Information Security
7 days ago
At Bank of Singapore, we are constantly on the lookout for exceptional individuals to join our team. We promote a culture of openness, teamwork and fairness. Most importantly, we invest in our people through our programmes that develop them on both professional and personal levels. Besides attractive remuneration packages, we offer non-financial benefits and opportunities to develop your potential within OCBC Group’s global network of subsidiaries and offices. If you have passion, drive and the will to succeed, rise to the challenge today
Responsible for second line of defence related to governance and oversight of Information Security Risk and Digital Risks (Technology, Information and Cyber) within the organisation.
**Responsibilities**
- Lead and support the risk governance and oversight of Information Security Risk and Digital Risks (Technology, Information and Cyber) in second line.
- Lead second line Information Security initiatives and establish/roll-out Local Information Security Office (LISO) program to each of global locations within the organisation.
- Lead and represent second line in regulatory assessments in Information Security risk and Digital risks topics.
- Lead and / or support internal / cross-functional initiatives such as technology, information and cyber thematic and process reviews, as well as technology projects.
- Lead and / or participate in risk committees and working groups that have been established to enhance governance and oversight over Information Security risk and Digital risks matters.
- Develop, review and maintain Information Security and Digital risk framework, policies and departmental operating procedures to ensure that they are relevant, up to date and aligned to Group and regulatory standards.
- Monitor Information Security and Digital risk exposures via dashboards and Key Risk Indicators (KRIs) and provide independent reporting on the effectiveness of risk posture or activities to management.
- Provide risk advisory services to business units on the adoption of new and emerging technologies (e.g. cloud computing, Fintech etc), as well as third party arrangements.
- As a second line of defence, provide an effective challenge on the adequacy, completeness and timeliness of risk assessments and / or action plans that have been put in place to address prevailing and emerging Information Security and Digital risks. This includes the review of system risk acceptances.
- Plan and deliver a comprehensive Information Security and Digital risk awareness training and testing program for all staff. This includes the conduct of periodic social engineering tests to reinforce awareness.
**Qualifications**
- Good understanding of banking processes, technology, operations, and regulations (in particular MAS Technology Risk Management Guidelines), as well as ISO 27001.
- Prior experience in managing projects / change initiatives would be an added advantage
Academic and professional qualifications
- University degree preferred.
- Professional certification in information security. E.g. CISA, CISM, CRISC, CISSP etc.
- Proficient in Microsoft Office Applications (i.e. Excel, PowerPoint, Word).
Language skills
- Fluent in English.
Personal attributes
- Good communication, presentation and interpersonal skills to facilitate interactions with key stakeholders within and outside of the organisation.
- Ability to collaborate well within the team, department and across different departments/locations.
- Able to exercise sound judgment and establish plans to manage the execution of deliverables within the stipulated timelines.
- Self-driven with attitude and aptitude to learn and accomplish tasks that have been assigned.
- Analytical mindset and good report writing skills.
- Able to prioritise and multi-task in a competitive environment
- A team player.
-
Singapore SMART INFORMATION MANAGEMENT SYSTEMS PRIVATE LIMITED Full time**Key Responsibilities**: **Cybersecurity Risk Assessment & Mitigation**: - **Cyber Risk Assessment**:Conduct comprehensive cyber risk assessments in support of technology initiatives, identifying IT-related risks and recommending appropriate security controls to mitigate those risks. - **Risk Monitoring & Management**:Continuously track and manage risk...
-
Information Systems Security Developer
1 week ago
Singapore FEDERAL SECURITY SERVICES PTE. LTD. Full timeDesign artefacts, spanning design, development, and implementation, into enterprise systems that describe security principles and how they relate to the overall enterprise system architecture. - Perform routine activities related to the periodic review and audit activities of infrastructure security systems and maintains documentation of security standards...
-
Information Security
2 weeks ago
Singapore Scoot Tigerair Pte Ltd Full time $40,000 - $60,000 per yearInternshipSummaryProvide better appreciation and experiential learning in Cybersecurity defence in terms of concepts, architecture, technologies, tools, and operations.Job DescriptionResponsibilities:Application SecurityResearch web and mobile application security best practicesResearch into the latest IAM technologies and propose enhancements to existing...
-
Information Security
1 week ago
Singapore HQ Scoot Full time $80,000 - $120,000 per yearSummaryProvide better appreciation and experiential learning in Cybersecurity defence in terms of concepts, architecture, technologies, tools, and operations.Job DescriptionResponsibilities: Application Security- Research web and mobile application security best practices- Research into the latest IAM technologies and propose enhancements to existing SIA...
-
Information Security
1 week ago
Singapore Lexagle Full time $80,000 - $120,000 per yearCompany IntroductionLexagle is a Singapore-headquartered legal tech company dedicated totransforming how businesses manage their contracts and legal workflows.We value innovation, security, and collaboration, ensuring our technologyand operations meet the highest standards of compliance and trust.Position OverviewWe are seeking an experienced and highly...
-
Information Security Manager
1 day ago
Singapore SINGAPORE AEROSPACE MANUFACTURING PTE LTD Full timeSAM is looking to fill the position of **Information Security Manager **. This is a regional role and is overall in-charge of all the entities under SAM. He/She will report to the CEO. **Responsibilites** - To develop and implement a long-term Information Security & Cyber Security strategies and roadmap to protect corporate information and IT assets. - Set...
-
Information Security Manager
3 days ago
Singapore SPARROW RESEARCH PTE. LTD. Full time**Job Summary** Implement and oversee Sparrow's IT security operations framework, including security operations role definitions, monitoring, incident and event management, privileged access management, and overall security architecture. Ensure compliance with industry standards and regulatory requirements. **Responsibilities**: - Define and implement IT...
-
Director, Information Security
7 days ago
Singapore Ensign InfoSecurity Full timeEnsign is hiring ! As Director, Information Security, you will play a crucial role in implementing Ensign's cybersecurity vision. Reporting to the Information Security Office, you will collaborate with senior management and business units on cybersecurity initiatives. You will play a crucial role in supporting the CISO in establishing and maintaining an...
-
Head of Information Security
2 weeks ago
Singapore ECARX TECHNOLOGY PTE. LTD. Full time $120,000 - $200,000 per yearJob ResponsibilitiesAble to break down detailed information security compliance technical requirements and rules, and can support the identification, improvement, tracking, and post-event evaluation of security risks associated with related business.Interface with and organize business departments to participate in non-China regulatory agencies' security...
-
Engineer (Information Security)
7 days ago
Singapore Good Job Creations Pte Ltd Full timeProvides security analysis of IT activities to ensure that appropriate security measures are in place and are enforced. - Assists with the development and maintenance of corporate security policies and procedures, the remediation of identified risks, and the implementation of security measures to ensure information systems’ reliability and to prevent and...