ED, Cybersecurity Governance, Risk & Compliance Head, Information Security Services, Group Technology
DBS Bank Singapore, Singapore, Singapore
Banking · 10,001+ employees
Applying here? Try the free cover letter tool — paste this posting and your résumé, no account needed.
About the role
The role involves driving cybersecurity governance, regulatory compliance, and data protection programs as the first line of defense. Responsibilities include developing security standards, managing risk assessments, and overseeing data loss prevention and security awareness initiatives.
What they look for
Requirements
Candidates must have 15 or more years of experience in information security within financial or technology environments. Strong expertise in security frameworks, risk management, data analytics, and regulatory compliance is required.
Full description
Business Function
Group Technology enables and empowers the bank with an efficient, nimble, and resilient infrastructure through a strategic focus on productivity, quality & control, technology, people capability and innovation. In Group Technology, we manage most the Bank's operational processes and inspire to delight our business partners through our multiple banking delivery channels.
About the role
DBS operates a 3 Lines of Defence model for cybersecurity risk management. This role serves as Line 1, with responsibilities for driving regulatory compliance and governance, awareness and training and data protection for cybersecurity within the bank.
Cybersecurity Governance, Risk and Compliance
As the 1st Line of Defence, the incumbent is responsible for driving the Bank’s compliance with the relevant cybersecurity legislation (e.g. Singapore’s Cybersecurity Act) and regulations (e.g. MAS).
The responsibilities include:
- Development of cybersecurity standards and guidelines,
- Assessment and validation of cyber risks and controls applic , and
- Reporting and providing assurance for the cybersecurity program to DBS risk committees.
The candidate will work with key stakeholders to implement controls and practices to manage the cyber risks and ensure the identified risks and gaps are adequately addressed and remediated. The candidate is also responsible for providing oversight and governance over cybersecurity related activities and update management on the metrics and compliance posture of the cybersecurity environment.
Cybersecurity Awareness and Training
The candidate is responsible for the development and delivery of the cybersecurity awareness and training program for the stakeholders within the Bank, including the design and development of targeted content to meet the training needs for the different roles in the Bank. The candidate is to continuously assess the efficacy of the training program, and improve and update the training content.
Data Protection Management
The incumbent will be responsible for the driving the data protection program including data loss management within the Bank. This includes the design of the data protection control environment, implementation and operations of the data protection technologies, and driving the data protection operations. The role also requires the candidate to drive the inhouse data analytics program to prioritize data loss events and identify potential misuse of the Bank’s applications and customer data. This role will be required to work closely with key stakeholders including the Enterprise Data Security and Data & AI Risk team.
Cybersecurity Governance, Risk and Compliance Responsibilities
- Legislation, regulations and policies
- Review and assess the Bank’s cybersecurity policy architecture for compliance with new and emerging cyber security legislation, regulations and policies.
- Review and update information security standards to comply with the regulatory requirements as required
- Work with regional information security services teams in the core markets to monitor new cybersecurity legislation and/ or regulation, and assess the impact to and the compliance of the Bank’s security policy architecture
- Where necessary, work with Line of Business Technology units to drive change management to comply with the regulatory guidelines
- Security risk and compliance
- Work with key Line of Business Technology to manage material changes to critical systems, conduct risk control self assessment to assess key cybersecurity controls and risk areas and ensure continuous compliance with the cybersecurity legislation and regulations
- Engage Line of Business Technology units to conduct annual cybersecurity risk assessment for key bank systems as required under the prevailing regulations
- Engage external auditors and certification bodies to assess and audit key bank systems and control environment under the Cyber Trust Mark, ISO27000, SOC2 and Cybersecurity Act
- Focal point for international centres on information security matters
- Security metrics
- Develop and maintain a set of security metrics and visualization for the reporting of cybersecurity landscape to senior management and the Board
- Where possible, automate the extraction, transformation and loading of raw security events to generate the security metrics and graphs for the reporting
- Establish a framework to organize, manage and archive the security data used for the generation of security metrics and visualization
- Generate quarterly reports and insights to apprise senior management of the security trends and areas of concern
Cybersecurity Awareness and Training
- Conduct regular phishing exercises and disseminate timely cybersecurity content to inculcate the cybersecurity hygiene and practices
- Develop targeted training content and collaborate with various control functions to deliver the content to meet the training needs for specific stakeholders
- Drive annual cybersecurity awareness campaign to promote cybersecurity culture and behavior
Data Protection Management
- Data Loss Prevention
- Design and implement data protection controls to mitigate the risk of data loss across various channels including web, email, network, endpoint etc.
- Work with Line of Business Technology to design and implement technology enablers to support the secure handling of Bank’s and customers’ data
- Review and investigate data loss events and refer substantiated events to HR for disciplinary actions
- Continuously review and enhance the data protection controls to improve the efficacy of data loss prevention
- Provide management reporting on data loss matters to the Bank’s risk committees.
- Unusual Employee Behavior Monitoring
- Drive the implementation of data analytics and machine learning techniques to • Prioritize and highlight data loss events for review and investigation
- Identify suspicious activities and misuse of applications and customer data
- Oversee the inhouse development of the machine learning models and investigation platform
- Drive the development and implementation of data visualization techniques to improve the efficiency of the review and investigation process
- Drive the development and enhancement of the investigation platform to meet the users’ need
Requirements
- Information security professional with 15 or more years of experience, with a background in a financial or technology environment.
- Experience in implementing a program the collation, management and reporting of security metrics such as open security vulnerabilities, penetration testing findings, security alerts and incidents, etc.
- Experienced in information security framework including ISO27000, NIST800-53 and regulations such as Cybersecurity Act, Technology Risk Management Guidelines and Personal Data Protection Act.
- Good working knowledge of enterprise security risk management methods and techniques to successfully deliver the security risk management and assessment outcome.
- Strong background on security technology solutions including IDS, IPS, anti-virus, content filtering, secure email solutions, network sniffing, log analysis, forensics and VPN
- Hands-on technical experience in the management of security data for the generation of security metrics and visualization
- Good working knowledge of data analytics, machine learning techniques and software development lifecycle
- Good verbal and written communication for the generation of security awareness content
- Proactive, analytical and independent worker with strong organization skills and performance-oriented, demonstrate effectiveness to track and follow up on the assigned projects
- Regional experience is a plus and the ability to travel on need-to basis
Location:
DBS Asia Hub
Job:
Technology
Schedule:
Regular
Employee Status:
Full time
Similar roles
-
Senior Product Security Engineer
Chainguard United States · $157K–$184K/yr
-
Cybersecurity Operations Lead
Edgewater Federal Solutions, Inc. Albuquerque, New Mexico, United States
-
Senior Security Engineer
Kiteworks United States · $75K–$90K/yr
-
Senior Application Security Engineer
Jobgether India
-
Principal Security Engineer Cloud and Infrastructure Security
Jobgether India
-
Security Engineer (DevSecOps / AppSec)
Jobgether Brazil