Home > Information Security Jobs

Information security officer

placeSingapore descriptionTemporary calendar_month 

The Information Security Officer (ISO) role is to support and be accountable for all IS activities including but not

limited to oversight of the IS Risk Management to the Franchise and its processes and support ASL where needed.

The ISO function will support & work closely with Business, Operations & Technology teams, and the overall ISO

community to oversee and monitor adherence with ASL IS Policy and Standards, manage risk and provide Business

advise on Information Security. Demonstrate understanding of cloud, mobile, application and infrastructure security

and will exercise sound judgement within existing practices and policies.

Role Attributes:

  • Perform Information Business Impact assessments and Security Risk Assessments on business applications
throughout development lifecycle for SDLC/Agile/Iterative Lifecycle.
  • Report Information Security issues/gaps with appropriate recommendations to mitigate and/or remediate

the risk as well as assist IT with corrective action plans. Provide subject matter expertise in application

development lifecycle to assess security requirements, controls and ensure that security controls are

implemented and planned
  • Promote awareness of information security policies, standards and best practices. Also, as a program
manager, manage information security assessments operational KPI/KRIs
  • Drive improvement to Information Security process, standards and policies
  • Interface with Risk, Internal Audit, external Audit, Regulator and/or provide timely support during audits.
  • Establish and maintain relationships with domain architects, project managers and IT SMEs.
  • Demonstrate good understanding of Singapore regulatory framework and local laws on information

security, technology risk, data protection. In addition, solid understanding of ISO 27001, NIST CSF, MITRE

etc.
  • Perform independent assessments of the technical security controls implemented within the system to

determine the overall effectiveness of the controls.

Requirements
  • Good understanding of Information Security control areas such as Authentication/Authorization, Access

Controls, Entitlement, Cryptography, Encryption, Network, Application/System Security, Key Management.

Vulnerability Management (OWASP, SANs)
  • Knowledge of SDLC, Agile/Iterative, DevOps/DevSecOps and integration with security assessment is
required.
  • Excellent Written and Verbal communication skills. Exhibit Strong Influencing/negotiating skills with

attention to details

business_centerHigh salary

Head of information security

placeSingapore
and fostering a secure environment for their international stakeholders. about the job. This is a strategic leadership opportunity for a seasoned professional to steer the enterprise information security roadmap and safeguard critical data assets.  •  Define...
apartmentStaffKing Pte LtdplaceBukit Merah
Conduct independent audits to assess organizations’ Information Security Management Systems (ISMS) and related management frameworks.  •  Evaluate compliance with relevant ISO standards and certification requirements.  •  Prepare audit findings, reports...
2 similar jobs: Geylang, Toa Payoh
placeSingapore
Citi Information Security Office (CISO) Technology Business Risk Group Manager candidate will work with their staff to support the APAC Citi Information Security Office (CISO) group, helping the team the associated risks for the CISO processes...