AVP, IT Security

Hong Leong Finance Limited

Singapore

On-site

SGD 120,000 - 180,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Hong Leong Finance Limited is seeking a senior IT security professional to drive secure-by-design architecture reviews within MAS TRM guidelines. You will lead governance, risk, and compliance activities across projects, cloud services, and third-party integrations.

You will promote secure design principles, conduct practical training, and engage stakeholders to mitigate technology risks while maintaining regulatory alignment.

Qualifications

  • Bachelor’s degree in Computer Science, Information Security, or related field.
  • 7+ years of experience in cybersecurity roles (security architecture, or GRC).
  • Strong knowledge of security frameworks (ISO 27001, NIST, CIS).
  • Hands-on experience with vulnerability management and compliance monitoring platforms.
  • Familiarity with MAS requirements and secure-by-design principles.
  • Excellent analytical and problem-solving skills.
  • Relevant certifications (e.g., CISSP, CISM, CISA) are a plus.
  • Strong communication and collaboration skills.
  • Proactive mindset with attention to detail.

Responsibilities

  • Governance framework management aligned with MAS TRM guidelines.
  • Lead secure-by-design assessments for new systems and cloud services; identify risks and remediation.
  • Perform MAS TRM reviews for architectures and initiatives.
  • Develop and update security policies, standards, checklists, and guidelines.
  • Manage third-party risk with vendor security assessments.
  • Promote secure design and conduct training; track KRIs and prepare GRC reports.
  • Act as trusted security advisor to teams with timely guidance.

Skills

Security architecture
GRC
Vulnerability management

Education

Bachelor’s degree in Computer Science or related

Tools

Vulnerability management platforms
Compliance monitoring platforms

Job description

The role will be responsible for driving secure-by-design assessments and MAS Technology Risk Management Guidelines reviews across system architectures, technology projects, applications, and infrastructure changes. As part of the IT Security team, the role will provide cyber assurance by assessing architecture designs, identifying security and regulatory gaps early in the technology lifecycle, and ensuring appropriate controls are embedded before implementation. You will act as a trusted advisor to IT project, infrastructure and application teams, promoting secure design principles, MAS TRM alignment, and practical risk mitigation across the organization.

The key responsibilities of the role include:

1. Governance Framework Management

Develop and maintain cybersecurity governance framework aligned with MAS Technology Risk Management Guidelines, with emphasis on translating regulatory expectations into practical architecture review criteria, secure design standards, and control requirements.

Lead secure-by-design assessments for new systems, major enhancements, infrastructure changes, cloud services, APIs, and third-party technology integrations; identify architecture risks, control gaps, and remediation actions before production implementation.

3. Regulatory & Compliance Management

Perform MAS TRM Guidelines reviews for system architectures and technology initiatives, ensuring compliance with regulatory expectations for technology risk governance, security controls, resilience, access management, data protection, and third-party dependencies.

4. Security Policy & Standards Development

Develop and update security policies, standards, architecture review checklists, and secure design guidelines; drive awareness and adoption across IT and business project teams.

5. Third-Party Risk Management

Manage vendor security assessments and review third-party solution architectures to ensure security, resilience, data protection, and MAS TRM-related requirements are adequately addressed.

6. Security Awareness & Training

Promote a secure-by-design culture and conduct practical training for IT teams on architecture risk assessment, MAS TRM considerations, and early security engagement in project delivery.

Track KRIs and security KPIs and prepare GRC reports for management updates.

Support incident response and maintain documentation for audit purposes.

9. Stakeholder Engagement

Act as a trusted security advisor to project, application, infrastructure, and architecture teams by providing timely guidance on secure design, regulatory alignment, and pragmatic risk mitigation options.

Qualifications & Skills:
  • Bachelor’s degree in Computer Science, Information Security, or related field.
  • 7+ years of experience in cybersecurity roles (security architecture, or GRC).
  • Strong knowledge of security frameworks (ISO 27001, NIST, CIS).
  • Hands‑on experience with vulnerability management and compliance monitoring platforms.
  • Familiarity with MAS requirements and secure‑by‑design principles.
  • Excellent analytical and problem-solving skills.
  • Relevant certifications (e.g., CISSP, CISM, CISA) are a plus.
  • Strong communication and collaboration skills.
  • Proactive mindset with attention to detail.

The successful candidate can expect a competitive package that includes an attractive basic salary, annual bonus and variable bonus.

(We regret that only shortlisted candidates will be notified)

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Technology Risk and Cyber Security Governance Senior Officer
Information Technology Risk and Cyber Security Governance Senior Officer

JAC Recruitment Pte Ltd • Singapore

Hybrid
SGD 90,000 - 140,000
Information Technology Risk and Cyber Security Governance Senior Officer
Information Technology Risk and Cyber Security Governance Senior Officer

JAC Recruitment • Singapore

Hybrid
SGD 120,000 - 180,000
Technology Risk & Regulatory Compliance Lead
Technology Risk & Regulatory Compliance Lead

TECSTATION PTE. LTD. • Singapore

On-site
SGD 120,000 - 170,000
IT Risk and Cyber Security Governance Senior Officer
IT Risk and Cyber Security Governance Senior Officer

jac recruitment pte. ltd. • Singapore

On-site
SGD 120,000 - 180,000
IT Governance & Cybersecurity Lead
IT Governance & Cybersecurity Lead

MICHAEL PAGE (PERSONNEL) PTE. LTD. • Singapore

On-site
SGD 150,000 - 210,000
Standalone leadership role
Exposure to cross-border regulatory环境
Competitive remuneration package
Executive / Senior Executive, Technology Risk Management
Executive / Senior Executive, Technology Risk Management

Maybank Singapore • Singapore

On-site
SGD 90,000 - 130,000
GRC Application Security Specialist (Contract)
GRC Application Security Specialist (Contract)

Monetary Authority of Singapore (MAS) • Singapore

On-site
SGD 120,000 - 170,000
Senior IT Security Architect – MAS TRM & Secure Design
Senior IT Security Architect – MAS TRM & Secure Design

Hong Leong Finance Limited • Singapore

On-site
SGD 120,000 - 180,000
Cyber Emerging Threats Analyst
Cyber Emerging Threats Analyst

Maybank Singapore • Singapore

On-site
SGD 90,000 - 130,000
Banking: IT Governance Risk/Cyber Security (Assistant Manager/Senior Officer)
Banking: IT Governance Risk/Cyber Security (Assistant Manager/Senior Officer)

the resolute hunter pte. ltd. • Singapore

On-site
SGD 60,000 - 90,000