The posting
Key Appointments
· The Technical Information Security Officer (TISO) role is crucial to our security resilience. This SME individual contributor position is the backbone of our Technical Information Security functions, ensuring that robust security measures are not just implemented but ingrained within client and its subsidiaries.
· The TISO ensures secure by design, secure by default, and secure operations principles are integrated into critical decisions. The TISO partners with development and project teams to embed security into every phase of the Software Development Life Cycle (SDLC) and foster a culture of shared security responsibility.
Key Responsibilities
1) Oversights in Technical Assessments and Recommendations
a) Conduct meticulous and comprehensive technical assessments of security controls, leaving no stone unturned in identifying critical gaps and providing strategic recommendations.
b) Perform technical information security risk assessments on business applications throughout the development lifecycle, including SDLC, Agile, and Iterative methodologies.
c) Identify and report significant information security issues and gaps, providing technical-level recommendations for risk mitigation.
2) Act as the Subject Matter Expertise in Application Development Lifecycle:
a) Provides expert advice in assessing security requirements and controls throughout the application development lifecycle.
b) Ensure strategic planning and implementation of security controls to enhance development lifecycle security.
3) Driving Strategic Improvements in Information Security:
a) Drive improvement initiatives to enhance information security processes, standards, and policies.
b) Advocate for the promotion of information security best practices, ensuring alignment with relevant regulations and frameworks.
4) Strategic Stakeholder Engagement and Collaboration
a) Collaborate with domain architects, project managers, and IT subject matter experts to foster a collective security culture.
b) Raise awareness of the organization’s information security policies, standards, and best practices among stakeholders.
c) Interface with Risk, Internal Audit, External Audit, and regulatory bodies during audits to provide support and facilitate smooth audit processes.
d) Ensure stakeholders understand their strategic roles and responsibilities concerning information security, fostering a culture of accountability.
Key Decisions within the Role
· Approve security reviews for all relevant projects and operational requirements.
· Provide independent assessment and advisory on all information security matters, both technical and process-related, serving as a knowledgeable reference source for security matters within the organisation.
Requirements
1) Experience
a. Minimum of 7+ years of progressive experience in Information Security, Audit, or Risk Management roles, with significant exposure in financial services or similarly regulated industries.
b. Good command of Information Security control areas including Authentication/Authorization, Access Controls, Entitlement, Cryptography, Encryption, Network, Application/System Security, and Key Management. In-depth knowledge of Vulnerability Management frameworks(OWASP, SANS) is essential.
c. Proficiency in SDLC, Agile/Iterative, DevOps/DevSecOps methodologies, and their integration with comprehensive security assessments.
d. Demonstrated understanding and application of the Singapore regulatory framework, local laws concerning information security, technology risk, and data protection (e.g., MAS TRM, PDPCPDPA).
e. Strong familiarity with global standards such as ISO-27001, NIST CSF, MITRE ATT&CK, and their practical application.
f. Expertise in API Security and Cloud Security architectures, particularly in AWS or Azure environments.
g. Exceptional written and verbal communication skills, with a proven ability to influence and negotiate effectively. Keen attention to detail with strong problem-solving and analytical abilities.
h. Demonstrated capability to lead and mentor teams, with a track record of driving strategic initiatives independently.
2) Education
a. University degree in Information Security, Computer Science, Engineering, or a related field. Advanced degrees and relevant certifications are preferred.
3) Certification
a. Relevant Information Security Industry qualifications / certifications such as CISSP, CISM, CISA, relevant SANS certifications, Cloud certifications (AWS/Azure), or equivalent industry-recognized qualifications are mandatory.



