Apac Information Security Consultant

2 days ago


Singapore Zurich Insurance Full time

**Job Title: APAC Information Security Consultant**

**Location: Singapore, Malaysia**

**The Opportunity**:
We are looking for an APAC Information Security Consultant, who is primarily responsible for supporting information security governance initiatives and activities across APAC business units.

**Key Responsibility**:
**Information Security governance**
- Maintain APAC’s regional Information Security, Risk and Compliance framework, and support Group in revising old or establishing new policies and standards
- Provide governance over and support APAC BISOs in the coordination of regional and local information security gap remediation
- Perform analysis to identify common themes and drive regional remediation activities
- Advise APAC BISOs and stakeholders in information security policy compliance requirements
- Provide advice, governance and support in information security policy exception and risk acceptance processes
- Work closely with the Group’s Information Security Governance (ISG) team and APAC BISOs to ensure global requirements are communicated to APAC stakeholders and APAC requirements are considered in global information security compliance projects
- Support Group’s ISG initiatives in the APAC region
- Provide support in APAC’s Information Security control assurance processes
- Work closely with the APAC Information Security Analytics & Reporting team in ensuring visibility via accurate security compliance metrics
- Identify and support opportunities for process simplification and automation initiatives.

**Information Security, Risk and Compliance Assessments**
- Support APAC BISOs in performing the following assessments using the Global standard approach:

- Cloud security assessments
- Third party vendor assessments
- Business / IT Application assessments (incl. pre & post implementation reviews, major changes)
- Regulatory assessments (e.g. local regulations, ISO27001, PCI DSS, SOC2, etc)
- Remediation action review, analysis and management and themed security reviews.
- Exception management and support continuous improvement of Global and Regional ISG processes

**Qualification, Skills & Experience**:

- University graduate of computer science, information technology/security or any other related disciplines.
- Minimum 6 years professional experience in information security or IT risk management, preferably in MNC environment or insurance industry.
- Certification of CISA, CRISC, CISSP or CISM is a must
- Experience or certification of PCI IA, ISO27001 is a plus.
- Big4 information security consulting and/or IT audit experience is an advantage.
- Excellent communication skills in English and ability to communicate security-related concepts to all levels of stakeholders
- Strong integrity and highly ethical
- Effective in influencing and persuasion
- Background in security/risk related topics and technologies
- Working knowledge of regulatory compliance drivers
- Good understanding of security concepts and architectures
- Good understanding of IT security and compliance controls
- General knowledge of regulatory requirements is a plus
- General knowledge of common security tools

**You are the heart & soul of Zurich**

At Zurich, we like to think outside the box and challenge the status quo. We take an optimistic approach by focusing on the positives and constantly asking What can go right?

People are Zurich’s most important asset. Their varied skills, perspectives and experiences drive innovation. And they reflect the breadth and diversity of our customers, suppliers, communities and investors around the world. We are committed to attracting and retaining talented individuals from a variety of backgrounds and experiences.

Let’s continue to grow together
- Location(s): Singapore or Malaysia
- Remote working: Hybrid Working Model
- Closing date:



  • Singapore softScheck APAC Full time

    Get AI-powered advice on this job and more exclusive features. softScheck is a fast-growing IT security consultancy firm in APAC. We provide cybersecurity consultancy services across multiple government agencies, Banks, MNCs, and large corporations. You will belong to and will be working with a group of fun and high-performing team members. As a member of...

  • Security Engineer

    4 days ago


    Singapore EvaBssi APAC Full time

    **Context**: EvaBssi APAC is an IT Consulting and Technical Expertise company, part of Sopra Steria Group, with expertise in IT Infrastructure, Cloud, Cybersecurity and Smart Data (Business Process Digital Transformation). Its growth has accelerated these last few years, due to heighten customers' needs in Cloud/Digital Transformation, seamless connectivity...


  • Singapore abrdn Full time

    Job Description Information Security & Resilience Analyst APAC Security, Resilience & Protection (SRP) APAC Location: Singapore About the Role- To support the regional SRP function in all matters relating to Information Security, Data Privacy, Operational Resilience and Third Party Risk Management working closely with regional and in country teams, as well...


  • Singapore PayPal Full time

    Overview Information Security Consultant at PayPal. You’ll partner with product teams to understand proposed new products and changes to PayPal products to ensure security is part of the design, development, and release to deliver secure solutions to our customers. Responsibilities Leverage specialized security expertise to identify and resolve complex...


  • Singapore NCC Group APAC Full time

    Overview Thanks for checking out our job opening; we are excited that YOU are interested in learning more about NCC Group. We are on a mission to make society a safer and more secure place. Our people are the ones who make that possible; a global community of talented individuals working together towards a safer future. We aim to create an environment where...


  • Singapore KRIS INFOTECH PTE. LTD. Full time

    The Manager of the Information Security Department is responsible for the organization's efforts to protect its information assets and ensure the security of its information systems. - This position requires a proactive approach to developing and implementing security policies, conducting security assessments, and responding to incidents. - The role involves...


  • Singapore PLAN B SECURITY PTE. LTD. Full time

    Job Description: As a next-gen Cyber Security Consultant. The candidates will be involved in project planning, rolling out of security solution to secure customers environment. Having an open heart and open mind, to learn the sophisticated Cyber Security technology. Join us and onboard to the next-gen journey. Product Coverage: Next-Gen Anti-Virus Next-Gen...


  • Singapore NCS Full time

    **Consultant, IT Security**: **Date**:17 Oct 2024 **Location**: Singapore, Singapore **Company**:Singtel Group NCS is a leading technology services firm that operates across the Asia Pacific region in over 20 cities, providing consulting, digital services, technology solutions, and more. We believe in harnessing the power of technology to achieve...


  • Singapore Ensign InfoSecurity Full time

    The incumbent is responsible for delivering information security projects that are related to Ensign’s Infrastructure Security (IS) competency tower, including the execution of all project implementation activities. This competency tower’s cybersecurity includes IPS/IDS, Firewall, WAF, NDR, Data Diode, APT and OT/IOT Cybersecurity Responsibilities...


  • Singapore PLAN B SECURITY PTE. LTD. Full time $80,000 - $120,000 per year

    Job Description: As a next-gen Cyber Security Consultant. The candidates will be involve in project planning, rolling out of security solution to secure customers environment. Having an open heart and open mind, to learn the sophisticated Cyber Security technology. Join us and onboard to the next-gen journey. Product Coverage * Next-Gen...