Head of Information and Cyber Security

5 days ago


Singapore TECH AALTO PTE. LTD. Full time

**Role: Head of Information and Cyber Security**
**Position Type: Contract
**Responsibilities**:
We are looking for an Information and Cyber Security Lead. You will be part of the founding key team member, reporting to the Chief Information Officer (CIO) and working closely with team leads in the transformation of the business. If you are passionate about technology and digital transformation for business and want to be in a team where your views matter, learning and collaboration is part of the culture, please reach out and we would love to talk to you
- Define and implement the Enterprise InfoSec (IS) landscape and roadmap.
- Architect and develop security solutions on on-premise and cloud platforms (AWS, GCP, or Azure) using cloud-native security services.
- Design and implement secure cloud architecture for various cloud platforms.
- Develop, maintain, and enhance IT Security checklists and guidelines.
- Manage third-party IS due diligence on service suppliers, including onsite assessments.
- Conduct Technology Security Risk Assessments on systems throughout their lifecycle to identify and mitigate security risks.
- Ensure compliance with security frameworks and processes such as CIS, NIST, PCI/DSS, SOC 2.
- Implement process improvements for effective IT Security risk management.
- Identify security risks in the Tech Obsolescence Risk program.
- Perform periodic risk analysis, vulnerability scanning, and testing.
- Drive enterprise initiatives for comprehensive security posture analysis across different layers and sources within the network environment.
- Respond to security incidents and manage incident response.
- Communicate with regulators such as MAS and ensure solutions meet external and internal requirements and guidelines.
- Conduct security awareness training and programs for employees.
- Stay updated on security trends and new threats to safeguard the organization.

**Qualifications & Experience Requirements**:
Bachelor's or Master's degree in Information Security, Computer Science, or a related field.

Industry certifications such as CISSP, CISM, CCSP, or relevant cloud certifications (AWS Certified Security, Azure Security Engineer, etc.) are highly desirable.

**Experience**:

- Minimum 10+ years of experience in IT Security, with a focus on Enterprise InfoSec architecture and risk management.
- 5+ years of hands-on experience architecting and developing security solutions for both on-premise and cloud platforms (AWS, GCP, or Azure) using cloud-native security services.
- Proven experience in designing and implementing secure cloud architectures across multiple platforms.
- Strong experience in conducting Technology Security Risk Assessments throughout the lifecycle of systems and implementing risk mitigation strategies.
- Experience in third-party IS due diligence assessments, including managing supplier audits and onsite evaluations.
- Familiarity with security frameworks and regulatory compliance standards such as CIS, NIST, PCI/DSS, SOC 2, and experience working with regulators like MAS.
- Experience in incident response and security operations, including vulnerability scanning, periodic risk analysis, and handling security incidents.
- Track record of leading enterprise security initiatives to enhance the overall security posture, including process improvements in IT Security risk management.
- Experience conducting security awareness training and staying updated with emerging security threats.

**Skills**:

- Strong knowledge of cloud security architecture, cloud-native security tools, and multi-cloud environments.
- Ability to communicate complex security concepts effectively to both technical and non-technical stakeholders.
- Proficiency in security tools and technologies used for vulnerability management, risk analysis, and incident response.
- Strong leadership and advisory skills with the ability to serve as a trusted security partner within the organization.


  • Snr Consultant

    7 days ago


    Singapore The Cyber Security Agency of Singapore Full time

    What the role is: Critical Information Infrastructure (CII) team works to strengthen the cybersecurity in our critical sectors such as energy, water and banking. You will work with a team of Sector Officers to partner regulators and operators to strengthen the cyber resiliency of the Nation's critical information infrastructure against cyber threats and to...

  • IT Project Admin

    7 days ago


    Singapore The Cyber Security Agency of Singapore Full time

    Overview What the role is: As a Senior/IT Project Admin in the CIO Office, you will support and run the operations for IT-related projects. You will also be required to plan, procure and manage inter/intra divisional IT resources, forecast and consolidate budget requirements and handle IT-related administrative matters if the need arise. What you will be...

  • Assistant Manager

    5 days ago


    Singapore The Cyber Security Agency of Singapore Full time

    Overview What the role is: Established on 1 April 2015, the Cyber Security Agency of Singapore (CSA) is the national body overseeing cyber security strategy, operation, education and outreach, technology and industry development. CSA provides dedicated and centralised oversight of Singapore's national cyber security functions, and engages partners to ensure...


  • Singapore The Cyber Security Agency of Singapore Full time

    What the role is: You will be part of a dynamic team to shape and develop a vibrant and growing cybersecurity ecosystem in Singapore. Your mission will be to strengthen Singapore’s cybersecurity capabilities in innovation through the formulating of strategies, plans, and implementation of new and existing initiatives to grow the cybersecurity industry for...


  • Singapore The Cyber Security Agency of Singapore Full time

    What the role is You will be part of a dynamic team to shape and develop the cybersecurity ecosystem in Singapore. Your mission will be to support the Director of the CSA Academy in uplifting Singapore's cybersecurity capabilities through programmes on skills and talent development. You will work with internal and external stakeholders such as the employers,...

  • Asst Director

    6 days ago


    Singapore Cyber Security Agency of Singapore Full time

    **What the role is** - This position is focused on cyber security readiness, protection, and incident response capabilities by developing, designing and conducting cyber exercises and workshops leading to the development of cyber incident planning artefacts for government and CII sectors/industry. **What you will be working on** - This requisition may be...


  • Singapore Cyber Security Agency of Singapore (CSA) Full time

    Deputy Director/Snr Asst Director, SingCERT (SG Cyber Emergency Response), NCIRC Join to apply for the Deputy Director/Snr Asst Director, SingCERT (SG Cyber Emergency Response), NCIRC role at Cyber Security Agency of Singapore (CSA)Deputy Director/Snr Asst Director, SingCERT (SG Cyber Emergency Response), NCIRC 1 day ago Be among the first 25 applicants Join...


  • Singapore The Cyber Security Agency of Singapore Full time

    Description Digital Business Analyst (Cybersecurity), Chief Information Officer Office What The Role IsAs a Digital Business Analyst, you support the Chief Information Officer (CIO) and collaborate with business owners (non‑tech), cybersecurity specialists, cloud infra‑security, DevSecOps and GRC (Governance Risk Compliance) to deliver secure and...


  • Singapore The Cyber Security Agency of Singapore Full time

    Digital Business Analyst (Cybersecurity), Chief Information Officer Office What The Role Is As a Digital Business Analyst, you support the Chief Information Officer (CIO) and collaborate with business owners (non‐tech), cybersecurity specialists, cloud infra‐security, DevSecOps and GRC (Governance Risk Compliance) to deliver secure and leading‐edge...


  • Singapore The Cyber Security Agency of Singapore Full time

    Description Digital Business Analyst (Cybersecurity), Chief Information Officer Office What The Role IsAs a Digital Business Analyst, you support the Chief Information Officer (CIO) and collaborate with business owners (non‐tech), cybersecurity specialists, cloud infra‐security, DevSecOps and GRC (Governance Risk Compliance) to deliver secure and...