CISO / IT Security Lead (prefer insurance sector)

1 week ago


Singapore MINDTECK SINGAPORE PTE LTD Full time

CISO / IT Security Lead The IT Security Lead will be responsible for leading the development, execution, and management of the enterprise-wide information security strategy, architecture, and program at Insurance Sector. Reporting directly to the CITO, the IT Security lead will work across departments to protect the organization’s information assets, mitigate cyber risks, and ensure alignment between business and security objectives. This executive role combines strategic planning, policy formulation, risk management, and hands-on oversight of cybersecurity operations and IT infrastructure resilience. Key Responsibilities Strategic Leadership & Governance Define and implement the enterprise-wide Information Security Strategy in alignment with business goals and regulatory requirements. Serve as the primary advisor to the CITO and executive leadership on all cybersecurity and risk matters. Lead the development, approval, implementation, and adherence of information security policies, procedures, and standards. Ensure business units understand and adhere to the organization's security objectives and practices. Risk Management & Compliance Lead comprehensive Information Security Risk Assessments across internal and external domains, including third-party/vendor risks. Design and oversee a formal Information Security Risk Management Plan, regularly reporting risk metrics and mitigation effectiveness. Ensure continuous compliance with relevant regulatory, industry, and internal standards (e.g., MAS TRM Guidelines, ISO 27001). Conduct periodic audits and reviews of cybersecurity controls and frameworks. Operational Excellence & Metrics Manage the IT Infrastructure and Information Security Budget efficiently, ensuring Cost Variance (CV) is minimized. Establish performance metrics such as: Cost Efficiency of IT Security investments System Uptime vs. Downtime (Availability) Incident Volume, Resolution Time, Aging Reports Vendor SLA Performance and operational KPIs Develop business cases and ROI justifications for information security initiatives and technologies. Cybersecurity Initiatives & Incident Response Oversee the implementation and continuous improvement of Cybersecurity Programs, ensuring proactive threat detection, response, and mitigation. Monitor and report on security posture through metrics such as: Number of breaches avoided Time to detect and respond to incidents Compliance level with cybersecurity standards Lead security incident response efforts, coordinating cross-functional support and communication. Technology & Innovation Evaluate emerging cybersecurity technologies, practices, and innovations aligned with company’s strategic IT direction. Ensure security assurance for all strategic IT initiatives by identifying suitable controls and countermeasures. Drive continuous improvement and maximize business value from IT Security investments through innovation and scalability. Qualifications Education & Certification: Bachelor’s or Master’s degree in Computer Science, Information Security, Information Technology, or a related field. Professional certifications such as CISSP, CISM, CISA, CRISC, CCSP, or equivalent are highly preferred. Experience: Minimum 8-10 years of experience in Information Security leadership, with at least 5 years in a IT Security Management or CISO or equivalent role. Proven track record of managing cybersecurity programs, risk frameworks, and compliance in financial services or regulated industries. Skills & Competencies: Strong understanding of regulatory frameworks, enterprise risk management, and cybersecurity standards. Executive presence and ability to communicate complex technical issues to non-technical stakeholders. Strong leadership, influence, and team-building skills across multidisciplinary teams. Demonstrated experience in budget planning, project management, and strategic execution. Key Deliverables (Annual & Ongoing): Annual Information Security Strategy and Risk Report Quarterly Risk Assessments and Executive Dashboards Cybersecurity Initiative Effectiveness Metrics Cost Variance and Budget Utilization Reports IT Security KPIs and SLA Performance Reviews #J-18808-Ljbffr


  • Regional CISO, APAC

    2 weeks ago


    Singapore Liberty Insurance Pte Ltd Full time

    Location: Singapore Type: Full Time Min. Experience: Experienced The Liberty International Insurance (LII) APAC Regional Chief Information Security Officer (CISO) is responsible for providing leadership and strategic alignment to global enterprise security policies and initiatives, whilst enabling the regional and country business goals and initiatives...


  • Singapore Google Full time

    Senior Security Advisor, Office of the CISO Join to apply for the Senior Security Advisor, Office of the CISO role at Google. The Office of the Chief Information Security Officer (CISO) is a security advisory team with a mission to support the security and digital transformation of enterprises, governments, critical infrastructure, and business....


  • Singapore Google Inc. Full time

    Senior Security Advisor, Office of the CISO Apply Bachelor's degree or equivalent practical experience. 15 years of experience in cybersecurity or a customer-facing technical security role. 10 years of cumulative industry experience in Financial Services, Technology/Digital Natives, Retail, FMCG/Manufacturing, Telecommunication, Public Sector or Healthcare...

  • Regional CISO, APAC

    1 week ago


    Singapore Liberty Mutual Group Full time

    Overview The Liberty International Insurance (LII) APAC Regional Chief Information Security Officer (CISO) is responsible for providing leadership and strategic alignment to global enterprise security policies and initiatives, whilst enabling the regional and country business goals and initiatives to achieve competitive advantage. The CISO collaborates with...


  • Singapore Pepperstone Full time

    The Pepperstone story started in 2010. We know what it's like to trade the world's markets. Our team describes us as a place for the curious and the driven, and we like to do things a little differently; as a transformative global fintech we're digital, nimble, connected, and united in our vision to create a better way to trade. We thrive on progress - for...


  • Singapore Pepperstone Full time

    The Pepperstone story started in 2010. We know what it's like to trade the world's markets. Our team describes us as a place for the curious and the driven, and we like to do things a little differently; as a transformative global fintech we're digital, nimble, connected, and united in our vision to create a better way to trade. We thrive on progress - for...


  • Singapore Google Full time

    Google will be prioritizing applicants who have a current right to work in Singapore, and do not require Google's sponsorship of a visa. Minimum qualifications: Bachelor's degree or equivalent practical experience. 15 years of experience in a technical project management or a customer-facing role. 10 years of experience in Financial Services, Manufacturing,...


  • Singapore Google Full time

    Google will be prioritizing applicants who have a current right to work in Singapore, and do not require Google's sponsorship of a visa. **Minimum qualifications**: - Bachelor's degree or equivalent practical experience. - 15 years of experience in a technical project management or a customer-facing role. - 10 years of experience in Financial Services,...


  • Singapore Randstad Singapore Full time

    Cyber Security Director | CISO | SOC | GRC Join to apply for the Cyber Security Director | CISO | SOC | GRC role at Randstad Singapore Our client is a multi-billion company who is a market leader (Close to 20 years of experience) within their area of specialization. As part of their plan to invest in technology, they are now hiring Head of Security &...


  • Singapore The Consulting Partnership Full time

    The Security Operations Lead is responsible for leading the design and implementation of EVIDENT DevSecOps strategy, ensuring the company’s security posture remains strong against the ever-evolving cyber threat landscape, enabling the protection of critical information assets within the Global Evident Healthcare and Manufacturing domain. **Decision-making...