Job offer
Head of Information Security & Business Continuity Management (Asia)
The position of Head of Information Security & BCM (Asia) at EFG International in Singapore or Hong Kong involves responsibility for developing and implementing information security strategies and programs across the region. The successful candidate must have experience in information security, strong leadership skills, and excellent communication skills to ensure the security of the bank’s infrastructure, applications, and data.
Job Description
EFG's Information Security and BCM team, led by the Group CIO, establishes and coordinates global information security strategy, initiatives, and standards. The team conducts security risk assessments, manages vulnerability and threat programs, and oversees security awareness and training. It protects infrastructure, applications, and data against cyberattacks. Additionally, it strengthens the bank's defenses through robust Business Continuity Management, supporting operational resilience and coordinated incident response.Main Responsibilities
The main tasks include:- Strategy, Governance, and Leadership: Support and implement EFG’s information security strategy and programs, ensuring that they align with local business objectives.
- Risk Management, Compliance, and Audit: Identification, Assessment, and Management of Regional Information Security Risks and Vulnerabilities.
- Incident Response: Conducting regular security audits and assessments to ensure compliance with internal, regulatory, and industry-specific requirements.
- Stakeholder Engagement: Monitoring the timely completion of local and regional user access certifications.
- Technology, Assessments, and Continuous Improvement: Supporting assessments of infrastructure and applications, and conducting periodic security assessments and audits.
- Performance Management and Resource Management: Reporting on metrics and processes based on emerging threats and best practices.
Skills and experience
The required skills and experience include:- Bachelor's degree in computer science, information technology, or a related field.
- Over 10 years of experience in information security, with extensive knowledge of security policies, practices, and technologies.
- Proven experience in designing and implementing corporate security programs.
- Practical experience in incident management and response.
- Proven leadership skills, including the ability to lead virtual/remote teams.
- Excellent communication and stakeholder engagement skills.
- Experience with regulations and regulatory agencies.
- Industry certifications (e.g., CISSP, CISM, CRISC).
Job details