About The Role
We are seeking an experienced senior manager to lead our information security team, combining strong hands-on technical expertise as well as people management experience in the information security domain. They will lead a team to manage Security Operations (SecOps), encompassing threat detection and response, incident management, vulnerability management, security monitoring, and continuous improvement of defensive capabilities.
What You’ll Be Doing
- Infrastructure Security: Manage end-to-end infrastructure security activities, such as vulnerability management, servers’ security monitoring & hardening, infrastructure as code, etc. Design and/or review infrastructure security architecture proposals for various security-driven initiatives for on-premises and cloud environments.
- Cloud Security: Manage compliance level of AIA SG cloud security assets based on ongoing regular scanning according to defined thresholds. Evaluate the security aspect of new cloud-based solutions proposed by application development, infrastructure, or business teams. Manage cloud security BAU activities, such as asset provisioning, deprovisioning, and hardening.
- Identity and Access Management: Supervise the AIA-SG IAM Manager and their team performing IAM Governance functions for the Business Unit.
- Cyber Security & Security Incident Handling: Work with the Security Operations Centre (SOC) Team to ensure secure protection of the AIA SG environment. Deploy new cyber security initiatives and roll out the platform with the SOC Team. Serve as the point of contact for security incident handling and investigation from identification through resolution.
- Security Advisory: Provide feasible security recommendations or guidance based on queries or changes initiated by application development, infrastructure, or business teams. Facilitate challenging security conversations and provide acceptable solutions where IT standards may conflict with business demands while maintaining security and compliance.
- People Development: Supervise 8 team members. Drive a continuous Learning and Development program for the team through in-house and external training. Promote activities to increase information security awareness within the teams to embed and continuously improve adherence to best practices.
What We Are Looking For
- University degree in Computer Science, Computer Engineering, Information Security, Information Systems, or related disciplines.
- Minimum 15 years of experience in information security, specifically in Application Security, Infrastructure Security, and Cloud Security.
- Preferably a security infrastructure operation background with hands-on experience designing and/or reviewing application security or infrastructure security.
- Hands-on information security experience in multiple cloud environments (SaaS, PaaS, IaaS) and cyber incident management.
- Security architecture or cloud security certifications are preferable (e.g., CCSP, Azure DevOps certification, Azure Solutions Architect certification).
- Having one or more information security and audit qualifications such as CISSP, CISA, CRISC, CCSP is preferred.
- Strong knowledge of current security technologies and cyber landscape in a regulated industry.
- Good interpersonal and communication skills. Strong leadership with integrity, proactive mindset, and ownership.
- Working experience in insurance, banking, or IT industries is preferred.
- Infrastructure Security: Windows, Linux, AS400.
- Security Advisory, Assessment, and incident management.
Build a career with us as we help our customers and the community live Healthier, Longer, Better Lives.