Epicareer Might not Working Properly
Learn More

Group Chief Information Security Officer

Salary undisclosed

Checking job availability...

Original
Simplified

Roles & Responsibilities:

  • Provide strategic vision and leadership, driving the development and implementation of both short- and long-term information security and technology risk initiatives that aligns with NTT DATA Payment Services strategic goals and vision.
  • Ensure global, regional standards and where applicable, local standards in the execution of Information
  • Security and Technology Risk activities are adhered to.
  • Drive the implementation of the organisation’s information security (technology risk included) strategy (to achieve and maintain a security capability that is consistent with the organization and related cyber security requirements across the industry.
  • Proactively lead the organization in advancing information security posture, explore and recommend the latest available technologies on cyber resilience, regularly report on information security performance, progress of controls implementation, and levels of cyber resilience automation.
  • Responsible for ensuring compliance with regulatory frameworks and standards to identify, measure and control technology and cyber risks. This would entail developing and implementing controls within the organisation’s Business Continuity Management, Enterprise Risk Management, Technology Risk Management and related frameworks/policies.
  • Guide and organise information security efforts, expenditure and capital investment in the implementation of a Cyber Resilience Framework (CRF) and perform appropriate financial budgeting for security to achieve the organisation’s cyber resilience vision and desired security posture. For this purpose, this job holder will be required to engage the Group Technology team in ensuring the appropriate budgeting is undertaken.
  • Lead the functions of Technology related operational risk governance and to ensure effective reporting of technology and information risks (cyber risk included) to the Senior Management and Board Committee members.
  • Involvement in project implementation in ensuring that technology related risks and cyber risk governance standards are adequately adhered to.
  • Oversee and implement a Information Security based risk aware culture in the organisation towards strengthening the organisation’s cross functional capability in managing Technology Risk and Information Security.
  • Proactively lead in advancing the organisation’s cyber security posture, explore and recommend the latest available technologies on cyber resilience, regularly report on cyber security performance, progress of controls implementation, and levels of cyber resilience automation.
  • Execute QA/spotcheck testing to support and deliver a cyber resilience plan for the organisation, premised on a risk-based approach complemented by industry level standards by regulators and card schemes.
  • Define and track key cybersecurity metrics (e.g. incident response times, breach containment timers, vulnerability remediation timeframes) to provide visibility into the organization’s security posture.
  • Represent the organisation (where required upon approval by supervisor) when dealing with external parties such as law enforcement agencies, customers, service providers on cyber resilience related matters.

Requirements:

  • Degree in Information Technology (IT), Computer Science, Information Security or Technology Risk Management related discipline with relevant experience in managing Technology Risk/Information Security in financial market infrastructures, critical national infrastructure, military, security intelligence or equivalent.
  • Fluency in in written and spoken English is essential for this position.
  • Cyber security expert with 7 to 10 years or more hands-on experience or more than 15 to 20 years relevant experience in the capacity of Chief Information Officer (CIO), Head of IT Risk, Head of IT Audit or Head of IT Security.
  • Familiarity of PCIDSS, ISO 27001, NIST (National Institute of Standards & Technology), CIS (Centre for Internet Security), BNM RMiT or Technology Risk Management Guidelines or other industry-relevant information security management frameworks.
  • Understanding of Data Protection Laws (PDPA), Card Scheme Technology and Payment Industry technology is an added advantage.
  • Good knowledge of Technology Operations and Security & how Technology interfaces with the Business, Risk Management and Compliance or IT Security processes.
  • Professional certification such as CISM, CISA, CSXP, CISSP, CREST, GPEN or equivalent is required.
  • Must possess excellent interpersonal skills and able to communicate and manage relationship at all levels including senior management, business users, vendors and team members.

Roles & Responsibilities:

  • Provide strategic vision and leadership, driving the development and implementation of both short- and long-term information security and technology risk initiatives that aligns with NTT DATA Payment Services strategic goals and vision.
  • Ensure global, regional standards and where applicable, local standards in the execution of Information
  • Security and Technology Risk activities are adhered to.
  • Drive the implementation of the organisation’s information security (technology risk included) strategy (to achieve and maintain a security capability that is consistent with the organization and related cyber security requirements across the industry.
  • Proactively lead the organization in advancing information security posture, explore and recommend the latest available technologies on cyber resilience, regularly report on information security performance, progress of controls implementation, and levels of cyber resilience automation.
  • Responsible for ensuring compliance with regulatory frameworks and standards to identify, measure and control technology and cyber risks. This would entail developing and implementing controls within the organisation’s Business Continuity Management, Enterprise Risk Management, Technology Risk Management and related frameworks/policies.
  • Guide and organise information security efforts, expenditure and capital investment in the implementation of a Cyber Resilience Framework (CRF) and perform appropriate financial budgeting for security to achieve the organisation’s cyber resilience vision and desired security posture. For this purpose, this job holder will be required to engage the Group Technology team in ensuring the appropriate budgeting is undertaken.
  • Lead the functions of Technology related operational risk governance and to ensure effective reporting of technology and information risks (cyber risk included) to the Senior Management and Board Committee members.
  • Involvement in project implementation in ensuring that technology related risks and cyber risk governance standards are adequately adhered to.
  • Oversee and implement a Information Security based risk aware culture in the organisation towards strengthening the organisation’s cross functional capability in managing Technology Risk and Information Security.
  • Proactively lead in advancing the organisation’s cyber security posture, explore and recommend the latest available technologies on cyber resilience, regularly report on cyber security performance, progress of controls implementation, and levels of cyber resilience automation.
  • Execute QA/spotcheck testing to support and deliver a cyber resilience plan for the organisation, premised on a risk-based approach complemented by industry level standards by regulators and card schemes.
  • Define and track key cybersecurity metrics (e.g. incident response times, breach containment timers, vulnerability remediation timeframes) to provide visibility into the organization’s security posture.
  • Represent the organisation (where required upon approval by supervisor) when dealing with external parties such as law enforcement agencies, customers, service providers on cyber resilience related matters.

Requirements:

  • Degree in Information Technology (IT), Computer Science, Information Security or Technology Risk Management related discipline with relevant experience in managing Technology Risk/Information Security in financial market infrastructures, critical national infrastructure, military, security intelligence or equivalent.
  • Fluency in in written and spoken English is essential for this position.
  • Cyber security expert with 7 to 10 years or more hands-on experience or more than 15 to 20 years relevant experience in the capacity of Chief Information Officer (CIO), Head of IT Risk, Head of IT Audit or Head of IT Security.
  • Familiarity of PCIDSS, ISO 27001, NIST (National Institute of Standards & Technology), CIS (Centre for Internet Security), BNM RMiT or Technology Risk Management Guidelines or other industry-relevant information security management frameworks.
  • Understanding of Data Protection Laws (PDPA), Card Scheme Technology and Payment Industry technology is an added advantage.
  • Good knowledge of Technology Operations and Security & how Technology interfaces with the Business, Risk Management and Compliance or IT Security processes.
  • Professional certification such as CISM, CISA, CSXP, CISSP, CREST, GPEN or equivalent is required.
  • Must possess excellent interpersonal skills and able to communicate and manage relationship at all levels including senior management, business users, vendors and team members.