SVP, Exposure Management, Technology Group

GIC Private Limited

Singapore

On-site

SGD 300,000 - 550,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid work arrangement
Office four days per week with work‑at

Job summary

GIC Private Limited in Singapore seeks a Senior Vice President of Exposure Management to fortify the firm’s security posture across infrastructure, cloud, and applications.

You will lead strategy, governance, and cross‑functional collaboration to reduce vulnerabilities and strengthen risk‑based decision making for enterprise resilience.

Qualifications

  • 15+ years in cybersecurity with 7+ years in senior leadership roles.
  • Experience maturing threat exposure management at enterprise scale.
  • Strong understanding of financial services risk & regulatory environments.
  • Proven track record leading large cybersecurity programs.

Responsibilities

  • Define and execute exposure and vulnerability management strategy.
  • Establish a roadmap for continuous threat management and automation.
  • Maintain visibility of the enterprise attack surface across environments.
  • Lead scanning, assessment, and remediation with consistent standards.
  • Drive risk-based prioritization using threat context and business impact.
  • Employ exposure validation techniques to confirm real-world risk.
  • Partner with technology teams to embed best practices and remediation.
  • Collaborate with risk and audit to align with enterprise risk management.
  • Communicate complex exposures to enable risk-based decisions.
  • Develop and manage exposure, vulnerability, and patch standards.
  • Track KRIs and KPIs to measure program maturity and impact.
  • Build and lead a high-performing security team.
  • Drive continuous improvement of processes and tooling.

Skills

Cybersecurity leadership
Exposure management
Vulnerability management
Threat intelligence
Communication & stakeholder mgmt
Regulatory & compliance knowledge
Security program management
Attack surface management
Penetration testing
AI & automation in security

Education

Degree in Computer Science or Information Security

Job description

Select how often (in days) to receive an alert: Create Alert

Location: Singapore, SG

Job Function: Technology Group

Job Type: Permanent

GIC is one of the world’s largest sovereign wealth funds. With over 2,000 employees across 11 locations around the world, we invest in more than 40 countries globally across asset classes and businesses. Working at GIC gives you exposure to an extraordinary network of the world’s industry leaders. As a leading global long-term investor, we Work at the Point of Impact for Singapore’s financial future, and the communities we invest in worldwide.

Technology Group

The Technology Group (TG) is a key enabler to keep our business moving forward and is constantly exploiting state-of-the‑art information technologies to enhance GIC’s ability to be the leading global long‑term investment firm. We aim to provide users with empowering and transformational capabilities, and to create an inclusive, innovative and integrated work environment.

Infrastructure Cybersecurity & Resilience (ICR)

Our mission is to fortify GIC's infrastructure and cybersecurity capabilities by embedding security and resilience into everything we do, providing stable, secure and dependable services and solutions. The individual will be part of the Cybersecurity Assurance & Defence (CSAD) team and will play a key role in strengthening the firm’s security posture through proactive vulnerability management, adversarial attack simulation planning, and continuous improvement of security. The individual will serve as a control owner, driving threat prioritization, root cause analysis, and cross‑team collaboration to remediate and prevent recurrence of vulnerabilities.

What impact can you make in this role?

This role will drive the strategic and operational excellence needed tosafeguard GIC’stechnology ecosystem. By leading efforts toidentify, assess, and remediate vulnerabilities across infrastructure, applications, and cloud environments, the SVP will ensure proactive risk reduction and resilience against evolving cyber threats. The impact of this role will be seen in stronger enterprise‑wide security posture, improved regulatory and compliance alignment, and enhanced confidence among stakeholders that critical assets are protected throughtimely, data‑driven, and coordinated vulnerability management practices.

What will you do as SVP Exposure Management?
  • Define and execute the exposure and vulnerability management strategy, aligned with enterprise risk appetite, regulatory requirements, and business objectives.
  • Establish a forward‑looking roadmap that operationalizes continuous threat management, integrating threat intelligence, security analytics, and automation to strengthen the discovery, prioritization, validation, and remediation of exposures.
  • Maintain continuous visibility of the enterprise attack surface — spanning external, cloud, on‑premises, hybrid, and identity‑based exposures — to move from reactive scanning to proactive exposure reduction.
  • Lead and govern scanning and assessment ensuring consistent standards, accuracy, timely mitigation, and transparent reporting.
  • Drive risk‑based prioritization of vulnerabilities and exposures using threat context, exploitability, attack‑path analysis, and business criticality — focusing remediation effort on what is genuinely exploitable and impactful.
  • Employ exposure validation techniques (e.g., attack path modelling, breach and attack simulation, and penetration testing) to confirm real‑world risk and measure the effectiveness of controls.
  • Partner with technology teams to embed best practices into technology and orchestrate the mobilization and remediation of exposures across accountable owners.
  • Collaborate with risk and audit teams to align technical exposure and vulnerability management with broader risk management practices and act as a key point of contact for audit matters.
  • Communicate complex technical exposures to drive informed, risk‑based decision‑making at all levels of the firm.
  • Develop, update, and manage the firm’s exposure, vulnerability, and security patch management standards.
  • Develop and track performance metrics, key risk indicators (KRIs), and key performance indicators (KPIs) to measure program maturity and impact.
  • Build and lead a high‑performing team.
  • Drive continuous improvement of program processes, tooling, and automation to accelerate mean‑time‑to‑remediate and reduce recurring exposures.
  • Stay abreast of global cybersecurity trends, emerging vulnerabilities, exploits, and regulatory developments.
What qualifications or skills should you possess in this role?
  • 15+ years of experience in cybersecurity, with at least 7 years in senior leadership roles overseeing exposure and vulnerability management operations.
  • Proven experience establishing or maturing a threat exposure management or equivalent risk‑based exposure management program at enterprise scale.
  • Deep understanding of regulatory environments, financial services operations, and technology risk management.
  • Proven track record of leading large‑scale cybersecurity programs.
  • Expertise across the exposure management lifecycle — attack surface management, vulnerability management tools, exposure assessment and prioritization, penetration testing, continuous/automated validation (e.g., breach and attack simulation), threat intelligence, and the use of AI and automation technologies.
  • Strong grasp of risk‑based prioritization, attack‑path analysis, and exposure validation to focus remediation on genuinely exploitable, high‑impact risk.
  • Strong communication and stakeholder management skills, with the ability to influence at various levels of the firm.
  • Degree in Computer Science, Information Security, or related field preferred; relevant certifications (SANS, OFFSEC, CISSP, CISM, CRISC, etc.) desirable.
Work at the Point of Impact

We need to be forward‑looking to attract the right people to help us become the Leading Global Long‑term Investor. Join our ambitious, agile, and diverse teams - be empowered to push boundaries and pursue innovative ideas, share your views, and be heard. Be anchored on our PRIME Values: Prudence, Respect, Integrity, Merit and Excellence, which guides us in how we make our day‑to‑day decisions. We strive to inspire. To make an impact.

Flexibility at GIC

At GIC, our offices are vibrant hubs for ideation, professional growth, and interpersonal connection. At the same time, we believe that flexibility allows us to do our best work and be our best selves. Thus, our teams come into the office four days per week to harness the benefits of in‑person collaboration, but have the flexibility to choose which days they work from home and adjust this arrangement as situational needs arise.

GIC is an equal opportunity employer

As an employer, we passionately believe every individual brings with them unique diversity of thought and perspectives to meaningfully enrich perspectives of GIC teams to drive competitive performance. An inclusive environment yields exceptional contribution.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

VP, Enterprise Cybersecurity Engineering, (Data Security and Protection Engineer), Technology Group
VP, Enterprise Cybersecurity Engineering, (Data Security and Protection Engineer), Technology Group

GIC Private Limited • Singapore

Hybrid
SGD 100,000 - 180,000
Flexible working arrangement
Professional growth opportunities
VP, Enterprise Cybersecurity Engineering, (Cybersecurity Platform Engineer), Technology Group
VP, Enterprise Cybersecurity Engineering, (Cybersecurity Platform Engineer), Technology Group

GIC Private Limited • Singapore

On-site
SGD 180,000 - 240,000
VP, Insider Threat, Cyber Security Assurance & Defense, Technology Group
VP, Insider Threat, Cyber Security Assurance & Defense, Technology Group

GIC Private Limited • Singapore

On-site
SGD 120,000 - 180,000
Flexible working arrangements
Professional development opportunities
Collaborative work environment
VP/SVP, Risk & Controls Officer, Technology Group
VP/SVP, Risk & Controls Officer, Technology Group

GIC Private Limited • Singapore

On-site
SGD 200,000 - 320,000
VP, Insider Threat, Cyber Security Assurance & Defense, Technology Group
VP, Insider Threat, Cyber Security Assurance & Defense, Technology Group

GIC Private Limited • Singapore

Hybrid
SGD 120,000 - 180,000
Flexible work arrangements
Professional growth opportunities
AVP/VP, Red Team Specialist, Cyber Security Assurance & Defence, Technology Group
AVP/VP, Red Team Specialist, Cyber Security Assurance & Defence, Technology Group

GIC Private Limited • Singapore

Hybrid
SGD 180,000 - 240,000
Flexible work arrangement
Equal opportunity employer
Assistant Vice President, Cyber Security Platform Operations, Technology Group
Assistant Vice President, Cyber Security Platform Operations, Technology Group

GIC Private Limited • Singapore

Hybrid
SGD 120,000 - 150,000
SVP, Information & Technology Risk (Infrastructure, Security & Resilience Risk Oversight)
SVP, Information & Technology Risk (Infrastructure, Security & Resilience Risk Oversight)

GIC Private Limited • Singapore

Hybrid
SGD 180,000 - 300,000
VP, Enterprise Cybersecurity Engineering, (Data Security and Protection Engineer), Technology Group
VP, Enterprise Cybersecurity Engineering, (Data Security and Protection Engineer), Technology Group

GIC • Singapore

On-site
SGD 120,000 - 160,000
Flexible work arrangements
Professional development opportunities
VP/SVP, Identity & Access Management (IAM), Technology Group
VP/SVP, Identity & Access Management (IAM), Technology Group

GIC Private Limited • Singapore

Hybrid
SGD 180,000 - 300,000