Stand out for this role — generate a tailored resume and cover letter in about a minute.
SBS Transit Limited is seeking a seasoned cybersecurity leader to head its cybersecurity operations for IT and OT environments. You will manage incident response, threat detection, and security tooling while coordinating with internal and external stakeholders to strengthen cyber resilience.
Key responsibilities include developing and enforcing cybersecurity policies, ensuring regulatory compliance (CCoP, ISO27001, NIST), and guiding continuous improvement through exercises and audits.
Lead the cybersecurity operations function to proactively defend SBST IT and OT environments against cyber threats, manage cyber incidents and security technologies, ensure regulatory compliance, and drive continuous improvement of cyber resilience.
Lead, manage and work with team members on the following:
Involve in sector-wide cybersecurity programme and engagement.
Coordinate and contribute to various external and internal forums and meetings.
Manage, administrate and provide all cybersecurity operations, services (e.g. VAPT) and tools management.
Manage EDR/XDR (Endpoint Detection and Response/Extended
Detection and Response) tools and respond to incidents with the support of various SOC teams.
Identify cyber security threats to systems, detect security anomalous activities and perform analysis of security logs from multiple sources.
Identify emerging threats and vulnerabilities and recommend appropriate advisories, controls and solutions for implementation to enhance cybersecurity posture.
Formulate cybersecurity policies, procedures and documentation for IT and OT systems, ensuring compliance with regulatory requirements and industry best practices (e.g. Cybersecurity Code of Practice (CCoP 2.0), CP8, ISO27001 etc.).
Work closely with internal and external stakeholders regularly to draft and enhance cybersecurity incident response plans and playbooks to achieve cybersecurity readiness.
Responsible for the handing of cyber incident and crisis in accordance with procedures, which include triage and handling of all cybersecurity alerts and incidents across IT & OT environments.
Perform security analysis on cloud platforms such as AWS, Azure as well M365 services.
Support in regulatory and sectorial audits as and when necessary.
Involve in the planning, conducting and exercising of TTXs (tabletop exercises), penetration tests and other cybersecurity (e.g. red/purple/blue teaming) exercises as and when necessary.
Oversee the development, testing, and maintenance of cybersecurity measures to safeguard both IT and OT Critical Information Infrastructure (CII) assets.
Evaluate, manage and liaison with cybersecurity vendors to ensure fulfilment of cybersecurity services.
Plan and implement budgeted cybersecurity projects based on business requirements.
Min. Degree in Computer Engineering or equivalent.
Trained in Cybersecurity, Information Security, Forensics or equivalent
Min. 15-25 years of direct and relevant full-time cybersecurity work experience in policy formulation, incident response, and management, regulatory oversight and compliane
CISSP/CISM/CISA/CEH/CRISC or equivalent certification
Strong domain knowledge of multiple cybersecurity practices (Email security solutions, vulnerability management, penetration testing, network security (firewall, IPS/IDS, SIEM, threat intelligence, etc.) and industry IT/OT and cybersecurity best practices.
Experience in Threat detection, Penetration testing and red/purple teaming
Knowledge in ISO27001 and IEC62443, NIST Cybersecurity Framework, CSA Code of Practice (CCoP).
Knowledge in Network, Web Security and Application Security would be highly valued.
Experience with information security tools (SIEM, anti-virus tools etc.).
Experience in forensics and incident management.
Strong leadership qualities & ability to work under pressure.
Self-motivated, a good team player and strong ability to multi-task.
Excellent verbal, written communication, presentation and analytical skills.
Ability to build strong and trusting relationships
Experience working in public transport and/or OT industry would be highly valued.