Singapore
* Drive enterprise cybersecurity strategy, governance, and capability development to strengthen organizational resilience and support business transformation * Oversee cybersecurity governance, risk management, compliance, cyber risk reporting, and security alignment across HQ and subsidiaries through governance oversight and technical advisory * Advise stakeholders on cybersecurity, privacy, data protection, and technology risks across M&A, digital transformation, cloud adoption, and modernization initiatives. * Establish and govern enterprise AI and GenAI security initiatives, including responsible AI usage, secure AI adoption, third-party AI risk management, and governance standards for AI and agentic applications * Lead cyber defense operations including incident response, threat hunting, Red Team exercises, continuous monitoring, and GenAI-driven automation to enhance detection, investigation, and operational efficiency * Operate and enhance security capabilities across SIEM, SOAR, EDR, NGFW, WAAP, DLP, CASB, SASE, CNAPP, IAM, Passwordless, and VM * Manage internal security teams and external providers (MSOC/MDR), ensuring effective governance, service delivery, and continuous improvement * Provide security leadership for digital platforms, mobile applications, APIs, cloud-native systems, and SaaS ecosystems, ensuring secure-by-design and privacy-by-design implementation * Drive security architecture strategy across identity, network, endpoint, cloud, application, and data security domains, supporting Zero Trust initiatives * Champion AppSec and DevSecOps practices by integrating automated security controls into CI/CD pipelines covering SAST, DAST, SCA, API, IaC, and container security. * Conduct security architecture reviews, cloud security assessments, supplier risk assessments, DPIA, audits, and compliance activities * Support cyber resilience initiatives including business continuity, disaster recovery, ransomware readiness, and cyber awareness programs
• As ASPAC RISO, represent the region to global information protection group, maintain regional level of security and information protection in line with global policies and standards • Develop and implement regional information protection strategies to drive operational efficiencies, form a global view of risk and reduce attack surface • Act as the first point of contact with regard to security and information protection related matters for the Global CISO, member firm CISO, regional CIO, Regional Quality & Risk Management partner • Support firms with global security functions security compliance, Managed Security Services, policy and standard, training and awareness, solutions assessment, privacy • Manage key global service suppliers and support vendor risk and security assessment • Organize regional security forum and prompt collaboration among Global security functions and firm CISOs • Oversee implementation of security projects, security solutions, initiatives, global managed security services and security & risk metrics to member firms in the region • Advise and oversee member firm security incident response
• As head of regional security team, accountable and responsible for security operations of regional business and technology services • Manage & develop regional security team, oversee security projects and security operations • Provide security advisories to executive management on regional technology projects • Lead security assessment of technology initiatives in regional hosting center and cloud environment to advise executive management risk exposure • Ensure compliance with company standards and requirements, prepare and engage independent auditors for information security compliance audit and drive remediation • Promote information protection practices and data privacy awareness • Prepare and review security controls and processes • Oversee third party supplier operations risk and responsible for cybersecurity incident response
Lead global security program for APAC region focusing on end-to-end information risk management around company security posture, develop and deploy ISMS to new sites/services in the region, conduct security and risk assessment to company critical delivery centers, primary data centers, Security Operations Center(SOC) services, Cloud Computing services, and provide advisory to the key stakeholders, manage regional internal and external audits against global security policies and ISO27001 standard, manage program schedule, budget, travel, and audit plans, regularly communicate with regional management and other key stakeholders on security governance review, ensure ISMS continuing suitability, adequacy and effectiveness. Support cybersecurity consulting opportunities.
Responsible for attaining and maintaining required security standards and accreditation of CSC China Delivery Centre (CCDC). Lead, direct, and coordinate site level security activities, local escalation point for all security events or incidents that occur at the site, ensure the compliance to the customer security requirements, communicate and liaise with corporate security governance bodies, key stakeholders, internal and external auditors to achieve security objectives, facilitate internal and external audits, provide security and risk advisory to center director, manage the budget for the security programs, systems and vendors for the site, support account Business Continuity activities.
Support Information Security Officer on planning, implementation and maintaining BS7799/ISO27001 standard in Dalian, Shanghai and Guangzhou software development centers, document, review and update IT security procedures and perform daily IT security operations, work with supporting groups and external auditors on ISMS audit, SAS70 audit, assist ISO and business to review and respond security questionnaires from existing and potential clients, facilitate client security visit and assessment, implement Business Continuity Management framework, and document account level security and BC/DR plans.