Epicareer Might not Working Properly
Learn More

Vice President – APAC Information Security and Technology Risk Compliance

  • Full Time, onsite
  • Natixis Corporate & Investment Banking
  • Singapore, Singapore
Salary undisclosed

Checking job availability...

Original
Simplified

Natixis Corporate & Investment Banking is a leading global financial institution that provides advisory, investment banking, financing, corporate banking and capital markets services to corporations, financial institutions, financial sponsors and sovereign and supranational organizations worldwide.

Our teams of experts in close to 30 countries advise clients on their strategic development, helping them to grow and transform their businesses, and maximize their positive impact. Natixis CIB is committed to aligning its financing portfolio with a carbon neutrality path by 2050 while helping its clients reduce the environmental impact of their business.

As part of Groupe BPCE, the second largest banking group in France through the Banque Populaire and Caisse d’Epargne retail networks, Natixis CIB benefits from the Group’s financial strength and solid financial ratings (Standard & Poor's: A+, Moody's: A1, Fitch Ratings: A+, R&I: A+).

The Information Security and Technology Risk Compliance Officer is responsible for supporting and monitoring the Bank’s vision, strategy and program to ensure information assets and technologies are adequately protected and in compliance with regulatory standards across APAC. The role will help with identifying, developing, implementing and maintaining policies, procedures and processes across the Bank to reduce information security and technology risks and ensure adherence to laws and regulations in APAC. In addition, the role will assist in strengthening the cyber resilience of the Bank by establishing appropriate standards and controls, managing security technologies, and supporting the establishment and implementation of relevant policies and procedures in order to ensure adherence to laws and regulations in APAC. The position has regional coverage across Asia Pacific.

Main Responsibilities:

  • Understand and able to analyze laws and regulations with respect to cybersecurity, information security and technology risk in APAC
  • Ensure information is protected across the Bank and that effective information security and technology risk programs, strategies, practices, processes and systems are in place and functioning as required
  • Work with the IT Security team and other internal teams to drive initiatives to strengthen the Bank’s cyber resilience (such as penetration testing)
  • Perform security risk assessment for new IT projects and technologies
  • Independently verify the functional and technical controls with respect to information security and technology risks across the Bank
  • Deliver security awareness trainings and other awareness activities to the Bank’s employees
  • Ensure the implementation and continuous adaptation of the technology risk management framework
  • Ensure compliance of the technology risk management framework in APAC
  • Prepare management information reporting in accordance to the Key Performance Indicators and Key Risk Indicators
  • Actively participate in global and regional initiatives to ensure technology risk management policies and practices are adhered to
  • Liaison with other functions via various meetings, working groups and Committees
  • Review Security Information and Event Management (SIEM) alerts to detect security breaches and conduct investigations if required
  • Monitor industry cyber threat feeds and news and document appropriate analysis
  • Assist in responses to regulators' requests

Required Skills:

  • Bachelor degree holder in Computer Science, Information Systems or relevant discipline
  • CISSP, CISA, CISM or SANS GIAC qualification preferred
  • Minimum 8-10 years of experience in handling information security or technology risk or IT security projects within multinational companies
  • Strong understanding of security risk assessment methodologies for different technologies
  • Good understanding of the information security, cyber security and technology risk regulations in APAC
  • Good understanding of the tools and techniques used by ethical hackers
  • Good understanding of commonly used security tools and concepts including Firewall, Intrusion Detection, APT, Data Loss Prevention, Virtualization and Cloud Computing
  • Good project management skill
  • Keen to develop or enhance existing information security, cyber security and technology risk skills
  • Knowledge of ISO 27001, NIST Cybersecurity Maturity Framework and other security compliance standards
  • Strong analytical skill with the ability to present complex data in a clear and concise manner
  • Strong presentation skill with the ability to explain complicated technical security issues to different stakeholders
  • Excellent communication skills (in English, verbally and in writing) and interpersonal skills
  • Proficiency in the Chinese language as the successful incumbent will need to work on China and Taiwan regulations

Natixis Corporate & Investment Banking is a leading global financial institution that provides advisory, investment banking, financing, corporate banking and capital markets services to corporations, financial institutions, financial sponsors and sovereign and supranational organizations worldwide.

Our teams of experts in close to 30 countries advise clients on their strategic development, helping them to grow and transform their businesses, and maximize their positive impact. Natixis CIB is committed to aligning its financing portfolio with a carbon neutrality path by 2050 while helping its clients reduce the environmental impact of their business.

As part of Groupe BPCE, the second largest banking group in France through the Banque Populaire and Caisse d’Epargne retail networks, Natixis CIB benefits from the Group’s financial strength and solid financial ratings (Standard & Poor's: A+, Moody's: A1, Fitch Ratings: A+, R&I: A+).

The Information Security and Technology Risk Compliance Officer is responsible for supporting and monitoring the Bank’s vision, strategy and program to ensure information assets and technologies are adequately protected and in compliance with regulatory standards across APAC. The role will help with identifying, developing, implementing and maintaining policies, procedures and processes across the Bank to reduce information security and technology risks and ensure adherence to laws and regulations in APAC. In addition, the role will assist in strengthening the cyber resilience of the Bank by establishing appropriate standards and controls, managing security technologies, and supporting the establishment and implementation of relevant policies and procedures in order to ensure adherence to laws and regulations in APAC. The position has regional coverage across Asia Pacific.

Main Responsibilities:

  • Understand and able to analyze laws and regulations with respect to cybersecurity, information security and technology risk in APAC
  • Ensure information is protected across the Bank and that effective information security and technology risk programs, strategies, practices, processes and systems are in place and functioning as required
  • Work with the IT Security team and other internal teams to drive initiatives to strengthen the Bank’s cyber resilience (such as penetration testing)
  • Perform security risk assessment for new IT projects and technologies
  • Independently verify the functional and technical controls with respect to information security and technology risks across the Bank
  • Deliver security awareness trainings and other awareness activities to the Bank’s employees
  • Ensure the implementation and continuous adaptation of the technology risk management framework
  • Ensure compliance of the technology risk management framework in APAC
  • Prepare management information reporting in accordance to the Key Performance Indicators and Key Risk Indicators
  • Actively participate in global and regional initiatives to ensure technology risk management policies and practices are adhered to
  • Liaison with other functions via various meetings, working groups and Committees
  • Review Security Information and Event Management (SIEM) alerts to detect security breaches and conduct investigations if required
  • Monitor industry cyber threat feeds and news and document appropriate analysis
  • Assist in responses to regulators' requests

Required Skills:

  • Bachelor degree holder in Computer Science, Information Systems or relevant discipline
  • CISSP, CISA, CISM or SANS GIAC qualification preferred
  • Minimum 8-10 years of experience in handling information security or technology risk or IT security projects within multinational companies
  • Strong understanding of security risk assessment methodologies for different technologies
  • Good understanding of the information security, cyber security and technology risk regulations in APAC
  • Good understanding of the tools and techniques used by ethical hackers
  • Good understanding of commonly used security tools and concepts including Firewall, Intrusion Detection, APT, Data Loss Prevention, Virtualization and Cloud Computing
  • Good project management skill
  • Keen to develop or enhance existing information security, cyber security and technology risk skills
  • Knowledge of ISO 27001, NIST Cybersecurity Maturity Framework and other security compliance standards
  • Strong analytical skill with the ability to present complex data in a clear and concise manner
  • Strong presentation skill with the ability to explain complicated technical security issues to different stakeholders
  • Excellent communication skills (in English, verbally and in writing) and interpersonal skills
  • Proficiency in the Chinese language as the successful incumbent will need to work on China and Taiwan regulations