DBS Bank

ED, Cybersecurity Governance, Risk & Compliance Head, Information Security Services, Group Technology

DBS Bank Singapore, Singapore, Singapore

Banking · 10,001+ employees

10 h ago
security Principal (10+ yrs) Full-time Singapore
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The role involves driving cybersecurity governance, regulatory compliance, and data protection programs as the first line of defense. Responsibilities include developing security standards, managing risk assessments, and overseeing data loss prevention and security awareness initiatives.

What they look for

Cybersecurity Governance Risk Management Regulatory Compliance Data Protection Information Security Security Metrics Data Analytics Machine Learning Cybersecurity Awareness Data Loss Prevention ISO 27000 NIST 800-53 Security Auditing Change Management Incident Management Stakeholder Management

Requirements

Candidates must have 15 or more years of experience in information security within financial or technology environments. Strong expertise in security frameworks, risk management, data analytics, and regulatory compliance is required.

Full description

Business Function 

Group Technology enables and empowers the bank with an efficient, nimble, and resilient infrastructure through a strategic focus on productivity, quality & control, technology, people capability and innovation. In Group Technology, we manage most the Bank's operational processes and inspire to delight our business partners through our multiple banking delivery channels. 

 

About the role 

DBS operates a 3 Lines of Defence model for cybersecurity risk management. This role serves as Line 1, with responsibilities for driving regulatory compliance and governance, awareness and training and data protection for cybersecurity within the bank.  

 

Cybersecurity Governance, Risk and Compliance 

As the 1st Line of Defence, the incumbent is responsible for driving the Bank’s compliance with the relevant cybersecurity legislation (e.g. Singapore’s Cybersecurity Act) and regulations (e.g. MAS).

The responsibilities include: 

  • Development of cybersecurity standards and guidelines, 
  • Assessment and validation of cyber risks and controls applic , and 
  • Reporting and providing assurance for the cybersecurity program to DBS risk committees.  

 

The candidate will work with key stakeholders to implement controls and practices to manage the cyber risks and ensure the identified risks and gaps are adequately addressed and remediated. The candidate is also responsible for providing oversight and governance over cybersecurity related activities and update management on the metrics and compliance posture of the cybersecurity environment. 

 

Cybersecurity Awareness and Training 

The candidate is responsible for the development and delivery of the cybersecurity awareness and training program for the stakeholders within the Bank, including the design and development of targeted content to meet the training needs for the different roles in the Bank. The candidate is to continuously assess the efficacy of the training program, and improve and update the training content. 

 

Data Protection Management 

The incumbent will be responsible for the driving the data protection program including data loss management within the Bank. This includes the design of the data protection control environment, implementation and operations of the data protection technologies, and driving the data protection operations. The role also requires the candidate to drive the inhouse data analytics program to prioritize data loss events and identify potential misuse of the Bank’s applications and customer data. This role will be required to work closely with key stakeholders including the Enterprise Data Security and Data & AI Risk team. 

 

Cybersecurity Governance, Risk and Compliance Responsibilities 

  • Legislation, regulations and policies 
  • Review and assess the Bank’s cybersecurity policy architecture for compliance with new and emerging cyber security legislation, regulations and policies.  
  • Review and update information security standards to comply with the regulatory requirements as required 
  • Work with regional information security services teams in the core markets to monitor new cybersecurity legislation and/ or regulation, and assess the impact to and the compliance of the Bank’s security policy architecture 
  • Where necessary, work with Line of Business Technology units to drive change management to comply with the regulatory guidelines 
  • Security risk and compliance 
  • Work with key Line of Business Technology to manage material changes to critical systems, conduct risk control self assessment to assess key cybersecurity controls and risk areas and ensure continuous compliance with the cybersecurity legislation and regulations  
  • Engage Line of Business Technology units to conduct annual cybersecurity risk assessment for key bank systems as required under the prevailing regulations  
  • Engage external auditors and certification bodies to assess and audit key bank systems and control environment under the Cyber Trust Mark, ISO27000, SOC2 and Cybersecurity Act 
  • Focal point for international centres on information security matters  
  • Security metrics 
  • Develop and maintain a set of security metrics and visualization for the reporting of cybersecurity landscape to senior management and the Board 
  • Where possible, automate the extraction, transformation and loading of raw security events to generate the security metrics and graphs for the reporting 
  • Establish a framework to organize, manage and archive the security data used for the generation of security metrics and visualization 
  • Generate quarterly reports and insights to apprise senior management of the security trends and areas of concern 

Cybersecurity Awareness and Training 

  • Conduct regular phishing exercises and disseminate timely cybersecurity content to inculcate the cybersecurity hygiene and practices   
  • Develop targeted training content and collaborate with various control functions to deliver the content to meet the training needs for specific stakeholders 
  • Drive annual cybersecurity awareness campaign to promote cybersecurity culture and behavior  

Data Protection Management 

  • Data Loss Prevention 
  • Design and implement data protection controls to mitigate the risk of data loss across various channels including web, email, network, endpoint etc. 
  • Work with Line of Business Technology to design and implement technology enablers to support the secure handling of Bank’s and customers’ data 
  • Review and investigate data loss events and refer substantiated events to HR for disciplinary actions 
  • Continuously review and enhance the data protection controls to improve the efficacy of data loss prevention 
  • Provide management reporting on data loss matters to the Bank’s risk committees. 
  • Unusual Employee Behavior Monitoring 
  • Drive the implementation of data analytics and machine learning techniques to • Prioritize and highlight data loss events for review and investigation
  • Identify suspicious activities and misuse of applications and customer data 
  • Oversee the inhouse development of the machine learning models and investigation platform 
  • Drive the development and implementation of data visualization techniques to improve the efficiency of the review and investigation process 
  • Drive the development and enhancement of the investigation platform to meet the users’ need 

Requirements 

  • Information security professional with 15 or more years of experience, with a background in a financial or technology environment. 
  • Experience in implementing a program the collation, management and reporting of security metrics such as open security vulnerabilities, penetration testing findings, security alerts and incidents, etc. 
  • Experienced in information security framework including ISO27000, NIST800-53 and regulations such as Cybersecurity Act, Technology Risk Management Guidelines and Personal Data Protection Act. 
  • Good working knowledge of enterprise security risk management methods and techniques to successfully deliver the security risk management and assessment outcome. 
  • Strong background on security technology solutions including IDS, IPS, anti-virus, content filtering, secure email solutions, network sniffing, log analysis, forensics and VPN 
  • Hands-on technical experience in the management of security data for the generation of security metrics and visualization 
  • Good working knowledge of data analytics, machine learning techniques and software development lifecycle 
  • Good verbal and written communication for the generation of security awareness content 
  • Proactive, analytical and independent worker with strong organization skills and performance-oriented, demonstrate effectiveness to track and follow up on the assigned projects 
  • Regional experience is a plus and the ability to travel on need-to basis 

Location:

DBS Asia Hub

Job:

Technology

Schedule:

Regular

Employee Status:

Full time

Similar roles