Skip to content

Open nowPosted today

SL2705 - Technology Information Security Officer (TISO)

MyCareersFuture97,045 open roles

Pay
SGD 8,000 – SGD 8,700 a month
Where
Central, Singapore
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSL2705 - Technology Information Security Officer (TISO)MyCareersFuture · Central, Singapore
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on MyCareersFuture's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. MyCareersFuture postings stay open a median of 3 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.6%3 days
  3. 8.1%7 days
  4. 15.0%14 days
  5. 33.9%30 days
This job: posted today

MyCareersFuture median: 3 days open

The posting

About the Role

We are looking for an experienced Technology Information Security Officer (TISO) to provide security assessment, advisory, and oversight across technology initiatives and business applications.

As a senior individual contributor and Subject Matter Expert (SME), you will ensure that secure-by-design, secure-by-default, and secure operations principles are embedded across the organisation.

You will work closely with development, architecture, project, and technology teams to integrate security throughout the Software Development Life Cycle (SDLC), identify technology risks, recommend appropriate security controls, and ensure alignment with regulatory and industry requirements.

Key Responsibilities

Security Assessments & Risk Management

  • Conduct comprehensive technical security assessments to identify security risks, control gaps, and vulnerabilities.
  • Perform information security risk assessments for business applications throughout the development lifecycle.
  • Assess projects operating under SDLC, Agile, Iterative, DevOps, and DevSecOps methodologies.
  • Identify and communicate significant information security risks and control gaps.
  • Recommend appropriate technical and process controls to mitigate identified risks.
  • Review and approve security assessments for relevant projects and operational requirements.

Application & SDLC Security

  • Serve as a Subject Matter Expert for security throughout the application development lifecycle.
  • Provide security advice to development, engineering, architecture, and project teams.
  • Assess security requirements and controls throughout application design, development, testing, deployment, and operations.
  • Ensure security requirements are incorporated into application and system designs from the beginning.
  • Promote secure-by-design and secure-by-default practices across technology initiatives.
  • Support the implementation of security controls to strengthen application and SDLC security.

Security Architecture & Controls

  • Provide guidance across key security domains including authentication, authorisation, access control, entitlement management, cryptography, encryption, network security, application security, system security, and key management.
  • Assess API security and cloud security architectures across AWS and Azure environments.
  • Review vulnerability management practices against recognised frameworks and industry standards.
  • Provide independent technical security assessments and recommendations on proposed technology solutions.

Security Governance & Continuous Improvement

  • Drive initiatives to strengthen information security processes, policies, standards, and controls.
  • Promote information security best practices across technology teams.
  • Ensure security practices remain aligned with applicable regulatory requirements and industry frameworks.
  • Identify opportunities to improve security governance, assessment processes, and overall technology risk management.
  • Support the continuous improvement of the organisation's information security capabilities.

Stakeholder Management

  • Collaborate with domain architects, project managers, developers, engineers, and technology Subject Matter Experts.
  • Provide clear security guidance and help stakeholders understand their information security responsibilities.
  • Promote awareness of information security policies, standards, controls, and best practices.
  • Work with Risk, Internal Audit, External Audit, and regulatory stakeholders during security reviews and audits.
  • Provide supporting documentation, technical clarification, and security evidence where required.
  • Influence stakeholders and drive appropriate remediation of identified security risks.

Key Responsibilities & Decision-Making

  • Review and approve security assessments for applicable technology projects and operational requirements.
  • Provide independent assessment and advisory on technical and process-related information security matters.
  • Recommend security controls and remediation approaches based on identified technology risks.
  • Escalate significant security risks and control gaps where appropriate.
  • Serve as a senior security reference point for technology and information security matters.

Requirements

  • Minimum 7+ years of progressive experience in Information Security, Technology Risk, IT Audit, Cybersecurity, or related functions.
  • Strong experience within financial services or other highly regulated industries is preferred.
  • Strong knowledge of authentication, authorisation, access controls, entitlement management, cryptography, encryption, network security, application security, system security, and key management.
  • Strong understanding of vulnerability management and application security frameworks, including OWASP and SANS.
  • Hands-on knowledge of SDLC, Agile, DevOps, and DevSecOps methodologies and their associated security requirements.
  • Strong understanding of Singapore information security, technology risk, and data protection requirements, including MAS TRM and PDPA.
  • Familiarity with industry frameworks and standards such as ISO 27001, NIST CSF, and MITRE ATT&CK.
  • Strong knowledge of API security and cloud security architecture, particularly within AWS and/or Azure environments.
  • Strong analytical and problem-solving skills with the ability to assess complex security risks and recommend practical solutions.
  • Excellent written and verbal communication skills with the ability to influence, advise, and negotiate with technical and business stakeholders.
  • Ability to independently drive security initiatives and provide guidance or mentorship to other team members.

Education & Certifications

  • Bachelor's degree in Information Security, Computer Science, Engineering, or a related discipline.
  • Advanced qualifications are advantageous.
  • Relevant industry certifications such as CISSP, CISM, CISA, SANS/GIAC, AWS Security, Azure Security, or equivalent recognised cybersecurity certifications are required.

Key Stakeholders

  • You will work closely with internal technology teams, business stakeholders, Risk, Audit, Architecture, Engineering, Development, and other Information Security functions.
  • External stakeholders may include technology vendors, professional service providers, auditors, and other approved third parties.

Team Structure

This is a senior individual contributor / SME role within the Technology Information Security Officer team, reporting directly to the Lead Technology Information Security Officer (TISO).

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against MyCareersFuture's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on MyCareersFuture's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    MyCareersFuture's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.