Senior Manager, Information Security Governance

1 month ago


Singapore AIA Singapore Private Limited Full time
At AIA we've started an exciting movement to create a healthier, more sustainable future for everyone.

As pioneering innovators for over 100 years, we're now transforming our organisation to be faster, simpler and more connected. Because we want to be even better equipped to develop digital solutions and experiences that help more people live Healthier, Longer, Better Lives.

To get there, we need people with tech/digital/analytics expertise and passion to help develop positive, sustainable change through digitally enhanced experiences that will impact the lives of millions of people and create a healthier future for everyone.

If you believe in developing a better tomorrow, read on.

About the Role

This role is responsible for delivering the AIA Singapore Line 1 GRC to the organisation, from coordination Governance reporting activities, Operational Technology Risk Management, Third Party Risk management and Compliance and Audit functions prescribed from AIA Group, industry regulations and the Monetary Authority of Singapore (MAS). This role is also responsible for AIA's Cyber Security Awareness training.

This leadership role is instrumental in maintaining AIA external stakeholder relations, working directly to AIA Singapore Information Security Head, the individual must be an exceptional communicator on both technical and non-technical issues for Line 2, Audit, Executive Committee, Board and Regulator communications. The occupant needs to lead and mentor a team of Cyber GRC professionals as they navigate scheduled and ad-hoc inspections or audits of AIA's controls by applying their professional and well-rounded experience as a Cyber Security Leader.

WHAT YOU'LL BE DOING :

Information Security & Technology Risk Metrics
  • Drive the management monitoring and reporting methodology for various key information security and security risk governance metrics, security incidents, policy/standards deviations, third party security assessments, etc.
  • Prepare and present relevant technology and security risk indicators and updates to the quarterly security forums, Operational Risk Committees and/or the Board Risk Committees.

IT Risk and Compliance Management
  • Drive organizational self-assessments against related technology and security regulatory advisories, circulars, guidelines and notices.
  • Coordinate annual IT risk and control self-assessment exercises according to MAS regulatory notices/guidelines, internal enterprise IT policies, and standards and maintain the Group electronic Governance Risk and Compliance (eGRC) tool.
  • Manage and follow through on the tracking of deviations and exemptions in the context of AIA's technology and security policies and standards within the Group eGRC tool.

Third Party Security Risk Management
  • Manage the security due diligence evaluations of the organisation's third-party service providers, with a focus on protecting AIA's data assets, and external access to our IT systems and databases.
  • Reinforce the lines of accountability and responsibility between the contract owners and service providers in regard to cybersecurity risk management of third-party engagements.

Security and Policies Awareness
  • Communicate material changes of internal policies/standards to internal staff and key stakeholders.
  • Develop effective methods to deliver cybersecurity training to various groups of audiences, including but not limited to - staff, IT teams, management, third party service providers and our agency forces.

Specialized Areas Governance
  • The role may be called upon to lead or be involved in ensuring governance of specialized areas under information security, such as the governance of operations in the areas of IAM, cloud security, application security, etc.
  • Assist in enterprise-wide risk and compliance coordination for Technology division, where applicable.

Managerial Responsibilities
  • Lead promotion of activities to increase information security within your teams to embed and continuously improve adherence to good practice.
  • Drive a continues Learning and Development program for staff training. (with inhouse and external training programs).

WHAT WE ARE LOOKING FOR:
  • Advanced degree in one of the following or related disciplines (Computer Science, Computer Engineering, Information Security, Information Systems).
  • 10 years of experience in a combination of these roles:
    • Cybersecurity governance, monitoring and reporting of key security metrics and risk indicators, either in Line 1 or Line 2.
    • Leading responses to IT audits and regulatory inspections.
    • Managing IT risk and compliance assessments, including assessments on the cyber hygiene of third-party service providers
    • Development, review and management of deviations/exemptions to technology policies and standards.
    • Developing and driving the organisation-wide information security awareness programme.

  • Substantial working experience from financial industry, big tech firms or established auditing firms will be considered favourably.
  • Experience and exposure in information security standards such as ISO27001 and other relevant industry frameworks will be an advantage.
  • Knowledge of tools such as PowerBI or JIRA would be advantageous, including the ability to implement automation.
  • Preferably a holder of one or more of the following information security and audit qualifications: CISSP, CISA, CRISC, CCSP.
  • Good communication, coordination, and interpersonal skills.
  • Strong stakeholder management capabilities.
  • High level of energy, professional integrity, and leadership demonstration.
  • Ability to adopt a helicopter view context to problem solving.

Build a career with us as we help our customers and the community live Healthier, Longer, Better Lives.

You must provide all requested information, including Personal Data, to be considered for this career opportunity. Failure to provide such information may influence the processing and outcome of your application. You are responsible for ensuring that the information you submit is accurate and up-to-date.

  • Associate Director

    3 weeks ago


    Singapore AIA Singapore Private Limited Full time

    At AIA we've started an exciting movement to create a healthier, more sustainable future for everyone. As pioneering innovators for over 100 years, we're now transforming our organisation to be faster, simpler and more connected. Because we want to be even better equipped to develop digital solutions and experiences that help more people live Healthier,...


  • Singapore KATZ SECURITY PTE. LTD. Part time

    Katz Security Pte Ltd looking to recruit Security Supervisors (SS) and Senior Security Officers (SSO) for the following sites:1) Night Shift Security Supervisor (SS) needed at Government Building located within walking distance of Paya Lebar MRT Station.  Starting salary at $3,300 per month2) Senior Security Officer (SSO) needed at Government Building...


  • Singapore ENCORA TECHNOLOGIES PTE. LTD. Full time

    About the RoleAs a Security Governance Specialist at ENCOREA TECHNOLOGIES PTE. LTD., you will play a critical role in supporting senior Security Governance team members and collaborating with various business, risk, and technology stakeholders to ensure the company's compliance with current and emerging security-related regulatory requirements.Key...


  • Singapore ANZ Full time

    About UsAt ANZ, we're harnessing the power of technology and data to drive financial wellbeing and sustainability for our millions of customers.About the RoleAs a Technology and Information Security Governance Lead for Singapore and International Cloud in our Digital Banking Operations Technology team, you will drive technology operational risk excellence...


  • Singapore INFOGAIN SOLUTIONS PTE. LIMITED Full time

    Job Title: Security Governance SpecialistWe are seeking a highly skilled Security Governance Specialist to join our team at InfoGain Solutions PTE. Limited. As a key member of our security team, you will be responsible for supporting senior security governance team members and working closely with various business, risk, and technology stakeholders.Key...


  • Singapore D L RESOURCES PTE LTD Full time

    Roles & ResponsibilitiesJob ObjectivesThe Security Governance Specialist role will support the Head of Security Governance in enhancing and maintaining the Security Governance within the Group Information Security(GIS) function in the Bank.Key ResponsibilitiesThis position will support senior Security Governance team members and work closely with...


  • Singapore ENCORA TECHNOLOGIES PTE. LTD. Full time

    Roles & ResponsibilitiesResponsibilitiesThis position will support senior Security Governance team members and work closely with various business, risk and technology stakeholders to:• Proactively assess the compliance exposure to current and emerging security-related regulatory requirements and plan & track remediation efforts.• Manage reverse...


  • Singapore Singtel Group Full time

    NCS is the leading technology services firm that operates across the Asia Pacific region in over 20 countries, providing consulting, digital services, technology solutions, and more. We believe in harnessing the power of technology to achieve extraordinary things, creating lasting value and impact for our communities, partners, and people. Our diverse...


  • Singapore MERRILL LYNCH GLOBAL SERVICES PTE. LTD. Full time

    Roles & ResponsibilitiesAt Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. Responsible Growth is how we run our company and how we deliver for our clients, teammates, communities, and shareholders every day.One of the keys to driving Responsible Growth is being a great place to...


  • Singapore NTT SINGAPORE PTE. LTD. Full time

    Roles & ResponsibilitiesSummary:The Security Governance Specialist role will support the Head of Security Governance in enhancing and maintaining the Security Governance within the Group Information Security(GIS) function in the Bank.Key Responsibilities: This position will support senior Security Governance team members and work closely with various...


  • Singapore MERRILL LYNCH GLOBAL SERVICES PTE. LTD. Full time

    About the RoleMerrill Lynch Global Services PTE. LTD. is seeking a highly skilled Information Security Controls Specialist to join our Global Information Security team. As a key member of our team, you will be responsible for providing oversight and assurance of information security processes and controls across Asia Pacific.Key ResponsibilitiesProvide...


  • Singapore MyCareersFuture Full time

    Job Summary:We are seeking a highly skilled IT Security Governance Lead to join our team at MyCareersFuture. As a key member of our organization, you will be responsible for formulating and implementing our ICT security strategy and work plan, ensuring alignment with our strategic plans.Key Responsibilities:Develop and implement Company-wide information...


  • Singapore EVO OUTSOURCING SOLUTIONS PTE. LTD. Full time

    Job Title: Security Governance SpecialistAt EVO OUTSOURCING SOLUTIONS PTE. LTD., we are seeking a highly skilled Security Governance Specialist to join our team. As a key member of our organization, you will play a critical role in maintaining and enhancing Security Governance within our Group Information Security (GIS) function.Key Responsibilities:Assess...


  • Singapore MyCareersFuture Full time

    **Job Summary**MyCareersFuture is seeking a highly skilled Security Governance Specialist, Banking to join our team. As a key member of our Security Governance team, you will play a critical role in supporting senior team members and collaborating with various stakeholders to ensure compliance with security-related regulatory requirements.**Key...


  • Singapore RECRUIT EXPRESS PTE LTD Full time

    Job Title: Governance, Risk and Compliance SpecialistRecruit Express Pte Ltd is seeking a highly skilled Governance, Risk and Compliance Specialist to join our team.Job Responsibilities:Provide expert advice to end-users on Governance, Risk, and Compliance within Security Management.Collaborate with various teams to meet security requirements, ensure...


  • Singapore METROPOLIS SECURITY SYSTEMS PTE. LTD. Full time

    Job SummaryMetropolis Security Systems Pte. Ltd. is seeking a highly skilled and experienced Senior Security Officer to join our team. As a Senior Security Officer, you will be responsible for regulating traffic, operating security and safety systems, and monitoring the Security Command Centre and Fire Command Centre.Key ResponsibilitiesRegulating Traffic:...


  • Singapore ARKCLUB INTERNATIONAL MANAGEMENT PTE. LTD. Full time

    Job Title: Chief Information Security OfficerARKCLUB INTERNATIONAL MANAGEMENT PTE. LTD. is seeking a highly skilled Chief Information Security Officer to lead our cybersecurity efforts.Key Responsibilities:Develop and implement secure processes and systems to prevent, detect, mitigate, and recover from cyberattacks.Educate and manage technology risk in...


  • Singapore MyCareersFuture Full time

    Roles & Responsibilities Job Description You will be a member of the Group Information Security Team responsible for ensuring corporate applications, systems, networks, and digital assets are adequately protected and mitigated against cyber threats and risks. You will help drive cybersecurity and risk management efforts and user awareness and...


  • Singapore PERSOLKELLY SINGAPORE PTE. LTD. Full time

    Job DescriptionJob Title: Security Governance SpecialistJob Summary:We are seeking a highly skilled Security Governance Specialist to join our team at PERSOLKELLY SINGAPORE PTE. LTD. The successful candidate will be responsible for ensuring the effective implementation of security governance policies and procedures across the organization.Key...


  • Singapore MyCareersFuture Full time

    Roles & Responsibilities Position: Chief Information Security Officer Job Description Developing and implementing secure processes and systems used to prevent, detect, mitigate, and recover from cyberattacks Educating and managing technology risk in collaboration with business leaders Building and driving a cybersecurity strategy and framework,...