Information Security
2 days ago
At Bank of Singapore, we are constantly on the lookout for exceptional individuals to join our team. We promote a culture of openness, teamwork and fairness. Most importantly, we invest in our people through our programmes that develop them on both professional and personal levels. Besides attractive remuneration packages, we offer non-financial benefits and opportunities to develop your potential within OCBC Group’s global network of subsidiaries and offices. If you have passion, drive and the will to succeed, rise to the challenge today
Responsible for second line of defence related to governance and oversight of Information Security Risk and Digital Risks (Technology, Information and Cyber) within the organisation.
**Responsibilities**
- Lead and support the risk governance and oversight of Information Security Risk and Digital Risks (Technology, Information and Cyber) in second line.
- Lead second line Information Security initiatives and establish/roll-out Local Information Security Office (LISO) program to each of global locations within the organisation.
- Lead and represent second line in regulatory assessments in Information Security risk and Digital risks topics.
- Lead and / or support internal / cross-functional initiatives such as technology, information and cyber thematic and process reviews, as well as technology projects.
- Lead and / or participate in risk committees and working groups that have been established to enhance governance and oversight over Information Security risk and Digital risks matters.
- Develop, review and maintain Information Security and Digital risk framework, policies and departmental operating procedures to ensure that they are relevant, up to date and aligned to Group and regulatory standards.
- Monitor Information Security and Digital risk exposures via dashboards and Key Risk Indicators (KRIs) and provide independent reporting on the effectiveness of risk posture or activities to management.
- Provide risk advisory services to business units on the adoption of new and emerging technologies (e.g. cloud computing, Fintech etc), as well as third party arrangements.
- As a second line of defence, provide an effective challenge on the adequacy, completeness and timeliness of risk assessments and / or action plans that have been put in place to address prevailing and emerging Information Security and Digital risks. This includes the review of system risk acceptances.
- Plan and deliver a comprehensive Information Security and Digital risk awareness training and testing program for all staff. This includes the conduct of periodic social engineering tests to reinforce awareness.
**Qualifications**
- Good understanding of banking processes, technology, operations, and regulations (in particular MAS Technology Risk Management Guidelines), as well as ISO 27001.
- Prior experience in managing projects / change initiatives would be an added advantage
Academic and professional qualifications
- University degree preferred.
- Professional certification in information security. E.g. CISA, CISM, CRISC, CISSP etc.
- Proficient in Microsoft Office Applications (i.e. Excel, PowerPoint, Word).
Language skills
- Fluent in English.
Personal attributes
- Good communication, presentation and interpersonal skills to facilitate interactions with key stakeholders within and outside of the organisation.
- Ability to collaborate well within the team, department and across different departments/locations.
- Able to exercise sound judgment and establish plans to manage the execution of deliverables within the stipulated timelines.
- Self-driven with attitude and aptitude to learn and accomplish tasks that have been assigned.
- Analytical mindset and good report writing skills.
- Able to prioritise and multi-task in a competitive environment
- A team player.
-
Information Technology Security Specialist
2 days ago
Singapore SMART INFORMATION MANAGEMENT SYSTEMS PRIVATE LIMITED Full time**Key Responsibilities**: **Cybersecurity Risk Assessment & Mitigation**: - **Cyber Risk Assessment**:Conduct comprehensive cyber risk assessments in support of technology initiatives, identifying IT-related risks and recommending appropriate security controls to mitigate those risks. - **Risk Monitoring & Management**:Continuously track and manage risk...
-
Information systems security developer
1 week ago
Singapore FEDERAL SECURITY SERVICES Full time $60,000 - $100,000 per yearDesign artefacts, spanning design, development, and implementation, into enterprise systems that describe security principles and how they relate to the overall enterprise system architecture. • Perform routine activities related to the periodic review and audit activities of infrastructure security systems and maintains documentation of security standards...
-
Information Security
1 week ago
Singapore Scoot Tigerair Pte Ltd Full time $40,000 - $60,000 per yearInternshipSummaryProvide better appreciation and experiential learning in Cybersecurity defence in terms of concepts, architecture, technologies, tools, and operations.Job DescriptionResponsibilities:Application SecurityResearch web and mobile application security best practicesResearch into the latest IAM technologies and propose enhancements to existing...
-
Information Security
3 days ago
Singapore D L Resources Pte Ltd Full time $13,200 - $144,000 per yearJob ObjectivesThe Security Governance Specialist role will support the Head of Security Governance in enhancing and maintaining the Security Governance within the Group Information Security(GIS) function in the Bank.Key ResponsibilitiesThis position will support senior Security Governance team members and work closely with various business, risk and...
-
Information Security Manager
2 days ago
Singapore SINGAPORE AEROSPACE MANUFACTURING PTE LTD Full timeSAM is looking to fill the position of **Information Security Manager **. This is a regional role and is overall in-charge of all the entities under SAM. He/She will report to the CEO. **Responsibilites** - To develop and implement a long-term Information Security & Cyber Security strategies and roadmap to protect corporate information and IT assets. - Set...
-
Director, Information Security
2 days ago
Singapore Ensign InfoSecurity Full timeEnsign is hiring ! As Director, Information Security, you will play a crucial role in implementing Ensign's cybersecurity vision. Reporting to the Information Security Office, you will collaborate with senior management and business units on cybersecurity initiatives. You will play a crucial role in supporting the CISO in establishing and maintaining an...
-
Engineer (Information Security)
1 week ago
Singapore Good Job Creations Pte Ltd Full timeProvides security analysis of IT activities to ensure that appropriate security measures are in place and are enforced. - Assists with the development and maintenance of corporate security policies and procedures, the remediation of identified risks, and the implementation of security measures to ensure information systems’ reliability and to prevent and...
-
Information Security Officer
3 days ago
Singapore percept-solutions Full timeThe Information Security Officer (ISO) is responsible for managing the Information Security and Data Privacy Program, serving as the Single Point of Contact (SPOC) for all second-line functional activities related to confidentiality, integrity, availability, privacy, and recovery of information. The ISO will ensure compliance with regulatory requirements and...
-
Information Security Architect
3 days ago
Singapore Schroders Full time**The team** The Information Security team at Schroders provide thought leadership on managing the information security threats and vulnerabilities to Schroders information assets and is the centre of excellence for advice and coordination. The team is comprises of various SME‘s in Technology Risk, Cybersecurity, Insider Security including Access and User...
-
Information Security Engineer
2 days ago
Singapore Haier Singapore Investment Holding Pte. Ltd. Full timeCarry out the end-to-end security management for enterprise of application security, host security, data security, network security, including but not limited to security policy management and system maintenance. Responsible for the Governance, Risk and Compliance technical implementation of personal information protection requirements. Project management,...