Cybersecurity Manager
Core
Lead end-to-end information risk assessments and manage operational risks for the Asia Cybersecurity & Information Security Office, serving as the Information Security Officer for the BUSO Center of Excellence.
Role type
Senior IC Information Security Manager / Risk Assessment Lead
Builds
Regional information risk assessment framework, playbooks, standardized reporting, and governance mechanisms for the Asia CoE
Domain
Financial Services / Cybersecurity & Information Risk Management
Required skills
Information security risk assessment, control evaluation, risk treatment, remediation tracking, security incident management, data loss prevention, access reviews, vulnerability management, business continuity planning, zero-trust concepts, governance framework development, stakeholder management, technical risk analysis
Preferred skills
CISM, CISSP, CRISC, CISA, ISO/IEC 27001, NIST Cybersecurity Framework, COBIT, regional/multi-market security program experience, process automation, ServiceNow, Jira, Power BI, Confluence, Archer, Devo, BlueCat Address Manager
Responsibilities
Lead and perform end-to-end project information risk assessments across Asia markets; Review assessments to ensure consistent application of risk methodologies; Analyze project designs and architectures to identify security risks; Translate assessment findings into risk statements and mitigation recommendations; Monitor risk-treatment plans and escalate unresolved risks; Develop and maintain the regional risk assessment framework; Provide application and information security consultation; Partner with market BUSOs to identify activities suitable for centralization; Establish effective governance for CoE services; Support end-to-end management of security incidents, particularly Data Loss Prevention; Provide regular status and performance updates to stakeholders; Conduct knowledge transfer and coaching sessions.
Seniority
Senior, hands-on IC with mentorship responsibilities