Information Security Manager
10 months ago
Roles and responsibilities:
Develop and implement a long-term Information Security & Cyber Security strategies and roadmap to protect.....
Roles and responsibilities:
- Develop and implement a long-term Information Security & Cyber Security strategies and roadmap to protect corporate information and IT assets.
- Set up Cyber Security policy to standardize practice and govern all the security landscape within the group of companies.
- Provide Information security & Cyber Security strategic advice to senior management.
- Implement Information & Cyber Security testing strategy not limited to penetration testing, code review, black-box, white-box, network security scan and vulnerabilities assessment.
- Carry out independent oversight and enforce business units’ compliance with the Information & Cyber Security policies and standards.
- Drive effective implementation and communication of IT risk management and Information & Cyber Security policies, standards and guidelines.
- Perform regular reviews of the Information & Cyber Security policies and related risk assessment.
- Modernize and optimize the conduct of governance and oversight roles to maintain risk register, third-party vendor assessment, leveraging and advanced analytics for trending and compliance monitoring.
- Manage Information & Cyber Security and Personal Data Protection matters, liaise with different stakeholders and oversee the implementation of it to improve the overall Information Security, Cyber Security and Personal Data Protection.
- Work closely with IT infrastructure and application teams to ensure that overall Information & Cyber Security Architecture governance is embedded into IT operations processes.
- Conduct regular review of Security Operations Center (SOC) activities and proactively identifying and preventing threats.
- Drive the review and enhancement of third-party vendor risk management and establish a holistic framework and structure to manage the risk.
- Ensure the Information & Cyber Security practices are in compliance with applicable laws, regulations and policies.
- Conduct regular communication and refresher briefing to senior management to maintain a good level of Information & Cyber Security and information risk awareness
Requirements:
- Degree in IT/Computer Studies or Diplomas with extensive relevant cybersecurity experience
- At least 5-7 years of relevant working experience in the field of Information Security and Cybersecurity
- Possess at least one of professional cyber security certifications such as CISA, CISSP and CISM. Those with CEH, CRISC will have added advantage.
- Good communication, interpersonal skills, with proven abilities to manage multiple priorities, drive project teams and collaborate across business units and partners to achieve desired goals.
- Possess Information & Cyber Security domain knowledge across areas such as IT architecture and solutions, security operation center, application security, infrastructure & network security, data & information protection, supply chain security, cloud security, Information & Cyber Security regulations and compliance will have added advantage.
- Strong experience and knowledge in technology and Information & Cyber Security standards and policy review, oversight and governance, risk management and audit.
- In-depth knowledge of industry information and cyber security practices, frameworks and standards such as the NIST Cybersecurity Framework and ISO 27001.
- Hands-on working knowledge in managing and delivering security penetration testing, vulnerability management services and application security.
Official account of Jobstore.