Cyber Risk & Operations Manager

FengHe Fund Management Pte Ltd

Singapore

On-site

SGD 180,000 - 260,000

Full time

10 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

FengHe Fund Management Pte Ltd in Singapore seeks a senior cyber security and technology risk leader to oversee outsourced IT security and risk performance. You will define security requirements, monitor provider deliverables, and manage incidents with senior stakeholders.

You will lead risk frameworks, maintain policies, and drive awareness programs while ensuring continuity and strong governance across the firm’s IT environment.

Qualifications

  • 7+ years in cyber security, technology risk, or IT governance.
  • Financial services background strongly preferred (hedge fund, asset manager, fund administrator, or investment bank).
  • Familiarity with outsourced managed-IT model common among hedge funds is a significant advantage.

Responsibilities

  • Act as the firm's primary point of accountability for the outsourced IT provider's security and risk performance.
  • Define, negotiate, and enforce SLAs, security requirements, and reporting obligations; review the outsourced IT provider's deliverables, reports, and evidence with a critical eye.
  • Run structured service and risk review meetings with the outsourced IT provider; track open issues, remediation items, and commitments to closure.
  • Independently validate the outsourced IT provider's work where warranted (e.g., third-party penetration tests, vulnerability review, access reviews, patching and configuration practices).
  • Review assurance materials (SOC 2 reports, certifications, subcontractor arrangements) and assess residual risk.
  • Ensure the firm retains knowledge, documentation, and exit options to avoid unhealthy dependency on any single provider.
  • Own the firm's cyber and IT risk framework: risk register, risk assessments, KRIs, risk appetite reporting.
  • Maintain information security policies and ensure provider operations comply with them.
  • Report to senior management on cyber risk posture, provider performance, and threats.
  • Own incident response plan and lead responses to cyber incidents; coordinate communications.
  • Lead tabletop exercises with firm and provider; drive lessons learned into improvements.
  • Ensure business continuity and disaster recovery arrangements meet objectives and are tested.
  • Run the security awareness program, including phishing simulations and training.

Skills

Judgment
Communication
Attention to detail
Composure under pressure
Vendor management
Integrity & discretion

Job description

We are a leading Asian investment firm with approximately USD 13 billion in assets under management across our funds.

Our flagship FengHe Asia Fund is recognised as one of the most consistent and best-performing long-short equity funds in Asia.

For more information, please visit www.fengheasia.com.

Role & Responsibilities
Managed Services Provider Oversight
  • Act as the firm's primary point of accountability for the outsourced IT provider's security and risk performance
  • Define, negotiate, and enforce SLAs, security requirements, and reporting obligations; review the outsourced IT provider's deliverables, reports, and evidence with a critical eye rather than accepting them at face value
  • Run structured service and risk review meetings with the outsourced IT provider; track open issues, remediation items, and commitments to closure
  • Independently validate the outsourced IT provider's work where warranted. E.g., commissioning third-party penetration tests, reviewing vulnerability scan results, sampling access reviews, and challenging patching and configuration practices
  • Review the outsourced IT provider's assurance materials (SOC 2 reports, certifications, subcontractor arrangements) and assess residual risk to the firm
  • Ensure the firm retains adequate knowledge, documentation, and exit options to avoid unhealthy dependency on any single provider
  • Own the firm's cyber and IT risk framework: risk register, risk assessments, key risk indicators, and risk appetite reporting
  • Maintain the firm's information security policies and ensure the outsourced IT provider's operations comply with them
  • Report regularly to senior management (and the board/investors as required) on the firm's cyber risk posture, outsourced IT provider performance, and emerging threats
Incident Leadership
  • Own the firm's incident response plan; ensure the outsourced IT provider's incident processes integrate well with it
  • Lead the firm's response to any cyber incident. Direct and coordinate the outsourced IT provider, brief executives in real time, manage legal/regulatory/insurer notifications, and own investor and counterparty communications
  • Run tabletop exercises involving both the firm and the outsourced IT provider at least annually; drive lessons learned into concrete improvements
Resilience & Awareness
  • Ensure business continuity and disaster recovery arrangements delivered through the provider meet the firm's recovery objectives and are validated through regular testing
  • Run the firm's security awareness program, including phishing simulations and targeted training for high-risk functions
Job Requirements
  • 7+ years in cyber security, technology risk, or IT governance, ideally including experience overseeing managed service providers or outsourced IT arrangements
  • Financial services background strongly preferred (hedge fund, asset manager, fund administrator, or investment bank); familiarity with the outsourced managed-IT model common among hedge funds is a significant advantage
  • Strong technical fluency across the domains typically delivered by an outsourced IT provider: cloud infrastructure, identity and access management, EDR/SIEM, vulnerability management, network security, and backup/DR architectures
Skills & Attributes
  • Sophistication and judgment: strong understanding of what effective security assurance looks like, with the ability to hold a large vendor to a high standard
  • Gravitas and communication: credibly represents the firm in front of investors, regulators, boards, and vendor executives; translates technical risk into commercial language
  • Exceptional attention to detail: thorough in reviewing assurance reports, technical evidence, and documentation, with a strong eye for gaps
  • Composure under pressure: leads decisively during incidents in a high-intensity environment
  • Strong vendor management skills: builds a productive, collaborative working relationship with the provider while maintaining clear accountability
  • High integrity and discretion: handles highly sensitive information appropriately
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Risk & Operations Manager
Cyber Risk & Operations Manager

FENGHE FUND MANAGEMENT PTE. LTD. • Singapore

On-site
SGD 120,000 - 200,000
Senior Cyber Risk & MSP Oversight Manager
Senior Cyber Risk & MSP Oversight Manager

FengHe Fund Management Pte Ltd • Singapore

On-site
SGD 180,000 - 260,000
Security Operations Lead – Global Hedge Fund - J13140
Security Operations Lead – Global Hedge Fund - J13140

Pinpoint Consulting Pte Ltd • Singapore

On-site
SGD 180,000 - 280,000
Restaurant d'entreprise
Senior Manager, Cybersecurity Operations
Senior Manager, Cybersecurity Operations

GOLDTECH RESOURCES PTE LTD • Singapore

On-site
SGD 80,000 - 130,000
Cyber Risk & MSP Governance Leader
Cyber Risk & MSP Governance Leader

FENGHE FUND MANAGEMENT PTE. LTD. • Singapore

On-site
SGD 120,000 - 200,000
Cyber Security Specialist
Cyber Security Specialist

LANDI Global • Singapore

On-site
SGD 90,000 - 130,000
VP/SVP -Tech & Cyber Risk Management (listed financial institution)
VP/SVP -Tech & Cyber Risk Management (listed financial institution)

LICO RESOURCES PTE. LTD. • Singapore

On-site
SGD 180,000 - 240,000
GENERAL MANAGER, CYBERSECURITY
GENERAL MANAGER, CYBERSECURITY

Rikvin Capital Pte. Ltd. • Singapore

On-site
SGD 260,000 - 380,000
IT Compliance Manager
IT Compliance Manager

Bank Of China Limited • Singapore

On-site
SGD 120,000 - 180,000
VP/SVP -Tech & Cyber Risk Management (listed financial institution)
VP/SVP -Tech & Cyber Risk Management (listed financial institution)

Lico Resources • Singapore

On-site
SGD 150,000 - 200,000