VP, Information Security (Data & Application) Singapore, Singapore, Singapore Permanent - Full Time
Job Description
Singlife is a leading homegrown financial servicescompany, offering consumers a better way to financial freedom. Throughinnovative, technology-enabled solutions and a wide range of products andservices, Singlife provides consumers coantrol over their financial wellbeingat every stage of their lives.
In addition to a comprehensive suite of insurance plans,employee benefits, partnerships with financial adviser channels andbancassurance, Singlife offers investment and advisory solutions through itsGROW with Singlife platform. It also offers the Singlife Account, amobile-first insurance savings plan.
Singlife is the exclusive insurance provider for theMinistry of Defence, Ministry of Home Affairs and Public Officers GroupInsurance Scheme. Singlife is also an official signatory of the United NationsPrinciples for Sustainable Insurance and the United Nations-supportedPrinciples for Responsible Investment, affirming its commitment to finding abetter way to sustainability.
The merger of Aviva Singapore and Singlife was announcedin September 2020 and created one of the largest homegrown financial servicescompanies in Singapore in a deal valued at S$3.2 billion. It was the largestinsurance deal in Singapore at the time. Singlife was subsequently acquired bySumitomo Life in March 2024, one of Japan’s leading life insurers, which valuedSinglife at S$4.6 billion, making the transaction one of the largest insurancedeals in Southeast Asia.
Key Responsibilities
Data Security
- Design and oversee data security controlsincluding encryption, key management, data loss prevention (DLP), dataclassification, and access governance to protect sensitive and customer dataacross on-premises and cloud environments.
- Conduct meticulous and comprehensive technicalassessments of data security controls, leaving no stone unturned in identifyingcritical gaps and providing strategic, risk-based remediation recommendations.
- Identify and report significant data securityissues and gaps, providing technical-level recommendations for risk mitigationaligned to regulatory expectations such as MAS TRM and PDPA.
Application Security
- Act as the subject matter expert across theapplication development lifecycle, performing technical information securityrisk assessments on business applications throughout SDLC, Agile, and DevSecOpsmethodologies.
- Provide expert advice in assessing securityrequirements and controls—including secure coding, API security, andvulnerability management—and drive strategic planning and implementation ofcontrols to strengthen application development lifecycle security.
Security Architecture
- Develop and maintain security referencearchitectures and design patterns—informed by industry frameworks such as SABSAand TOGAF—to data, application, network, and cloud domains, driving consistentadoption as enterprise standards and reusable building blocks.
- Conduct security architecture reviews acrossenterprise-wide projects, identifying design gaps and driving recommendationsto close them, while advocating for security best practices in alignment withrelevant regulations and frameworks (e.g., MAS TRM, ISO 27001, NIST CSF).
- Provide independent, expert assessment andadvisory on all data security, application security, and security architecturematters—serving as the trusted technical reference point for these domainswithin the organisation.
Strategic Stakeholder Engagement and Collaboration
- Collaborate with domain architects, projectmanagers, and IT subject matter experts to foster a collective securityculture.
- Raise awareness of the organization'sinformation security policies, standards, and best practices amongstakeholders.
- Interface with Risk, Internal Audit, ExternalAudit, and regulatory bodies during audits to provide support and facilitatesmooth audit processes.
- Ensure stakeholders understand their strategicroles and responsibilities concerning information security, fostering a cultureof accountability.
Experience
- Minimum of 6 years of progressive experience inInformation Security, with a strong focus on data security, applicationsecurity, and security architecture. Experience in financial services orsimilarly regulated industries is preferred.
- Strong command of data and application securitycontrols—encryption, key management, DLP, access management, and vulnerabilitymanagement (OWASP, SANS).
- Hands-on experience embedding security intoSDLC, Agile, and DevSecOps pipelines, with expertise in API and cloud security(AWS/Azure).
- Working knowledge of security architecture andregulatory frameworks—SABSA, TOGAF, ISO 27001, NIST CSF, MITRE ATT&CK, MASTRM, and PDPA.
- Strong communication and stakeholder influenceskills, with a track record of driving initiatives independently as a seniorSME.
Education
- University degree in Information Security,Computer Science, Engineering, or a related field. Advanced degrees andrelevant certifications are preferred.
- Relevant Information Security Industryqualifications / certifications such as CISSP, CISM, CISA, relevant SANScertifications, Cloud certifications (AWS/Azure), or equivalentindustry-recognized qualifications are mandatory.