Job purpose:
This position is part of the Asia information Security and Data Protection function in Singapore with focus on data loss prevention (DLP) and data protection (DP).
Key activities:
- Serving as the primary point of contact for authorities and stakeholders regarding compliance with Data Loss Prevention (DLP) regulations and the support to data protection (DP).
- Maintaining data protection policies, procedures, and guidelines, monitoring compliance with data protection laws and regulations and data loss prevention related requirements and ensuring appropriate measures are in place.
- Conducting data protection impact assessments (DPIAs) to identify and mitigate risks associated with the processing of personal data.
- Collaborating with IT, legal, HR, and other departments to ensure data protection considerations and controls are integrated into business processes and systems.
- Investigating incidents and breaches related to data loss, breach, or unauthorized access.
- Collaborating with internal teams to integrate DLP solutions with existing infrastructure and security systems. e.g. management of DLP policy and ruleset
- Providing advice, guidance, and training to employees on data protection requirements, best practices, and data breach procedures
- Assisting the Head of Information Security Asia and Data Protection officers in developing and delivering reports to senior management on the organization's data loss prevention and data protection compliance status
- Collaborating with auditors to provide necessary documentation, evidence, and support during audit fieldwork, testing, and reporting phases.
- Reviewing audit findings, recommendations, and reports to identify opportunities for improving information security practices, processes, and controls.
Formal education:
- University or college degree or comparable
- Possession of professional qualifications will be advantageous. e.g. CIPM, CIPP, CISA, CISM, CISSP, CRISC, PMP
Specialist knowledge (work experience, further qualification):
- Minimum 5+ years of related experience in Data Protection, Data Loss Prevention or technology Risk function in financial services industry or consultancy
- Extensive knowledge of the regulatory environment and data protection laws within the Asia region. PDPC, MAS, NAFR, PBOC, JFA
- Experience in cybersecurity, risk management, and familiarity with DLP technologies would be an advantage.
- Strong analytical skills, with the ability to breakdown complex problems into actionable and understandable steps.
- Strong communication, stakeholder management and problem-solving skills are essential.