual risk.
  • Manage security projects and provide expert guidance on security matters for other IT projects.
  • Assist and guide the disaster recovery planning team in the selection of recovery strategies and the development, testing and maintenance of disaster recovery plans.
  • Ensure audit trails, system logs and other monitoring data sources are reviewed periodically and are in compliance with policies and audit requirements.
  • Design, coordinate and oversee security testing procedures to verify the security of systems, networks and applications, and manage the remediation of identified risks.

Qualifications

  • Bachelor’s Degree in Engineering, Computer Science, Information Systems, or related discipline required.
  • Master’s Degree in a related field is preferred.
  • Professional security management certification is desirable, such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA) or other similar credentials

Experiences

  • A minimum of ten years of IT experience, with seven years in an information security role and at least five years in a managerial capacity is required.
  • Experience working with legal, audit and compliance staff is preferred.
  • Experience developing and maintaining policies, procedures, standards and guidelines is required.
  • Familiarity with applicable legal and regulatory requirements, including, but not limited to, the U.S. Sarbanes-Oxley Act, the U.S. Health Insurance Portability and Accountability Act (HIPAA), the European Union Privacy Directive, and the Japanese Financial Instruments and Exchange Law ("J-SOX").

Skill Sets

  • Excellent analytical skills, the ability to manage multiple projects under strict timelines, as well as the ability to work well in a demanding, dynamic environment and meet overall objectives
  • Project management skills: financial/budget management, scheduling and resource management
  • Ability to lead and motivate the information security team to achieve tactical and strategic goals, even when only "dotted line" reporting lines exist
  • A master of influencing entities and decisions in situations where no formal reporting structures exist, but achieving the desirable outcome is vital
  • Excellent communication, interpersonal and collaborative skills. Experience working with a multi-continent technical team preferred
  • High degree of initiative, dependability and ability to work with little supervision while being resilient to change

Technical Competencies

  • Experience with common information security management frameworks, such as International Standards Organization (ISO) 2700x, the IT Infrastructure Library (ITIL) and Control Objectives for Information and Related Technology (COBIT) frameworks
  • An understanding of operating system internals and network protocols.
  • Familiarity with the principles of cryptography and cryptanalysis.
  • Experience in application technology security testing (white box, black box and code review).
  • Experience in system technology security testing (vulnerability scanning and penetration testing).

Tell employers what skills you have

Information Security
Remediation
Vulnerability Scanning
Vulnerability Management
Risk Management
Security Management
Penetration Testing
CISA
Information Security Management
ITIL
Security Awareness
Incident Management
CISSP

  • Singapore APL LOGISTICS LTD Full time

    About the RoleAPL LOGISTICS LTD is seeking a highly experienced Senior Director to lead our Information Security team. The successful candidate will be responsible for establishing and maintaining a robust information security program, ensuring that our digital assets are adequately protected.The role requires strong leadership skills, with the ability to...


  • Singapore U3 Full time

    Job Title: Senior Information Security Specialist At U3, we are seeking a highly skilled Senior Information Security Specialist to join our team. The ideal candidate will have a strong background in information security, risk management, and compliance. This role will be responsible for supporting the Director, Regional Information Security and Data...


  • Singapore Careers@Gov Full time

    Job Title: Chief Information Security DirectorThis role offers a challenging and rewarding opportunity for a seasoned information security leader to join our team at Careers@Gov.


  • Singapore SINGAPORE SECURITY FORCE PTE. LTD. Full time

    Job Title: Security Operations DirectorSingapore Security Force Pte. Ltd. is seeking an experienced and skilled Security Operations Director to lead our security operations team in delivering exceptional service to our clients.About the Role:This is a critical leadership position that requires a strong understanding of security industry practices, safety...


  • Singapore SINGAPORE SECURITY FORCE PTE. LTD. Full time

    Job Title: Sales Director for Security ServicesCompany Overview:Singapore Security Force PTE. LTD.About the Job:We are seeking a highly skilled and experienced Sales Director to join our team in Singapore. As a key member of our sales department, you will be responsible for driving revenue growth by selling security manpower services to corporate,...


  • Singapore SINGAPORE SECURITY FORCE PTE. LTD. Full time

    Job Title: Sales Director for Security SolutionsOverview: We are seeking an experienced sales professional to lead our security solutions team at SINGAPORE SECURITY FORCE PTE. LTD. As a Sales Director, you will be responsible for driving revenue growth and expanding our client base in the security industry.Salary: $120,000 - $180,000 per annum, depending on...


  • Singapore ASCENTIAA SECURITY MANAGEMENT PTE. LTD. Full time

    About the RoleWe are seeking a highly skilled and experienced Executive Security Director to join our team at Ascentiaa Security Management PTE. LTD.Job Description:As an Executive Security Director, you will be responsible for handling day-to-day operations, conducting meetings with clients, and ensuring the security of our premises. You will also be...

  • Sales Director

    2 weeks ago


    Singapore SINGAPORE SECURITY FORCE PTE. LTD. Full time

    Sales Director - Security ServicesWe are seeking a seasoned Sales Director to lead our security services team in Singapore. As a key member of our management team, you will be responsible for driving revenue growth and expanding our client base.Job Description:The Sales Director will oversee the sales strategy and business development initiatives for our...


  • Singapore ST ENGINEERING INFO-SECURITY PTE. LTD. Full time

    Technical Leadership OpportunityST ENGINEERING INFO-SECURITY PTE. LTD.We are a leading technology and engineering group with global presence, serving customers in over 100 countries.Job SummaryWe seek an experienced Technical Director to provide leadership for our cybersecurity product capabilities development and sustenance.ResponsibilitiesProvide technical...


  • Singapore RECRUIT EXPERT PTE. LTD. Full time

    At RECRUIT EXPERT PTE. LTD., we are seeking a highly skilled Senior Information Security Specialist to join our team.Job DescriptionWe are a financial institution specializing in accepting fixed and savings deposits and providing loans and credit facilities to individuals and Small and Medium Enterprises (SMEs).The successful candidate will be responsible...


  • Singapore SMART INFORMATION MANAGEMENT SYSTEMS PRIVATE LIMITED Full time

    Roles & ResponsibilitiesKey Responsibilities:Cybersecurity Risk Assessment & Mitigation: Cyber Risk Assessment: Conduct comprehensive cyber risk assessments in support of technology initiatives, identifying IT-related risks and recommending appropriate security controls to mitigate those risks. Risk Monitoring & Management: Continuously...


  • Singapore SMART INFORMATION MANAGEMENT SYSTEMS PRIVATE LIMITED Full time

    Roles & ResponsibilitiesKey Responsibilities:Cybersecurity Risk Assessment & Mitigation: Cyber Risk Assessment: Conduct comprehensive cyber risk assessments in support of technology initiatives, identifying IT-related risks and recommending appropriate security controls to mitigate those risks. Risk Monitoring & Management: Continuously...


  • Singapore KS CONSULTING PTE. LTD. Full time

    Roles & ResponsibilitiesAs a Business Information Security Officer, you will play a key role in proactively managing the information security and Data privacy landscape within the organization. Your expertise will help guide strategic decision-making on technology risk and security matters, ensuring robust IT security architecture, practices, and compliance...


  • Singapore ZENITH INFOTECH (S) PTE LTD. Full time

    Job OverviewZENITH INFOTECH (S) PTE LTD. is seeking a highly skilled Senior Information Security Specialist to join our team. In this role, you will be responsible for designing and implementing a comprehensive security architecture blueprint to protect our applications and infrastructure.About the RoleThis is a 12-month contract position that requires the...


  • Singapore LUXOFT INFORMATION TECHNOLOGY (SINGAPORE) PTE. LTD. Full time

    Job OverviewLUXOFT INFORMATION TECHNOLOGY (SINGAPORE) PTE. LTD. is seeking a highly skilled and experienced professional to fill the role of Senior Automotive Solutions Director in Singapore.


  • Singapore Citi Full time

    Job Summary:This Senior Information Security Analyst role is an intermediate level position responsible for leading efforts to prevent, monitor and respond to information/data breaches and cyber-attacks. The overall objective of this role is to ensure the execution of Information Security directives and activities in alignment with Citi's data security...


  • Singapore This is an IT support group Full time

    Work Location: Singapore, Singapore Hours: 40Line of Business: Technology Solutions Pay Details: We’re committed to providing fair and equitable compensation to all our colleagues. As a candidate, we encourage you to have an open dialogue with a member of our HR Team and ask compensation related questions, including pay details for this role. Job...


  • Singapore PAYPAL PTE. LTD. Full time

    Join PayPal PTE. LTD. as a Senior Information Security Architect and embark on an exciting career journey!About the RoleWe are seeking a highly skilled and experienced Senior Information Security Architect to lead our security architecture team in designing, implementing, and maintaining robust security solutions that protect our infrastructure and end-user...


  • Singapore PREMIER SECURITY CO-OPERATIVE LTD Full time

    We are seeking a highly skilled and experienced Senior Security Operations Manager to join our team at Premier Security Co-operative Ltd.Job SummaryThis role is responsible for managing security personnel in security surveillance, coaching, conducting team briefings, supervising, compiling incident reports, executing evacuation plans or exercises, handling...


  • Singapore United Overseas Bank Full time

    Job SummaryWe are seeking an experienced Senior Information Security Architect to join our team at United Overseas Bank. As a trusted partner and key enabler in Group Technology and Operations, you will work with GTO teams to design, implement, and operate the bank's IT systems and applications.About the RoleThe Security Architect will develop security...