Job Description & Requirements
The primary role of Infrastructure Security Lead is to support and lead the transformation of the security services within the Technology Infrastructure and Operations team. The role will serve as a bridge between the Cybersecurity team and the various technology team to drive end to end IT security implementation as per the governance and policies. The role will be expected to have good security knowledge to lead the team and assist in developing security infrastructure standards and assist in planning out project implementation. The role will collaborate with Engineering, Architecture, Application Development, Business partners, Corporate Systems, venders / service providers, and various infrastructure and operations groups to create and support the operational environment for new and existing services. The right candidate earns trust through outstanding performance, effective communication skills, and a strong record of delivering results timely and effectively. You should have experience managing security programs and implementing security standard.
Key Responsibilities
● Performing end to end IT solutioning and workflows risk assessment to identify potential technology security risks and propose mitigation solutions.
● Responsible for all cyber security related activities of the systems under the technical team.
● Ensure compliance and secure operation of the application in accordance with internal processes, procedures, and compliance requirements set forth by the Cybersecurity policy.
● Ensuring that requirements in IT Audit, Standard, Policy, Compliance and Risk controls are met when providing security solutioning.
● Define and delivery measure to ensure the effectiveness of controls.
● Provide technology security best practices and security consultancy to multi cross functional business teams.
● Understanding business requirements and capable to apply Security-By-Design.
● Ability to articulate security requirement and present in technology language.
● Grow Security Technology team competence.
● Five years or more of IT Service Management, enterprise networking, voice, and security and/or project management is preferred.
● Facilitate teams to critically review current processes for effectiveness, quality, and simplification.
- Review and approve network security measures and monitoring.
● Develop and implement process solutions to improve operational efficiency.
● Hand-on experience in leading security project, audit and compliance.
Required Skills and Knowledge
● BA/BS degree or equivalent experience.
● Minimum 8 years of relevant experience in Cyber Security.
● Experienced with PCI DSS, ISO Standards, Payment Service Act by MAS, PDPA and GDPR.
● Security certifications (E.g. CISSP, CISM, ISO27001 Lead Auditor, LPT, CMQAPT).
● Persistence, stakeholders influence and attention to detail personality.
● Open minded to explore security initiatives.
● Knowledge in NIST, ISO27001, OWASP Security Standard.
● 3 years or more in leading and managing projects.
● 3 years related experience in infrastructure/network/storage environments and designing, planning, documenting and implementation of infrastructure. Professional experience architecting/operating solutions built on Network and Security.
● Experience migrating or transforming legacy business/ customer solutions to the cloud.
● Outstanding customer relationship management, operations, delivery experience and collaboration skills.
● Demonstrated ability to think strategically about business, product, and technical challenges.
● Familiarity with archive, disaster recovery and business continuity in global operations.
● Familiarity with compliance & security standards across the enterprise IT landscape. Required Competencies
● Effective communicator at all levels of the organisation and outside with third parties
● Familiarity with project management approaches, tools, and phases of the project lifecycle.
● Exceptional communication skills – both written and verbal.
● Ability to be personable and tenacious as the situations requires.
● Able to work effectively at all levels in an organization. Excellent active listening skills.
● Problem solving and root cause identification skills. Strong analytic and decision-making abilities. ● Must be a team player and able to work with and through others.
● Ability to influence others and move toward a common vision or goal.
● Ability to work in a multicultural and international environment.
● Integrity & Self Development (live up to commitments; seek feedback to enhance performance; deal constructively with own mistakes).
Required Qualifications
● Degree in IT or equivalent
● Professional certifications such as
o IT Service Management (ITIL) best practices o Security Certification o Other Technical certifications