Information Security Manager
2 weeks ago
The successful candidate will be responsible for overseeing the vendor security risk management and cyber risk management for Asia Pacific, excluding China. This includes conducting risk assessments and periodic re-assessments, performing application security testing, and providing remediation options. The candidate will also assist in managing relationships with service providers, managing outcomes and results, and collaborating with stakeholders across IT and business departments to develop strategies for securing company information and assets.
Candidate Profile
The ideal candidate will have a Bachelor's degree in information systems or a related field, or equivalent experience/certification. They will have 5+ years of security governance, risk management, and compliance-related experience, with 2+ years of direct work experience in third-party security risk management. Fluency in English is required, and one or more current information security certifications are preferred.
Key Responsibilities
The successful candidate will be responsible for:
- Overseeing, evaluating, and supporting the documentation and validation processes necessary to ensure that associates, information technology systems, and business processes meet the organization's information assurance, security, and privacy requirements.
- Developing a strategy for the vendor information security risk compliance program.
- Performing security controls assessments of third-party providers, assessing security architecture, adherence to requirements, conducting application scanning, and results validation.
- Documenting controls gap analysis and risk assessment of third-party providers.
- Reviewing controls exception requests and making risk-based approval decisions.
- Leading, participating, or performing various infrastructure compliance initiatives and projects.
- Performing application security testing using Nessus, IBM App Scan, HP Web Inspect, Fortified on Demand, Qualys, Burp, or Retina.
- Conducting and validating findings discovered during scans.
- Monitoring compliance to applicable security policies and standards and reporting related risk issues.
- Managing and administering processes and tools that enable the organization to identify, document, and track third-party risks and compliance exceptions.
- Conducting assessments of threats and vulnerabilities, determining deviations from acceptable configurations or enterprise or local policy, assessing the level of risk, and developing and/or recommending and operationalizing appropriate mitigation countermeasures.
- Providing sound advice and recommendations to leadership and staff on a variety of relevant topics within the pertinent subject domain.
Requirements
The ideal candidate will have:
- A Bachelor's degree in information systems or a related field, or equivalent experience/certification.
- 5+ years of security governance, risk management, and compliance-related experience, with 2+ years of direct work experience in third-party security risk management.
- Fluency in English.
- One or more current information security certifications.
Preferred Qualifications
The ideal candidate will also have:
- A security certification such as GWAPT, GPEN, AWS Associate Architect, AWS Professional Architect, PCI experience.
- Technical knowledge in one or more of the following areas: application security, operating system security, network security.
- Technical leadership experience in an outsourced environment.
- Excellent communication skills and problem-solving ability.
- Experience conducting and maintaining vendor risk assessments.
- Experience with reviewing and assessing security controls of cloud service providers.
- Proficient with assessing a multi-tiered system architecture.
- Knowledge of OWASP Top 10 and SANS 25.
- Working knowledge of infrastructure and application scanning tools.
- Manual web application testing experience.
- Familiarity with ISO27001 and PCI DSS Standards.
Marriott International is an Equal Opportunity Employer
We believe in hiring a diverse workforce and sustaining an inclusive, people-first culture. We are committed to non-discrimination on any protected basis, such as disability and veteran status, or any other basis covered under applicable law.
-
Information Security Manager
1 month ago
Singapur, Singapore Marriott International Full timeJob SummaryThe Continent Information Security Partnerships position drives continent security program, policy, and project execution, providing leadership and direction to the above property and on-property teams. The position strives for outstanding security compliance status and ensures that Security implementations within the continent follow company...
-
Information Security Manager
1 month ago
Singapur, Singapore OCBC Bank Full timeJob Title: Information Security ManagerOCBC Bank is seeking a highly skilled Information Security Manager to join our team. As a key member of our Information Security and Digital Risk Management (ISDRM) team, you will be responsible for supporting the 2nd line governance and oversight of information security and digital risks within the bank.Key...
-
Information Security Manager
1 month ago
Singapur, Singapore OCBC Bank Full timeJob Title: Information Security ManagerOCBC Bank is seeking a highly skilled Information Security Manager to join our team. As a key member of our Information Security and Digital Risk Management department, you will be responsible for supporting the 2nd line governance and oversight of information security and digital risks within the bank.Key...
-
Information Security Manager
4 weeks ago
Singapur, Singapore OCBC Bank Full timeOverview:As the Information Security Manager at OCBC Bank, you will play a pivotal role in overseeing the governance and management of information security and digital risks. Your primary responsibility will be to fortify defenses against cyber threats, ensuring robust information security and effective digital risk management in collaboration with the Chief...
-
Information Security Manager
4 weeks ago
Singapur, Singapore OCBC Bank Full timeOverview:As the Information Security Manager at OCBC Bank, you will play a pivotal role in overseeing the governance and management of information security and digital risk. Your primary responsibility will be to safeguard the organization against cyber threats and ensure robust digital risk management practices in collaboration with the Chief Information...
-
Information Security Manager
4 weeks ago
Singapur, Singapore OCBC Bank Full timeOverview:As the Information Security Manager at OCBC Bank, you will play a pivotal role in overseeing the governance and management of information security and digital risks. Your primary responsibility will be to safeguard the organization against cyber threats and ensure compliance with digital risk management protocols, working closely with the Chief...
-
Information Security Manager
2 months ago
Singapur, Singapore OCBC Bank Full timeAbout the RoleWe are seeking a highly skilled and experienced Information Security Manager to join our team at OCBC Bank. As a key member of our Information Security and Digital Risk Management team, you will play a critical role in supporting the 2nd line governance and oversight of information security and digital risks within the bank.Key...
-
Information Security Manager
2 months ago
Singapur, Singapore Marex Spectron Full timeAbout the RoleThe Information Security Officer will work closely with the Head of Information Security to lead and report on security programs across Marex entities in the APAC region. The primary responsibility is to ensure consistent application and adherence to the Group's information security policies and local regulations, as well as assistance in...
-
Information Security Manager
4 weeks ago
Singapur, Singapore Marriott International Full timeJob SummaryThe successful candidate will be responsible for overseeing the vendor security risk management and cyber risk management for Asia Pacific, excluding China. This includes conducting risk assessments and periodic re-assessments, performing application security testing, and providing remediation options. The individual will also assist in managing...
-
Information Security Manager
1 month ago
Singapur, Singapore Marriott International Full timeJob SummaryThe successful candidate will be responsible for overseeing the vendor security risk management and cyber risk management for Asia Pacific, excluding China. This includes conducting risk assessments and periodic re-assessments, performing application security testing, and providing remediation options. The candidate will also assist in managing...
-
Senior Information Security Manager
4 weeks ago
Singapur, Singapore IHiS Full timeJob Title: Senior ManagerJob Summary:We are seeking a highly experienced Senior Manager to lead our information security governance and risk management efforts. The successful candidate will be responsible for defining and maintaining corporate-wide information security governance and controls to ensure the protection of our information assets.Key...
-
Senior Manager
5 months ago
Singapur, Singapore IHiS Full timeJob Responsibilities Roles and requirement Defining and maintaining corporate-wide information security governance and controls to ensure that information assets are adequately protected · Involved in Identifying, evaluating and reporting of information security risks in a manner that meets compliance and regulatory requirements · Work closely with...
-
Senior Information Security Manager
1 week ago
Singapur, Singapore IHiS Full timeJob SummaryWe are seeking a highly skilled Senior Manager to lead our corporate information security governance and compliance efforts.Key ResponsibilitiesDevelop and maintain information security governance frameworks and controls to ensure the protection of our information assets.Identify, evaluate, and report information security risks in compliance with...
-
Regional Information Security Manager
2 months ago
Singapur, Singapore KPMG - Singapore Full timeJob Title: Regional Information Security Manager About the Role: We are seeking a highly skilled Regional Information Security Manager to join our team at KPMG - Singapore. As a key member of our Global Information Security Group, you will play a critical role in advising member firms on the implementation of KPMG information risk and security...
-
Regional Information Security Manager
1 month ago
Singapur, Singapore KPMG - Singapore Full timeJob Title: Regional Information Security Manager About the Role: As a Regional Information Security Manager at KPMG - Singapore, you will play a critical role in advising member firms on the implementation of KPMG information risk and security standards. You will maintain an up-to-date knowledge base and work with the Risk and Information Security Office...
-
Lead Information Security Manager
4 weeks ago
Singapur, Singapore IHiS Full timePosition OverviewWe are in search of an experienced professional to take on the role of Senior Manager of Information Security at IHiS. This pivotal position involves establishing and overseeing comprehensive information security governance and controls to safeguard our critical information resources. Key responsibilities for this role include:Assessing and...
-
Senior Information Security Manager
2 weeks ago
Singapur, Singapore NCS Full timeJob Title: Senior Information Security ManagerWe're seeking a seasoned Senior Information Security Manager to join our team at NCS. As a key member of our cybersecurity team, you will be responsible for driving the implementation of our cybersecurity policies, standards, and processes within the practice.Your key responsibilities will include:Developing and...
-
Information Security Governance Manager
4 weeks ago
Singapur, Singapore IHiS Full timePosition OverviewWe are in search of an experienced professional to become a part of our organization as a Senior Manager in Information Security. This pivotal role involves establishing and upholding comprehensive information security governance and controls to safeguard our critical information resources. Your key responsibilities will encompass:Assessing...
-
Regional Information Security Manager
2 weeks ago
Singapur, Singapore KPMG - Singapore Full timeJob DescriptionKPMG's Global Information Security Group (GISG) is a critical component of our Global Technology & Knowledge group. GISG provides the information protection and technology infrastructure that secures KPMG's technology environment and connects its network of member firms. GISG works closely with other GT&K domains to ensure that appropriate...
-
Regional Information Security Manager
5 months ago
Singapur, Singapore KPMG - Singapore Full timeJob DescriptionGISG (Global Information Security Group) is one of five domains within KPMG's Global Technology & Knowledge group. GISG provides the information protection and technology infrastructure that secures KPMG's technology environment and connects its network of member firms. GISG works with the other GT&K domains to ensure that appropriate security...