Technology Information Security Officer

ESPIRE INFOLABS (SINGAPORE) PTE. LTD.

Singapore

On-site

SGD 120,000 - 180,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

ESPIRE INFOLABS (SINGAPORE) PTE. LTD. invites a seasoned Technical Information Security Officer to join as a pivotal individual contributor, shaping security resilience across the organization and its subsidiaries.

You will embed secure by design/default principles and partner with development teams to weave security into every SDLC phase. The role demands extensive expertise in information security controls, risk management, regulatory frameworks, and scalable cloud security across AWS/Azure,

Qualifications

  • 7+ years in information security, audit, or risk roles in regulated industries.
  • Strong knowledge of security controls across authentication, access, encryption, network, app security, and key management.
  • Familiarity with SDLC, DevSecOps, and secure design principles.

Responsibilities

  • Conduct technical security assessments and provide strategic recommendations.
  • Perform risk assessments across the development lifecycle (SDLC/Agile/Iterative).
  • Lead and mentor teams to drive security initiatives and best practices.
  • Collaborate with architects, project managers, and stakeholders to ensure alignment with regulatory requirements.

Skills

Information security
Audit & risk management
SDLC/DevSecOps
Regulatory compliance
Cloud security

Education

Bachelor's or higher in Information Security/CS/Engineering

Tools

AWS
Azure

Job description

Key Appointments
  • The Technical Information Security Officer (TISO) role is crucial to our security resilience. This SME individual contributor position is the backbone of our Technical Information Security functions, ensuring that robust security measures are not just implemented but ingrained within client and its subsidiaries.
  • The TISO ensures secure by design, secure by default, and secure operations principles are integrated into critical decisions. The TISO partners with development and project teams to embed security into every phase of the Software Development Life Cycle (SDLC) and foster a culture of shared security responsibility.
Key Responsibilities
  1. 1) Oversights in Technical Assessments and Recommendations
    1. a) Conduct meticulous and comprehensive technical assessments of security controls, leaving no stone unturned in identifying critical gaps and providing strategic recommendations.
    2. b) Perform technical information security risk assessments on business applications throughout the development lifecycle, including SDLC, Agile, and Iterative methodologies.
    3. c) Identify and report significant information security issues and gaps, providing technical-level recommendations for risk mitigation.
  2. 2) Act as the Subject Matter Expertise in Application Development Lifecycle:
    1. a) Provides expert advice in assessing security requirements and controls throughout the application development lifecycle.
    2. b) Ensure strategic planning and implementation of security controls to enhance development lifecycle security.
  3. 3) Driving Strategic Improvements in Information Security:
    1. a) Drive improvement initiatives to enhance information security processes, standards, and policies.
    2. b) Advocate for the promotion of information security best practices, ensuring alignment with relevant regulations and frameworks.
  4. 4) Strategic Stakeholder Engagement and Collaboration
    1. a) Collaborate with domain architects, project managers, and IT subject matter experts to foster a collective security culture.
    2. b) Raise awareness of the organization's information security policies, standards, and best practices among stakeholders.
    3. c) Interface with Risk, Internal Audit, External Audit, and regulatory bodies during audits to provide support and facilitate smooth audit processes.
    4. d) Ensure stakeholders understand their strategic roles and responsibilities concerning information security, fostering a culture of accountability.
Key Decisions within the Role
  • Approve security reviews for all relevant projects and operational requirements.
  • Provide independent assessment and advisory on all information security matters, both technical and process-related, serving as a knowledgeable reference source for security matters within the organisation.
Requirements
  1. 1) Experience
    1. a. Minimum of 7+ years of progressive experience in Information Security, Audit, or Risk Management roles, with significant exposure in financial services or similarly regulated industries.
    2. b. Good command of Information Security control areas including Authentication/Authorization, Access Controls, Entitlement, Cryptography, Encryption, Network, Application/System Security, and Key Management. In-depth knowledge of Vulnerability Management frameworks(OWASP, SANS) is essential.
    3. c. Proficiency in SDLC, Agile/Iterative, DevOps/DevSecOps methodologies, and their integration with comprehensive security assessments.
    4. d. Demonstrated understanding and application of the Singapore regulatory framework, local laws concerning information security, technology risk, and data protection (e.g., MAS TRM, PDPCPDPA).
    5. e. Strong familiarity with global standards such as ISO-27001, NIST CSF, MITRE ATT&CK, and their practical application.
    6. f. Expertise in API Security and Cloud Security architectures, particularly in AWS or Azure environments.
    7. g. Exceptional written and verbal communication skills, with a proven ability to influence and negotiate effectively. Keen attention to detail with strong problem-solving and analytical abilities.
    8. h. Demonstrated capability to lead and mentor teams, with a track record of driving strategic initiatives independently.
  2. 2) Education
    1. a. University degree in Information Security, Computer Science, Engineering, or a related field. Advanced degrees and relevant certifications are preferred.
  3. 3) Certification
    1. a. Relevant Information Security Industry qualifications / certifications such as CISSP, CISM, CISA, relevant SANS certifications, Cloud certifications (AWS/Azure), or equivalent industry-recognized qualifications are mandatory.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SL2705 - Security Engineer
SL2705 - Security Engineer

FPT Asia Pacific • Singapore

On-site
SGD 150,000 - 230,000
IT Security Officer - JN
IT Security Officer - JN

DCI CONSULTANTS PRIVATE LIMITED • Singapore

On-site
SGD 120,000 - 170,000
IT Security Officer (ITSO)
IT Security Officer (ITSO)

CAPGEMINI SINGAPORE PTE. LTD. • Singapore

On-site
SGD 90,000 - 130,000
IT Security Officer - #1617
IT Security Officer - #1617

JOBSTER PRIVATE LTD. • Singapore

On-site
SGD 70,000 - 120,000
IT Security Consultant
IT Security Consultant

DADACONSULTANTS PTE. LTD. • Singapore

On-site
SGD 90,000 - 150,000
IT Security Officer (ITSO)
IT Security Officer (ITSO)

Cognizant • Singapore

On-site
SGD 120,000 - 180,000
Cybersecurity Consultant, CISOaas
Cybersecurity Consultant, CISOaas

Ensign InfoSecurity • Singapore

On-site
SGD 70,000 - 110,000
IT Security Consultant - #1655
IT Security Consultant - #1655

JOBSTER PRIVATE LTD. • Singapore

On-site
SGD 120,000 - 180,000
IT Security Manager (Public Sector)
IT Security Manager (Public Sector)

NEWTONE CONSULTING PTE. LTD. • Singapore

On-site
SGD 90,000 - 130,000
IT Security Officer
IT Security Officer

Base Camp Digital • Singapore

On-site
SGD 90,000 - 130,000