Information Security Lead

BOND FINANCIAL GROUP PTE. LTD.

Shenton Way

On-site

SGD 180,000 - 280,000

Full time

44 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Bond Financial Group Pte. Ltd. seeks an Information Security Lead to own the policy framework and ISMS, driving ISO 27001:2022 certification and governance across engineering teams.

The role covers IAM design (SSO, MFA, PAM), secure development standards, and security operations oversight. You will lead audits, vendor management, and 24x7 incident response readiness.

Qualifications

  • 10+ years of progressive information security experience, with 3+ years in a lead or management role.
  • Experience designing and implementing ISMS and ISO 27001:2022 certification programs.
  • Experience establishing IAM frameworks (SSO, MFA, PAM) and managing external audits.
  • Proven incident response leadership in production environments.
  • Experience managing MSSPs and penetration testing vendors.

Responsibilities

  • Establish and own information security policy framework and ISMS.
  • Lead ISO 27001:2022 certification and surveillance audits across departments.
  • Design and implement IAM controls (SSO, MFA, PAM) and access reviews.
  • Oversee secure development standards (OWASP) and architecture reviews.
  • Manage security vendors and provide incident response guidance.

Skills

ISMS design
IAM (SSO MFA PAM)
Threat modelling
Security architecture reviews
Email security
Endpoint protection

Education

Bachelor's degree in Information Security / CS
CISSP or CISM preferred

Tools

Okta
Azure AD
CyberArk
BeyondTrust

Job description

The Information Security (InfoSec) Lead is a senior player-manager responsible for establishing and owning the information security policy framework and ISMS. This role leads ISO 27001:2022 certification, governs identity and access management, and ensures security standards are embedded across all engineering teams.

Key Responsibilities
Security Policy and ISMS Ownership
  • Establish and maintain the information security policy framework, ISMS risk register, risk treatment plan, and Statement of Applicability (SoA).
  • Lead the organisation through ISO 27001:2022 certification and ongoing surveillance audits; coordinate all departments on control implementation and evidence.
  • Conduct periodic policy reviews to ensure alignment with regulatory requirements and evolving threat landscapes.
Identity, Access and Secure Development
  • Design and implement IAM controls including SSO, MFA, and PAM; govern user provisioning and access review processes.
  • Define secure development standards (e.g. OWASP); conduct security architecture reviews with the Applications Lead.
  • Configure and maintain email security gateways and endpoint protection platforms.
Security Operations Oversight and Support
  • Provide strategic direction and escalation support to the Senior Security Engineer and SoC team.
  • Review security incident post-mortems and ensure effective remediation.
  • Manage security service providers and vendors, including MSSPs and penetration testing firms.
  • On-call availability is required to support 24x7 incident response coverage.
Requirements
Experience
  • 10+ years of progressive information security experience, with 3+ years in a lead or management role.
  • Demonstrated experience designing and implementing an ISMS and leading ISO 27001:2022 certification programmes.
  • Experience establishing IAM frameworks (SSO, MFA, PAM) and managing external audits and regulatory examinations.
  • Proven experience leading incident response, containment, and post-incident reviews in a production environment.
  • Experience managing MSSPs, penetration testing firms, and security tooling vendors; regulated industry background preferred.
Technical Skills
  • ISMS design and operation: risk register, SoA, control framework, continual improvement
  • IAM platforms: SSO (e.g. Okta, Azure AD or equivalent), MFA, PAM (e.g. CyberArk, BeyondTrust, or equivalent)
  • Secure development frameworks: OWASP, SANS CWE Top 25
  • Security architecture review methodologies and threat modelling
  • Email security gateways and endpoint protection platforms
  • ISO 27001:2022 control framework implementation across all domains
Qualifications
  • Bachelor's degree or higher in Information Security, Computer Science, or a related discipline.
  • CISSP or CISM strongly preferred.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Lead
Information Security Lead

Bond Financial Group • Singapore

On-site
SGD 180,000 - 260,000
Senior Security Engineer
Senior Security Engineer

BOND FINANCIAL GROUP PTE. LTD. • Shenton Way

On-site
SGD 120,000 - 180,000
Senior Security Engineer
Senior Security Engineer

Bond Financial Group • Singapore

On-site
SGD 120,000 - 180,000
IT Security Director
IT Security Director

SEARCHASIA CONSULTING PTE. LTD. • Singapore

On-site
SGD 180,000 - 240,000
Cyber Security Specialist
Cyber Security Specialist

LANDI Global • Singapore

On-site
SGD 90,000 - 130,000
Senior IT Manager (Security)
Senior IT Manager (Security)

TAURUS FIRM PTE. LTD. • Singapore

On-site
SGD 180,000 - 240,000
Information Technology Security Manager
Information Technology Security Manager

Newtone Consulting • Singapore

On-site
SGD 180,000 - 240,000
Director - Cyber Security Architect
Director - Cyber Security Architect

Selby Jennings • Singapore

On-site
SGD 240,000 - 360,000
IT Security Officer
IT Security Officer

PCCW SOLUTIONS INSYS PTE. LTD. • Singapore

On-site
SGD 100,000 - 150,000
Head of Information Security
Head of Information Security

JAC Recruitment Pte Ltd • Singapore

On-site
SGD 250,000 - 360,000