Role Title: AI, Governance & Incident Management Lead - Tech Security Operations
Department: Technology
Type: Permanent
Job Summary
We're hiring a multi-disciplinary cybersecurity professional to own security operations, incident management, GRC, and AI-driven automation across our APAC insurance markets — running penetration tests, coordinating incident response with the global CSOC, bridging APAC threat intelligence, leading local regulatory procedures, and building AI/automation solutions that scale security operations regionally. You'll work with market CISOs and global policy owners to translate global standards into procedures that satisfy local regulators while staying enterprise-aligned, using AI and automation to reduce manual effort and speed detection and response.
Markets & Regulators: Singapore (MAS), Hong Kong (HKIA), Australia (APRA), Malaysia (BNM), China (NFRA), India (IRDAI)
Job Responsibilities
- Penetration Testing & Offensive Security — Plan and execute pen tests across web/API, mobile, cloud, and network environments; run purple team exercises with the CSOC; document findings with remediation guidance and verify fixes; manage external pen-test vendors, including regulator-mandated testing (APRA CPS 234, MAS TRM); explore AI-assisted tools for vulnerability discovery and attack path analysis.
- Incident Response & Coordination — Act as APAC's regional incident coordinator through triage, containment, eradication, and recovery; drive incident bridges and post-incident reports; maintain IR runbooks reflecting each regulator's notification timelines (MAS 1-hour, APRA CPS 234, HKIA, BNM, NFRA, IRDAI); partner with Legal, Compliance, and Privacy on regulatory submissions; maintain a full incident evidence trail and use AI-powered triage/correlation to reduce MTTR.
- Threat Intelligence & CSOC Liaison — Serve as the two-way link between APAC markets and the global CSOC/threat intel teams; curate and share region-specific threat intelligence; escal…?
- AI & Security Automation — Design and implement AI/automation use cases using SOAR platforms, Python/PowerShell, and low-code tools (Power Automate, Logic Apps); build AI/ML solutions for threat detection, anomaly identification, alert enrichment, and predictive risk scoring; integrate LLMs/GenAI for report generation, drafting assistance, and natural-language querying; automate log analysis, alert triage, phishing analysis, vulnerability correlation, and compliance monitoring/evidence collection; build CISO dashboards and AI-driven user behaviour analytics; ensure all deployments meet AI governance requirements (e.g., MAS FEAT) with documented models and drift/bias monitoring.
- Governance, Risk & Compliance — Develop and version‑control local procedures/SOPs per market against global policy baselines; perform gap analyses and maintain a traceability matrix to policies and regulatory clauses; track and interpret requirements from MAS, HKIA, APRA, BNM, NFRA, and IRDAI via a per‑market regulatory obligations register; drive closure of audit/regulatory findings through to evidence and sign‑off; coordinate regulatory inquiries, audits, and incident notifications, keeping programs continuously audit‑ready.
- Stakeholder Engagement & Reporting —