Manager, Information Security

2 weeks ago


Singapur, Singapore Corporate Full time

JOB SUMMARY

The candidate will be responsible for governing the vendor security risk management and cyber risk management for Asia Pacific exclude China, including conducting risk assessments and periodic re-assessments, performing application security testing and provide remediation options, and evaluations. He\She will also assist in managing relationship with Service Providers who are responsible for the actual delivery of services, managing outcomes and results, and collaborating with stakeholders across IT and business departments to develop strategies for securing company information and assets. Shares responsibility for planning, directing, and coordinating compliance activities pertaining to technology projects for a given business unit. Verifies that project goals are accomplished and in line with business objectives.

The candidate will also work with other peers to coordinate, articulate, and track actions related to developing and driving the implementation of cybersecurity risk management plans for Asia Pacific, ensuring effective cyber security risk management practices, and engaging with business unit members on a wide range of cyber security matters to achieve overall business objectives.

The candidate will also be responsible for supporting the overall Asia Pacific security program including security policy, procedures, and standards, ensuring Marriott iT documents are compliant with Marriott security policies and procedures, and reviewing documents for accuracy and completeness.

Excellent communication skills are required to effectively communicate (verbally and written) across all levels within the organization.

CANDIDATE PROFILE

Education and Experience

Required:

Bachelor’s degree in information systems or related field or equivalent experience/certification 5+ years security governance, risk management and compliance related experience with 2+ years direct work experience in third-party security Risk Management Fluent in English  One or more current information security certifications such as Certified in Risk and Information Systems Controls (CRISC), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA) or Certified Information Systems Security Professional (CISSP) Possession of good communication skills (including soft skills, structured thinking, effective report writing and presentations, and stakeholder engagement) A team player, with positive attitude and enthusiasm in the performance of responsibilities Strong innovative thinking, able to continuously enrich and improve the security policy, procedure and standards.

Preferred:

A security certification such as GWAPT, GPEN, AWS Associate Architect, AWS Professional Architect, PCI experience. Technical knowledge in one or more of the following areas is required: Application Security, Operating System security (UNIX, Windows, Mainframe, etc.) and network security (routers, switches, firewalls)  Technical leadership experience in an outsourced environment Excellent communication skills and problem-solving ability Experience conducting and maintaining vendor risk assessments Experience with reviewing and assessing security controls of Cloud service providers Proficient with assessing a multi-tiered system architecture (Web Server, App Server & Database) Knowledge of OWASP Top and SANS . Working knowledge of the infrastructure and application scanning tools (such as Retina, Nessus, IBM App Scan, HP Web Inspect, Fortified on Demand, Qualys, etc.) Manual Web Application Testing experience. Familiarity with ISO and PCI DSS Standards

CORE WORK ACTIVITIES

Vender Risk Management & Cyber Risk Management

Oversee, evaluate, and support the documentation, and validation processes necessary to assure that associates, information technology systems and business processes meet the organization’s information assurance, security, and privacy requirements. Ensures appropriate treatment of risk, compliance, and assurance of internal policies and external regulations. Develop strategy for the vendor information security risk compliance program Perform security controls assessments of third-party providers – assess security architecture, adherence to the requirements, conduct application scanning and results validation Document controls gap analysis and risk assessment of the third-party providers Review controls exception requests and make risk-based approval decision Lead, participate or perform various infrastructure compliance initiatives and projects  Perform Application Security Testing using (Nessus, IBM App Scan, HP Web Inspect, Fortified on Demand, Qualys, Burp, or Retina)  Conduct and validate finding discovered during the scans Monitor compliance to applicable security policies and standards and report related risk issues Manage and administer processes and tools that enable the organization to identify, document, and track third party risks and compliance exceptions Conduct assessments of threats and vulnerabilities, determine deviations from acceptable configurations or enterprise or local policy, assess the level of risk, and develop and/or recommend and operationalize appropriate mitigation countermeasures. Provide sound advice and recommendations to leadership and staff on a variety of relevant topics within the pertinent subject domain. Advocate policy changes and make a case on behalf of the company via a wide range of written and oral work products.

Managing Projects and Priorities 

Champions leaders’ vision for product and service delivery.  Thinks creatively and practically to develop, execute, and implement new project plans.  Generates and provides accurate and timely results in the form of reports, presentations, etc.  Plans, develops, implements, and evaluates the quality of operations.  Supports regulator inspections, coordinates submission preparation, and tracks remediations. Supports cyber regulation awareness program catering to various roles in the entity.

Delivering on the Needs of Key Stakeholders 

Understands and meets the needs of key stakeholders.  Communicates concepts in a clear and persuasive manner that is easy to understand.  Demonstrates an understanding of business priorities.  Supports achievement of performance goals, budget goals, team goals, etc. Generates and provides accurate and timely results in the form of reports, presentations, etc.

Providing Technical Support and Consultation 

Provides recommendations to improve the effectiveness of processes and programs.  Demonstrates advanced knowledge of job-relevant issues, products, systems, and processes. Demonstrates advanced knowledge of function-specific procedures.  Applies knowledge/judgment to achieve business goals.  Foresees, identifies, and resolves problems.  Keeps up-to-date technically and applies new knowledge to job.  Performs other reasonable duties as required for this position. 

Marriott International is the world’s largest hotel company, with more brands, more hotels and more opportunities for associates to grow and succeed. Be where you can do your best work,​ begin your purpose, belong to an amazing global​ team, and become the best version of you.

  • Senior Manager

    4 weeks ago


    Singapur, Singapore IHiS Full time

    Job Responsibilities Roles and requirement  Defining and maintaining corporate-wide information security governance and controls to ensure that information assets are adequately protected · Involved in Identifying, evaluating and reporting of information security risks in a manner that meets compliance and regulatory requirements · Work closely with...


  • Singapur, Singapore KPMG - Singapore Full time

    Job DescriptionGISG (Global Information Security Group) is one of five domains within KPMG's Global Technology & Knowledge group. GISG provides the information protection and technology infrastructure that secures KPMG's technology environment and connects its network of member firms. GISG works with the other GT&K domains to ensure that appropriate security...


  • Singapur, Singapore Nityo Infotech Full time

    Key Responsibilities• Plan and conduct the security review for bank’s IT systems throughout the lifecycle covering different layers of technology architecture to identify the risk. This covers both in-house and 3rd party hosted systems.• Work closely with business stakeholders to ensure security risks are identified, communicated, understood and assist...


  • Singapur, Singapore Ensign InfoSecurity Full time

    Ensign is hiring !As Director, Information Security, you will play a crucial role in implementing Ensign's cybersecurity vision. Reporting to the Information Security Office, you will collaborate with senior management and business units on cybersecurity initiatives. You will play a crucial role in supporting the CISO in establishing and maintaining an...


  • Singapur, Singapore Razer Full time

    Job Responsibilities :The Senior Information Security Manager is responsible for implementing the organisation's information security (InfoSec) solutions and the development of security frameworks, policies, and controls. He/she will collaborate with experienced business/technology leaders and cross-functional teams to ensure the security of IT systems,...


  • Singapur, Singapore Scotiabank Full time

    Purpose Contributes to the overall success of the IS&C Department in Asia-Pac Region ensuring specific individual goals, plans, initiatives are executed / delivered in support of the team’s business strategies and objectives. Ensures all activities conducted are in compliance with governing regulations, internal policies and procedures. ...

  • Senior Consultant

    4 weeks ago


    Singapur, Singapore Sia Partners Full time

    Job description Due to our exceptional growth in Asia, we are looking for a Senior Consultant specialized in Information Security to join our team in Singapore. As a Senior Consultant, you will help to build our expertise and guarantee the quality of delivery to ensure market-leading practices for our Singapore office, taking into account the global...


  • Singapur, Singapore AIA Full time

    At AIA we’ve started an exciting movement to create a healthier, more sustainable future for everyone. If you believe in developing a better tomorrow, read on.  About the Role This position is responsible for providing consultation, professional advice, awareness/training on information security and key technology risk matters relating to the...


  • Singapur, Singapore Crédit Agricole CIB Full time

    Description du poste Chief Information Security Officer for ISS Singapore Reporting functionally to the Global CISO - Head of ISS in CACIB Paris, and hierarchically to the Head of ISAP, he is: - CISO of Singapore Branch - Head of APAC/ME ISS filière, that coordinates Information Security on the APAC/ME region. He/She is in charge of assessing the...


  • Singapur, Singapore Crédit Agricole CIB Full time

    Job description Business type Types of Jobs - IT, Digital et Data Job title Chief Information Security Officer Contract type Permanent Contract Job summary Chief Information Security Officer for ISS Singapore Reporting functionally to the Global CISO - Head of ISS in CACIB Paris, and hierarchically to the Head of ISAP, he...


  • Singapur, Singapore RAS SECURITY PTE. LTD. Full time

    Roles & ResponsibilitiesOPERATION EXECUTIVE for Security Agency Located at Woodlands- Must be able to travel island-wide for Meetings- Deployment of Security Manpower- Schedule their work shift, Leavedeveloping and implementing security policies, protocols and procedures• Recruiting, training and supervising security officers• Build rapport with security...


  • Singapur, Singapore NCS Full time

    NCS is the leading technology services firm that operates across the Asia Pacific region in over 20 countries, providing consulting, digital services, technology solutions, and more. We believe in harnessing the power of technology to achieve extraordinary things, creating lasting value and impact for our communities, partners, and people. Our diverse...


  • Singapur, Singapore NCS Group Full time

    NCS is the leading technology services firm that operates across the Asia Pacific region in over 20 countries, providing consulting, digital services, technology solutions, and more. We believe in harnessing the power of technology to achieve extraordinary things, creating lasting value and impact for our communities, partners, and people. Our diverse...


  • Singapur, Singapore United Overseas Bank Full time

    VP, Business Information and Cyber Security Manager Posting Date: 24-May-2023 Location: Alexandra (City Area), Singapore, Singapore, 048624 Company: United Overseas Bank Ltd About UOB United Overseas Bank Limited (UOB) is a leading bank in Asia with a global network of more than 500 branches and offices in 19 countries and territories in...


  • Singapur, Singapore United Overseas Bank Full time

    VP, Business Information and Cyber Security Manager Posting Date: 16-May-2023 Location: Singapore (City Area), Singapore, Singapore, 048624 Company: United Overseas Bank Ltd About UOB United Overseas Bank Limited (UOB) is a leading bank in Asia with a global network of more than 500 branches and offices in 19 countries and territories in...


  • Singapur, Singapore First Abu Dhabi Bank Full time

    Job Description Job Purpose:: The Regional Security Head (RSH) will be responsible for managing the FAB’s Information Security Program at the regional level. The Regional Security Head will report to Head of International Security and shall be responsible to plan, implement, monitor, and review the information security program in the consultation...


  • Singapur, Singapore JPMorgan Chase & Co. Full time

    Take on a crucial role where you'll be a key part of a high-performing team delivering secure software solutions. Make a real impact as you help shape the future of software security at one of the world's largest and most influential companies. As a Lead Security Engineer at JPMorgan Chase within the Cyber Security and Technology Controls you are an...


  • Singapur, Singapore GovTech Singapore Full time

    The Government Technology Agency (GovTech) is the lead agency driving Singapore’s Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm Technology and Smart Systems (ICT & SS), GovTech develops the Singapore Government’s capabilities in Data Science & Artificial Intelligence, Application...


  • Singapur, Singapore Careers@Gov Full time

    The Government Technology Agency (GovTech) is the lead agency driving Singapore’s Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm Technology and Smart Systems (ICT & SS), GovTech develops the Singapore Government’s capabilities in Data Science & Artificial Intelligence, Application...

  • Lead IT Consultant

    4 weeks ago


    Singapur, Singapore Singapore Institute of Technology Full time

    As the Lead IT Consultant, you will support the Communications & Information Technology division in all SIT's IT security initiatives Job Responsibilities: Lead the IT Security team to manage and all IT security-related matters that support SIT’s business objectives and strategies. Develop and carry out IT security policies and plans. Conduct...