442 Security Governance jobs in Singapore

Information Security Governance Manager

Singapore, Singapore Energent Media LLC

Posted 11 days ago

Job Viewed

Tap Again To Close

Job Description

Founded by Changpeng Zhao (CZ) in 2017, Binance is currently the largest cryptocurrency exchange in terms of daily volume. Binance is the core global exchange. However, Binance operates separate exchanges in some countries such as the US, UK, Singapore, and Turkey due to regulatory reasons.

Since Binance has global operations, the exchange does a lot of hiring on a regular basis. Being a market leader, Binance Jobs also come with significant perks. Most of the jobs are remote, with flexible working hours. Binance also offers health insurance, the option to be paid in crypto, and programs to develop your skills.

Binance is the leading global blockchain ecosystem and cryptocurrency infrastructure provider whose suite of financial products includes the world’s largest digital-asset exchange. Our mission is to accelerate cryptocurrency adoption and increase the freedom of money. If you’re looking for a fast-paced, mission-driven organization where opportunities to learn and excel are endless, then Binance is the place for you. We are seeking an Information Security Governance Manager to be responsible for implementing a comprehensive and consistent security governance and compliance strategy across the organization to protect and manage its technology and data related information security risks. The candidate will be responsible for coordinating, identifying gaps, providing guidance and establishing end to end security governance to ensure effective internal controls are implemented to achieve data privacy, security, reliability and resilience that meets compliance and local regulatory requirements.

Responsibilities
  • Support the delivery of global security governance and compliance strategies.
  • Manage and maintain a security compliance framework across global entities that can align to Binance’s compliance and internal audits requirements.
  • Develop, manage and maintain effective information security policies, processes, standards and procedures.
  • Lead and support ISO 27001, PCI-DSS, SOC 2 Type 1/2 and other security compliance projects.
  • Develop maturity model and track information security controls.
  • Internal first point of contact for general security enquiries. Proactively approach and support internal stakeholders across global entities.
  • Establish and maintain global security governance and compliance process.
  • Respond to security questionnaires from internal/external security audits and organize/document the common answers and approaches for future audits.
  • Facilitate security risk management within the business units.
  • Establish and maintain information risk metrics to highlight information assets that have the highest risk exposure.
  • Conduct regular reviews of remediation actions and report to business and technology senior management.
Requirements
  • Bachelor's degree or higher in information technology, cyber security or related field.
  • 5+ years of experience in a security governance role.
  • Strong leadership and excellent communication skills.
  • Understanding of information risk, security control, data privacy related regulations (e.g. CCPA, SG PDPA, EU GDPR, China Cybersecurity law) within the financial services and banking industry.
  • Strong knowledge and practical working experiences in delivering global projects of international data privacy and information security frameworks including NIST Cybersecurity & Privacy Framework, ISO 27001, ISO 27701, CIS, SOC 2 Type 1/2 Report, PCI-DSS and ISAE 3000.
  • Demonstrable work experience delivering effective business and technical security solutions, processes, tools, and high performing teams.
  • A good working knowledge of the latest information technology security trends and emerging threats is essential.
  • Experience of implementing risk management principles and methodologies within a security or technology function.
  • Good project management experience and skills.
  • Strong analytical and problem-solving skills are a must-have.
  • Having one of the below security or privacy qualifications is a plus - CISSP, CISM, CISA, CEH, SANS, CCSP, ISO 27001 Lead Auditor, IAPP CIPP / CIPM.
  • An understanding of cloud infrastructure technologies and associated risks would be beneficial.

Working at Binance

  • Be a part of the world’s leading blockchain ecosystem that continues to grow and offers excellent career development opportunities.
  • Work alongside diverse, world-class talent in an environment where learning and growth opportunities are endless.
  • Tackle fast-paced, challenging and unique projects.
  • Work in a truly global organization, with international teams and a flat organizational structure.
  • Competitive salary and benefits.
  • Flexible working hours, remote-first, and casual work attire.

Learn more about how Binancians embody the organization’s core values , creating a unified culture that enables collaboration, excellence, and growth. Apply today to be a part of the Web3 revolution! Binance is committed to being an equal opportunity employer. We believe that having a diverse workforce is fundamental to our success. By submitting a job application, you confirm that you have read and agree to our Candidate Privacy Notice .

#J-18808-Ljbffr
This advertiser has chosen not to accept applicants from your region.

Information Security Governance Manager

Singapore, Singapore Energent Media LLC

Posted today

Job Viewed

Tap Again To Close

Job Description

full-time

Founded by Changpeng Zhao (CZ) in 2017, Binance is currently the largest cryptocurrency exchange in terms of daily volume. Binance is the core global exchange. However, Binance operates separate exchanges in some countries such as the US, UK, Singapore, and Turkey due to regulatory reasons.
Since Binance has global operations, the exchange does a lot of hiring on a regular basis. Being a market leader,
Binance Jobs
also come with significant perks. Most of the jobs are remote, with flexible working hours. Binance also offers health insurance, the option to be paid in crypto, and programs to develop your skills.
Binance is the leading global blockchain ecosystem and cryptocurrency infrastructure provider whose suite of financial products includes the world’s largest digital-asset exchange. Our mission is to accelerate cryptocurrency adoption and increase the freedom of money. If you’re looking for a fast-paced, mission-driven organization where opportunities to learn and excel are endless, then Binance is the place for you. We are seeking an Information Security Governance Manager to be responsible for implementing a comprehensive and consistent security governance and compliance strategy across the organization to protect and manage its technology and data related information security risks. The candidate will be responsible for coordinating, identifying gaps, providing guidance and establishing end to end security governance to ensure effective internal controls are implemented to achieve data privacy, security, reliability and resilience that meets compliance and local regulatory requirements.
Responsibilities
Support the delivery of global security governance and compliance strategies.
Manage and maintain a security compliance framework across global entities that can align to Binance’s compliance and internal audits requirements.
Develop, manage and maintain effective information security policies, processes, standards and procedures.
Lead and support ISO 27001, PCI-DSS, SOC 2 Type 1/2 and other security compliance projects.
Develop maturity model and track information security controls.
Internal first point of contact for general security enquiries. Proactively approach and support internal stakeholders across global entities.
Establish and maintain global security governance and compliance process.
Respond to security questionnaires from internal/external security audits and organize/document the common answers and approaches for future audits.
Facilitate security risk management within the business units.
Establish and maintain information risk metrics to highlight information assets that have the highest risk exposure.
Conduct regular reviews of remediation actions and report to business and technology senior management.
Requirements
Bachelor's degree or higher in information technology, cyber security or related field.
5+ years of experience in a security governance role.
Strong leadership and excellent communication skills.
Understanding of information risk, security control, data privacy related regulations (e.g. CCPA, SG PDPA, EU GDPR, China Cybersecurity law) within the financial services and banking industry.
Strong knowledge and practical working experiences in delivering global projects of international data privacy and information security frameworks including NIST Cybersecurity & Privacy Framework, ISO 27001, ISO 27701, CIS, SOC 2 Type 1/2 Report, PCI-DSS and ISAE 3000.
Demonstrable work experience delivering effective business and technical security solutions, processes, tools, and high performing teams.
A good working knowledge of the latest information technology security trends and emerging threats is essential.
Experience of implementing risk management principles and methodologies within a security or technology function.
Good project management experience and skills.
Strong analytical and problem-solving skills are a must-have.
Having one of the below security or privacy qualifications is a plus - CISSP, CISM, CISA, CEH, SANS, CCSP, ISO 27001 Lead Auditor, IAPP CIPP / CIPM.
An understanding of cloud infrastructure technologies and associated risks would be beneficial.
Working at Binance
Be a part of the world’s leading blockchain ecosystem that continues to grow and offers excellent career development opportunities.
Work alongside diverse, world-class talent in an environment where learning and growth opportunities are endless.
Tackle fast-paced, challenging and unique projects.
Work in a truly global organization, with international teams and a flat organizational structure.
Competitive salary and benefits.
Flexible working hours, remote-first, and casual work attire.
Learn more about how Binancians embody the organization’s
core values , creating a unified culture that enables collaboration, excellence, and growth. Apply today to be a part of the Web3 revolution! Binance is committed to being an equal opportunity employer. We believe that having a diverse workforce is fundamental to our success. By submitting a job application, you confirm that you have read and agree to our
Candidate Privacy Notice .
#J-18808-Ljbffr

This advertiser has chosen not to accept applicants from your region.

Strategic Information Security Governance Professional

Singapore, Singapore beBeeGovernance

Posted today

Job Viewed

Tap Again To Close

Job Description

Job Description

We are seeking an accomplished IT Security Governance & GRC leader to take charge of a mission-critical function within a prominent organisation. This position plays a key role in shaping the governance, risk, compliance, and security awareness agenda across multiple Asian markets.

You will lead a talented team, work closely with senior executives and regulators, and ensure the organisation consistently meets stringent governance, risk, and compliance requirements while driving a culture of security excellence.

This advertiser has chosen not to accept applicants from your region.

Chief Security Governance Officer

Singapore, Singapore beBeeSecurity

Posted today

Job Viewed

Tap Again To Close

Job Description

Job Overview

We are seeking an experienced Security Administration Lead to oversee the development and implementation of our security framework. As a key member of our cybersecurity team, you will be responsible for establishing security processes, collaborating with regional leadership, and serving as an identity and access management expert.

Key Responsibilities
  • Establish and maintain a comprehensive security framework, defining requirements and developing key processes.
  • Assist with the transition from local to regional administration, providing hands-on support as needed.
  • Collaborate with Regional Cyber Security leadership to assign team responsibilities, including user management, certificate handling, and security configurations.
  • Serve as the Identity & Access Management expert, guiding centralized authentication and access reviews.
  • Support incident response efforts, including investigation and remediation.
  • Manage relationships with external vendors, ensuring alignment with our security objectives.
  • Oversee security resources APAC, including those outside the team, to ensure cohesive security practices.
  • Provide assistance with other security projects as needed, aligning with our organizational goals.
Requirements

A successful candidate will possess:

  • Bachelor's or above degree in Information Security, Computer Science, or a related field.
  • At least 8 years of experience in hands-on cybersecurity, with prior management experience in a Security Administration role.
  • Proven knowledge and experience with Identity & Access Management.
  • Strong understanding of various cyber security technologies addressing the protection of identities, data, applications, endpoints, and infrastructure.
  • Demonstrated experience in applying security and risk frameworks such as NIST, Mitre ATT&CK, Mitre DEFEND, and ISO27K.
  • Experience running and maturing a Security Administration function.
  • Professional certificates beneficial (CISSP / CISM / SANS).
Benefits

This role offers a unique opportunity to join our dynamic cybersecurity team and contribute to the growth and success of our organization.

What We Offer

We provide a supportive work environment, opportunities for professional growth, and a competitive compensation package.

This advertiser has chosen not to accept applicants from your region.

Associate Director, Security Governance

528799 $17500 Monthly AIA SINGAPORE PRIVATE LIMITED

Posted 11 days ago

Job Viewed

Tap Again To Close

Job Description

At AIA we’ve started an exciting movement to create a healthier, more sustainable future for everyone.

As pioneering innovators for over 100 years, we’re now transforming our organisation to be faster, simpler and more connected. Because we want to be even better equipped to develop digital solutions and experiences that help more people live Healthier, Longer, Better Lives.

To get there, we need people with tech/digital/analytics expertise and passion to help develop positive, sustainable change through digitally enhanced experiences that will impact the lives of millions of people and create a healthier future for everyone.


If you believe in developing a better tomorrow, read on.

About the Role

This role is responsible for delivering the AIA Singapore Line 1 GRC to the organisation, from coordination Governance reporting activities, Operational Technology Risk Management and Compliance and Audit functions prescribed from AIA Group, industry regulations and the Monetary Authority of Singapore (MAS). This role is also responsible for AIA’s Cyber Security Awareness training.

This leadership role is instrumental in maintaining AIA external stakeholder relations. Working directly with AIA Singapore Information Security Head, the individual must be an exceptional communicator on both technical and non-technical issues for Line 2, Audit, Executive Committee, Board and Regulator communications. The occupant needs to lead and mentor a team of GRC professionals as they navigate scheduled and ad-hoc inspections or audits of AIA’s controls by applying their professional and well-rounded experience as a Governance Leader.


Information Security & Technology Risk Metrics

  • Drive the management monitoring and reporting methodology for various key information security and security risk governance metrics, security incidents, policy/standards deviations, third party security assessments, etc.
  • Prepare and present relevant technology and security risk indicators and updates to security forums, Operational Risk Committees and/or the Board Risk Committees.

IT Risk and Compliance Management

  • Drive organizational self-assessments against related technology and security regulatory advisories, circulars, guidelines and notices.
  • Coordinate annual IT risk and control self-assessment exercises according to MAS regulatory notices/guidelines, internal enterprise IT policies, and standards and maintain the Group electronic Governance Risk and Compliance (eGRC) tool.
  • Manage and follow through on the tracking of deviations and exemptions in the context of AIA’s technology and security policies and standards within the Group eGRC tool.

Security and Policies Awareness

  • Communicate material changes of internal policies/standards to internal staff and key stakeholders.
  • Develop effective methods to deliver cybersecurity training to various groups of audiences, including but not limited to – staff, IT teams, management, third party service providers and our agency forces.

Specialized Areas Governance

  • The role may be called upon to lead or be involved in ensuring governance of specialized areas under information security, such as the governance of operations in the areas of IAM, cloud security, application security, etc.
  • Assist in enterprise-wide risk and compliance coordination for Technology division, where applicable.
  • Lead promotion of activities to increase information security within your teams to embed and continuously improve adherence to good practice.
  • Drive a continues Learning and Development program for staff training. (with inhouse and external training programs).

Requirements:

  • Advanced degree in one of the following or related disciplines (Computer Science, Computer Engineering, Information Security, Information Systems).
  • Preferably a holder of one or more of the following information security and audit qualifications: CISSP, CISA, CRISC, CCSP.
  • 15 years of experience in a combination of these roles:
    Cybersecurity governance, monitoring and reporting of key security metrics and risk indicators, either in Line 1 or Line 2.
  • Leading responses to IT audits and regulatory inspections.
  • Managing IT risk and compliance assessments, including assessments on the cyber hygiene of third-party service providers
  • Development, review and management of deviations/exemptions to technology policies and standards.
  • Developing and driving the organisation-wide information security awareness programme.
  • Managing medium size team as the incumbent is responsible in managing 12 team members in Singapore and remotely.
  • Substantial working experience from financial industry, big tech firms or established auditing firms will be considered favourably.
  • Experience and exposure in information security standards such as ISO27001 and other relevant industry frameworks will be an advantage.
  • Knowledge of tools such as PowerBI or JIRA would be advantageous, including the ability to implement automation.
  • Good communication, coordination, and interpersonal skills.
  • Strong stakeholder management capabilities.
  • High level of energy, professional integrity, and leadership demonstration.
  • Ability to adopt a helicopter view context to problem solving.

Build a career with us as we help our customers and the community live Healthier, Longer, Better Lives.

You must provide all requested information, including Personal Data, to be considered for this career opportunity. Failure to provide such information may influence the processing and outcome of your application. You are responsible for ensuring that the information you submit is accurate and up-to-date.

This advertiser has chosen not to accept applicants from your region.

IT Security & Governance Administrative Assistant

Singapore, Singapore beBeeInformation

Posted today

Job Viewed

Tap Again To Close

Job Description

Job Overview

The successful candidate will be responsible for establishing procedures for tracking IT assets, including SSL certificates and licenses, to ensure timely renewal and prevent disruptions to bank operations.

This advertiser has chosen not to accept applicants from your region.

Regional Manager, Business Security & Governance

139941 $12000 Monthly THALES DIS (SINGAPORE) PTE. LTD.

Posted 6 days ago

Job Viewed

Tap Again To Close

Job Description

Responsibilities:

  • Reporting to Asia CDI Security Director is responsible & accountable for Security Governance and Oversight for Thales DIS Asia Business, R&D and Outsourced activities (Manuf / SW Dev etc).
  • Ensure that site security processes and procedures are setup and operated in accordance with Corporate and Site Security Polices & requirements.
  • Support as needed site security management on all aspects of personnel, physical, production and IT security at the various card, secured documents production and personalization sites within the region responsible.
  • Acting in accordance with the Corporate Security Management System and Policy to support the related site security management on all aspects of personnel, physical, logical, IT security at all Asia R&D / Outsource Manuf activities.
  • Ensure the oversight of information security for the related sites in Asia region are in accordance to required org security requirements and compliance to applicable certification and regulatory requirements.
  • Serves as a SME for the related stakeholders in Asia region in regard to any security queries, issues and provide appropriate solutions in line with the required compliance and risk level
  • Support the sites in obtaining accreditation and then ensure ongoing compliance with the security regulatory requirements in respect for business / R&D security activities as per applicable standards such (CC/EMVCo, ISO27001, GSM-SAS etc).
  • Cloud Platform Expertise: Deep understanding of security best practices and native security services within major cloud platforms (e.g., AWS, Azure, GCP). Specify which platforms are most relevant to your organization.
  • Container and Kubernetes Security: Understanding of security best practices for containerized applications and orchestration platforms like Kubernetes in cloud environments.
  • Serverless Security: Awareness of the unique security challenges and best practices associated with serverless computing (e.g., AWS Lambda, Azure Functions).
  • Cloud Data Security: Expertise in implementing data loss prevention (DLP), encryption at rest and in transit, data masking, and other data security controls specific to cloud storage and databases.
  • Perform Risk Assessment and regular audits for both internal and external stakeholders as per Accreditation or Corporate Standards and recommend and verify the implementation of solutions/controls.
  • Ensure that Security risks and issues are appropriately managed in a measurable way and in accordance with Corporate policies and customer requirements
  • Develop and maintain the Site Security Management System (SMS) to fulfill the regulatory requirements and ensure all Security KPI compliance to ensure & achieve desired level of security for Sites & Business Activities.
  • Provide inputs and recommendations to management and take necessary steps to propose the security controls needed to protect information and assets as well as all business data and information of customers and partners.
  • Act as the Tactical Process Manager between personnel responsible for security and organizational leaders to help organization achieve its strategic security objectives.
  • Formulate security audit plan with Asia Security Director and perform internal cross-site audits in Asia region to ensure that controls and audit trials are in place to protect company assets.
  • Monitor all security activities (Logical & Physical) and advice the management team on all matters concerning card/secured documents production security, IT system security as well as outsourced activities.
  • To work with all business owners and departments to ensure the security requirements and deployment of security framework in all production sites as well as outsourced manufacturing activities.
  • Lead and manage the investigation of any security breaches that has significantly impact to the business.
  • Any other special projects as specified, as and when required.

The job holder shall always during the employment with the company, respect and comply with the Quality, Health, Safety, Environmental & Security requirements during the performance of his/her duties.



Requirements:

  • Bachelor Degree in IT related field or equivalent
  • Strong communication (Oral & Written).
  • IT security knowledge & experience.
  • Operational IT Security is an advantage
  • CISSP, CISA, CISM certification is preferred.
  • Security auditing experience will be added advantage.
  • At least 8 years of experience of IT Security or Audit experience in established firm preferred,
  • Experience in security incident investigation and report writing.
  • Experience to present & communicate at all levels of the org .
  • High degree of integrity, confidentiality, and discretion.
  • Strong interpersonal and communication skills required;
  • Ability to interact and communicate effectively at all levels;
  • Independent, approachable & analytical;
  • Able to remain calm and effective under pressure.
  • Strong interpersonal and communication skills (written and verbal).
  • Demonstrated knowledge and experience in Operational Technology (OT) and Information Technology (IT) Security .
  • Solid understanding of security principles, frameworks, and best practices.
  • Experience in conducting security risk assessments and audits.
  • Familiarity with relevant security standards and regulations (e.g., ISO 27001, specific industry standards).
  • Proven ability to develop and implement security policies and procedures.
  • Strong analytical and problem-solving skills.
  • Self-motivated with a proactive and responsible attitude.
  • Ability to work independently and collaboratively.
  • Experience in security within a manufacturing or related industry .
  • Knowledge of cloud security principles and practices (mention specific platforms if crucial, e.g., "familiarity with AWS or Azure security concepts").
  • Understanding of container and Kubernetes security concepts.
  • Awareness of serverless security considerations.
  • Experience with data loss prevention (DLP) and data encryption techniques.
  • Familiarity with embedded programming fundamentals (if relevant to the role's scope).
  • Experience with Security GRC tools and processes &
  • Experience security dashboard platforms (e.g., Splunk, Grafana, Kibana, Power BI) is a plus.
  • Able to travel 20-30% of time within Asia as needed.
This advertiser has chosen not to accept applicants from your region.
Be The First To Know

About the latest Security governance Jobs in Singapore !

Insider Threat Lead, Security Governance and Compliance

Singapore, Singapore ByteDance

Posted 8 days ago

Job Viewed

Tap Again To Close

Job Description

Insider Threat Lead, Security Governance and Compliance Insider Threat Lead, Security Governance and Compliance

2 days ago Be among the first 25 applicants

Responsibilities
About the Team
The Internal Threat Management team is responsible for managing and mitigating information security risks posed within the organisation. To ensure that the company's risk management and governance strategies are up to date and aligned across the organisation, this team is responsible for regular industry benchmarking and working with stakeholders from cross-functional teams to perform regular risk assessments and align risk mitigation strategies. This team is also responsible for managing the optimization, operation, training, and data analysis of the internal threat platform and UEBA (User and Entity Behavior Analytics) and DLP (Data Loss Prevention) platforms within the company.

Responsibilities
1. Maintain a robust risk governance framework that supports internal threat management, ensuring it is aligned with the organization’s overall risk management and compliance strategies.
2. Establish and manage processes for risk assessment, control testing, and risk mitigation related to internal threats, ensuring that these processes are effective and aligned with industry best practices.
3. Develop and define key risk metrics to assess the effectiveness of internal threat detection and mitigation strategies
4. Continuously monitor and analyze internal threat data, identifying emerging trends, patterns, and areas of concern related to insider threats
5. Develop and deliver regular risk reports for senior management, providing insights on the status and effectiveness of internal threat programs, key risk indicators, and threat trends.
6. Work closely with internal stakeholders to ensure that policies and procedures are properly followed and that risk management processes are integrated across departments.

Qualifications
Minimum Qualifications
1. Bachelor's degree or above, with a preference for majors in Information Security, Computer Science, Information Technology, privacy, risk or a related field. Professional certifications such as CISSP, CISM, CRISC, or CGEIT are highly desirable.
2. Minimum of 5 years of work experience, with at least 3 years of team management experience and a preference for experience in risk management and insider threat program.
3. Strong experience in data analysis and the ability to extract insights from complex risk data to identify patterns and trends. Expertise in developing dashboards and reports that clearly communicate complex risk data to senior management and non-technical stakeholders.
4. Proficient in risk governance frameworks and best practices for internal threat management, including risk assessments, control testing, and compliance.
5. Solid understanding of insider threat risks, including data exfiltration, privilege abuse, policy violations, and insider fraud.
6. Strong communication skills, with the ability to translate complex risk-related information into clear, actionable insights for diverse audiences.

Preferred Qualifications
1. Familiarity with regulatory requirements related to data protection and internal threat management (e.g., GDPR, CCPA, HIPAA).
2. Experience with designing, implementation and operation of commercial or in-house UBA/UEBA solutions (e.g., Splunk, Exabeam) are highly desirable
3. Experience with threat modeling methodologies (e.g., STRIDE, PASTA) to analyze and assess security threats within software applications, systems, and networks.

About Us
Founded in 2012, ByteDance's mission is to inspire creativity and enrich life. With a suite of more than a dozen products, including TikTok, Lemon8, CapCut and Pico as well as platforms specific to the China market, including Toutiao, Douyin, and Xigua, ByteDance has made it easier and more fun for people to connect with, consume, and create content.


Why Join ByteDance
Inspiring creativity is at the core of ByteDance's mission. Our innovative products are built to help people authentically express themselves, discover and connect – and our global, diverse teams make that possible. Together, we create value for our communities, inspire creativity and enrich life - a mission we work towards every day.
As ByteDancers, we strive to do great things with great people. We lead with curiosity, humility, and a desire to make impact in a rapidly growing tech company. By constantly iterating and fostering an "Always Day 1" mindset, we achieve meaningful breakthroughs for ourselves, our Company, and our users. When we create and grow together, the possibilities are limitless. Join us.
Diversity & Inclusion
ByteDance is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives. Our platform connects people from across the globe and so does our workplace. At ByteDance, our mission is to inspire creativity and enrich life. To achieve that goal, we are committed to celebrating our diverse voices and to creating an environment that reflects the many communities we reach. We are passionate about this and hope you are too.

Seniority level
  • Seniority level Not Applicable
Employment type
  • Employment type Full-time
Job function
  • Job function Other, Information Technology, and Management
  • Industries Technology, Information and Internet

Referrals increase your chances of interviewing at ByteDance by 2x

Get notified about new Security Lead jobs in Singapore, Singapore .

Client Information Security Lead/Senior Manager (Infra Enterprise) Senior Executive / Assistant Manager / Manager, Security Policy & Governance Regional Security Associate Manager - Disney Cruise Line Cyber Security Operations (CSO) - Asia Cluster Governance Lead Senior Manager, Client Info Security (Applications) Senior Information Technology Security Officer Global Information Security, Risk and Governance Manager Regional Manager, Business Security & Governance Senior Information Security Incident Response Lead IT Risk, Compliance and Security Manager Chief Information Security Officer - Fintech Sr Customer Success Manager - Identity Security - APAC TDI – Chief Security Office (CSO) - APAC - Threat Intelligence Regional Lead - Vice President Assistant Manager / Manager (Security Operations) VP, Cyber Security Program Manager, COO's Office Security Operations Manager, Data Center

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

#J-18808-Ljbffr
This advertiser has chosen not to accept applicants from your region.

Insider Threat Lead, Security Governance and Compliance

Singapore, Singapore ByteDance

Posted today

Job Viewed

Tap Again To Close

Job Description

Insider Threat Lead, Security Governance and Compliance

Insider Threat Lead, Security Governance and Compliance

2 days ago Be among the first 25 applicants

Responsibilities
About the Team
The Internal Threat Management team is responsible for managing and mitigating information security risks posed within the organisation. To ensure that the company's risk management and governance strategies are up to date and aligned across the organisation, this team is responsible for regular industry benchmarking and working with stakeholders from cross-functional teams to perform regular risk assessments and align risk mitigation strategies. This team is also responsible for managing the optimization, operation, training, and data analysis of the internal threat platform and UEBA (User and Entity Behavior Analytics) and DLP (Data Loss Prevention) platforms within the company.
Responsibilities
1. Maintain a robust risk governance framework that supports internal threat management, ensuring it is aligned with the organization’s overall risk management and compliance strategies.
2. Establish and manage processes for risk assessment, control testing, and risk mitigation related to internal threats, ensuring that these processes are effective and aligned with industry best practices.
3. Develop and define key risk metrics to assess the effectiveness of internal threat detection and mitigation strategies
4. Continuously monitor and analyze internal threat data, identifying emerging trends, patterns, and areas of concern related to insider threats
5. Develop and deliver regular risk reports for senior management, providing insights on the status and effectiveness of internal threat programs, key risk indicators, and threat trends.
6. Work closely with internal stakeholders to ensure that policies and procedures are properly followed and that risk management processes are integrated across departments.
Qualifications
Minimum Qualifications
1. Bachelor's degree or above, with a preference for majors in Information Security, Computer Science, Information Technology, privacy, risk or a related field. Professional certifications such as CISSP, CISM, CRISC, or CGEIT are highly desirable.
2. Minimum of 5 years of work experience, with at least 3 years of team management experience and a preference for experience in risk management and insider threat program.
3. Strong experience in data analysis and the ability to extract insights from complex risk data to identify patterns and trends. Expertise in developing dashboards and reports that clearly communicate complex risk data to senior management and non-technical stakeholders.
4. Proficient in risk governance frameworks and best practices for internal threat management, including risk assessments, control testing, and compliance.
5. Solid understanding of insider threat risks, including data exfiltration, privilege abuse, policy violations, and insider fraud.
6. Strong communication skills, with the ability to translate complex risk-related information into clear, actionable insights for diverse audiences.
Preferred Qualifications
1. Familiarity with regulatory requirements related to data protection and internal threat management (e.g., GDPR, CCPA, HIPAA).
2. Experience with designing, implementation and operation of commercial or in-house UBA/UEBA solutions (e.g., Splunk, Exabeam) are highly desirable
3. Experience with threat modeling methodologies (e.g., STRIDE, PASTA) to analyze and assess security threats within software applications, systems, and networks.
About Us
Founded in 2012, ByteDance's mission is to inspire creativity and enrich life. With a suite of more than a dozen products, including TikTok, Lemon8, CapCut and Pico as well as platforms specific to the China market, including Toutiao, Douyin, and Xigua, ByteDance has made it easier and more fun for people to connect with, consume, and create content.
Why Join ByteDance
Inspiring creativity is at the core of ByteDance's mission. Our innovative products are built to help people authentically express themselves, discover and connect – and our global, diverse teams make that possible. Together, we create value for our communities, inspire creativity and enrich life - a mission we work towards every day.
As ByteDancers, we strive to do great things with great people. We lead with curiosity, humility, and a desire to make impact in a rapidly growing tech company. By constantly iterating and fostering an "Always Day 1" mindset, we achieve meaningful breakthroughs for ourselves, our Company, and our users. When we create and grow together, the possibilities are limitless. Join us.
Diversity & Inclusion
ByteDance is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives. Our platform connects people from across the globe and so does our workplace. At ByteDance, our mission is to inspire creativity and enrich life. To achieve that goal, we are committed to celebrating our diverse voices and to creating an environment that reflects the many communities we reach. We are passionate about this and hope you are too.

Seniority level

  • Seniority level

    Not Applicable

Employment type

  • Employment type

    Full-time

Job function

  • Job function

    Other, Information Technology, and Management
  • Industries

    Technology, Information and Internet

Referrals increase your chances of interviewing at ByteDance by 2x

Get notified about new Security Lead jobs in Singapore, Singapore .

Client Information Security Lead/Senior Manager (Infra Enterprise)

Senior Executive / Assistant Manager / Manager, Security Policy & Governance

Regional Security Associate Manager - Disney Cruise Line

Cyber Security Operations (CSO) - Asia Cluster Governance Lead

Senior Manager, Client Info Security (Applications)

Senior Information Technology Security Officer

Global Information Security, Risk and Governance Manager

Regional Manager, Business Security & Governance

Senior Information Security Incident Response Lead

IT Risk, Compliance and Security Manager

Chief Information Security Officer - Fintech

Sr Customer Success Manager - Identity Security - APAC

TDI – Chief Security Office (CSO) - APAC - Threat Intelligence Regional Lead - Vice President

Assistant Manager / Manager (Security Operations)

VP, Cyber Security Program Manager, COO's Office

Security Operations Manager, Data Center

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

#J-18808-Ljbffr

This advertiser has chosen not to accept applicants from your region.

Intern - IT Security & Governance Administrative (5 mths)

Singapore, Singapore HL BANK

Posted today

Job Viewed

Tap Again To Close

Job Description

Roles & Responsibilities

JOB DESCRIPTION:

  • Establishing the procedures of tracking IT Assets (SSL Certs, Licenses) to ensure relevant PIC's timely renewal to prevent any disruptions to bank operations.
  • Assist IT in facilitating the various business teams to migrate to Google Drive, which includes engaging them via meetings, helping to answer queries on ad hoc and go as far as executing on behalf should the situation arises.
  • Documentation on the understanding of what goes into onboarding & offboarding of users, which includes working with HR, IT Helpdesk & IT IAM processes to integrate it into a singular flow.
  • Revamping of the existing Bank's access portal, making it easily maintainable by various teams, which integrates the links to all applications, HLBS Newsletters & events and HLBS policies & forms.
  • Work with relevant PIC's (in branch or head office) to further understand and improve on any tracking mechanism.
  • Identify any process improvement opportunities to increase efficiency of the onboarding & offboarding process of user.
  • Work with various departments' identified key personnel and communicate to the respective reporting manager on further improvements that can be made to the Bank's access portal.
  • Carry out any other duties as directed by Company Management

REQUIREMENTS

  • ITE/Diploma/Degree in Computer Science, Information Technology, Finance, Business Administration, or related field
  • Knowledge of VBA (which is for Google App Script) is a plus.
  • Technically inclined (able to understand code & syntax, perform setup/configuration)
  • Documentation skills (knows proper sectioning, workflow & diagram drawing)
  • Strong analytical and problem-solving skills, with attention to detail and accuracy
  • Excellent communication and interpersonal skills, with the ability to build relationships and collaborate with diverse groups of people
  • Ability to learn new technologies quickly and adapt to changing priorities and deadlines
  • Self-motivated and proactive learner who takes initiative and seeks feedback regularly
Tell employers what skills you have

Market Research
Outlook
Document Management
Version Control
Microsoft Office
Data Modeling
Change Management
Process Improvement
Interpersonal Skills
Google Drive
Knowledge Management
Documentation Skills
VBA
Administration
Information Technology
SQL
Attention to Detail
Publishing
Ability To Learn
Surveys
This advertiser has chosen not to accept applicants from your region.
 

Nearby Locations

Other Jobs Near Me

Industry

  1. request_quote Accounting
  2. work Administrative
  3. eco Agriculture Forestry
  4. smart_toy AI & Emerging Technologies
  5. school Apprenticeships & Trainee
  6. apartment Architecture
  7. palette Arts & Entertainment
  8. directions_car Automotive
  9. flight_takeoff Aviation
  10. account_balance Banking & Finance
  11. local_florist Beauty & Wellness
  12. restaurant Catering
  13. volunteer_activism Charity & Voluntary
  14. science Chemical Engineering
  15. child_friendly Childcare
  16. foundation Civil Engineering
  17. clean_hands Cleaning & Sanitation
  18. diversity_3 Community & Social Care
  19. construction Construction
  20. brush Creative & Digital
  21. currency_bitcoin Crypto & Blockchain
  22. support_agent Customer Service & Helpdesk
  23. medical_services Dental
  24. medical_services Driving & Transport
  25. medical_services E Commerce & Social Media
  26. school Education & Teaching
  27. electrical_services Electrical Engineering
  28. bolt Energy
  29. local_mall Fmcg
  30. gavel Government & Non Profit
  31. emoji_events Graduate
  32. health_and_safety Healthcare
  33. beach_access Hospitality & Tourism
  34. groups Human Resources
  35. precision_manufacturing Industrial Engineering
  36. security Information Security
  37. handyman Installation & Maintenance
  38. policy Insurance
  39. code IT & Software
  40. gavel Legal
  41. sports_soccer Leisure & Sports
  42. inventory_2 Logistics & Warehousing
  43. supervisor_account Management
  44. supervisor_account Management Consultancy
  45. supervisor_account Manufacturing & Production
  46. campaign Marketing
  47. build Mechanical Engineering
  48. perm_media Media & PR
  49. local_hospital Medical
  50. local_hospital Military & Public Safety
  51. local_hospital Mining
  52. medical_services Nursing
  53. local_gas_station Oil & Gas
  54. biotech Pharmaceutical
  55. checklist_rtl Project Management
  56. shopping_bag Purchasing
  57. home_work Real Estate
  58. person_search Recruitment Consultancy
  59. store Retail
  60. point_of_sale Sales
  61. science Scientific Research & Development
  62. wifi Telecoms
  63. psychology Therapy
  64. pets Veterinary
View All Security Governance Jobs