Live opening · Posted 18 hours ago

ED, Cybersecurity Governance, Risk & Compliance Head, Information Security Services, Group Technology

Dbs · Singapore - East
Workday
JobBeeper subscribers received an alert for this role.

At a glance

The key details from the original listing.

Posted 18 hours ago
CompanyDbs
LocationSingapore - East
SourceWorkday
ListedPosted 18 hours ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
1 min from Workday publishing this role to us finding it
13 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
62,686 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

Business Function
Group Technology enables and empowers the bank with an efficient, nimble, and resilient infrastructure through a strategic focus on productivity, quality & control, technology, people capability and innovation. In Group Technology, we manage most the Bank's operational processes and inspire to delight our business partners through our multiple banking delivery channels.
About the role
DBS operates a 3 Lines of Defence model for cybersecurity risk management. This role serves as Line 1, with responsibilities for driving regulatory compliance and governance, awareness and training and data protection for cybersecurity within the bank.
Cybersecurity Governance, Risk and Compliance
As the 1st Line of Defence, the incumbent is responsible for driving the Bank’s compliance with the relevant cybersecurity legislation (e.g. Singapore’s Cybersecurity Act) and regulations (e.g. MAS).
The responsibilities include:
Development of cybersecurity standards and guidelines,
Assessment and validation of cyber risks and controls applic , and
Reporting and providing assurance for the cybersecurity program to DBS risk committees.
The candidate will work with key stakeholders to implement controls and practices to manage the cyber risks and ensure the identified risks and gaps are adequately addressed and remediated. The candidate is also responsible for providing oversight and governance over cybersecurity related activities and update management on the metrics and compliance posture of the cybersecurity environment.
Cybersecurity Awareness and Training
The candidate is responsible for the development and delivery of the cybersecurity awareness and training program for the stakeholders within the Bank, including the design and development of targeted content to meet the training needs for the different roles in the Bank. The candidate is to continuously assess the efficacy of the training program, and improve and update the training content.
Data Protection Management
The incumbent will be responsible for the driving the data protection program including data loss management within the Bank. This includes the design of the data protection control environment, implementation and operations of the data protection technologies, and driving the data protection operations. The role also requires the candidate to drive the inhouse data analytics program to prioritize data loss events and identify potential misuse of the Bank’s applications and customer data. This role will be required to work closely with key stakeholders including the Enterprise Data Security and Data & AI Risk team.
Cybersecurity Governance, Risk and Compliance Responsibilities
Legislation, regulations and policies
Review and assess the Bank’s cybersecurity policy architecture for compliance with new and emerging cyber security legislation, regulations and policies.
Review and update information security standards to comply with the regulatory requirements as required
Work with regional information security services teams in the core markets to monitor new cybersecurity legislation and/ or regulation, and assess the impact to and the compliance of the Bank’s security policy architecture
Where necessary, work with Line of Business Technology units to drive change management to comply with the regulatory guidelines
Security risk and compliance
Work with key Line of Business Technology to manage material changes to critical systems, conduct risk control self assessment to assess key cybersecurity controls and risk areas and ensure continuous compliance with the cybersecurity legislation and regulations
Engage Line of Business Technology units to conduct annual cybersecurity risk assessment for key bank systems as required under the prevailing regulations
Engage external auditors and certification bodies to assess and audit key bank systems and control environment under the Cyber Trust Mark, ISO27000, SOC2 and Cybersecurity Act
Focal point for international centres on information security matters
Security metrics
Develop and maintain a set of security metrics and visualization for the reporting of cybersecurity landscape to senior management and the Board
Where possible, automate the extraction, transformation and loading of raw security events to generate the security metrics and graphs for the reporting
Establish a framework to organize, manage and archive the security data used for the generation of security metrics and visualization
Generate quarterly reports and insights to apprise senior management of the security trends and areas of concern
Cybersecurity Awareness and Training
Conduct regular phishing exercises and disseminate timely cybersecurity content to inculcate the cybersecurity hygiene and practices
Develop targeted training content and collaborate with various control functions to deliver the content to meet the training needs for specific stakeholders
Drive annual cybersecurity awareness campaign to promote cybersecurity culture and behavior
Data Protection Management
Data Loss Prevention
Design and implement data protection controls to mitigate the risk of data loss across various channels including web, email, network, endpoint etc.
Work with Line of Business Technology to design and implement technology enablers to support the secure handling of Bank’s and customers’ data
Review and investigate data loss events and refer substantiated events to HR for disciplinary actions
Continuously review and enhance the data protection controls to improve the efficacy of data loss prevention
Provide management reporting on data loss matters to the Bank’s risk committees.
Unusual Employee Behavior Monitoring
Drive the implementation of data analytics and machine learning techniques to
Prioritize and highlight data loss events for review and investigation
Identify suspicious activities and misuse of applications and customer data
Oversee the inhouse development of the machine learning models and investigation platform
Drive the development and implementation of data visualization techniques to improve the efficiency of the review and investigation process
Drive the development and enhancement of the investigation platform to meet the users’ need
Requirements
Information security professional with 15 or more years of experience, with a background in a financial or technology environment.
Experience in implementing a program the collation, management and reporting of security metrics such

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App