Assistant Information Security Manager
1 day ago
PURPOSE
Minimize and mitigate the risk and protect the organization’s information against a variety of cyberthreats (cyberattacks; theft or corrupti..
PURPOSE
Minimize and mitigate the risk and protect the organization’s information against a variety of cyberthreats (cyberattacks; theft or corruption from within; etc.), in line with FWD’s risk enterprise risk management framework.
KEY ACCOUNTABILITIES
- Works with IT teams and business functions to make sure that security tools and monitoring applications are compliant with security standards.
- Ensure IT operations and activities comply with Information Security standards set by FWD Group and regulatory standards as required by the Monetary Authority of Singapore (MAS).
- Analyze periodic vulnerability scan reports and collaborate with IT and business stakeholders to remediate identified vulnerabilities promptly. Monitor security patches, updates, exceptions and ensuring timely application across the organization’s systems.
- Analyze hardening configuration reports and collaborate with different stakeholders to remediate identified gaps. Monitor compliance and track exceptions as needed.
- Review and analyze data generated from other Information Security tools and follow-up for remediation action.
- Investigate security alerts and incidents, analyze root causes, and track corrective actions to closure.
- Assist in developing and enforcing security policies, standards, and guidelines.
- Analyze and collaborate with different stakeholders ensure security metric data is complete and accurate.
- Perform periodic Information Security controls as per FWD policies and regulatory compliance bodies (such as hardening configuration review, log reviews, user access review, etc.)
- Collaborate with Group Information Security Team on the various Information Security projects initiatives.
- Collaborate with business functions to ensure employees are aware & trained about cybersecurity issues & practices.
- Other Information Security tasks as required.
QUALIFICATIONS / EXPERIENCE
- Diploma or Degree in IT, Computer Science or equivalent
- At least 5 years experience
- Relevant certifications (e.g., CC, CISSP, CISM, CEH) or strong desire to obtain those certifications are advantageous.
KNOWLEDGE, SKILLS & ABILITY
- Strong analytical skills, attention to detail, and problem-solving abilities.
- Technical skills and hands-on experience with Information Security related solutions considered an asset.
- Good understanding of Cyber Security, IT networking, Windows OS, technical troubleshooting, and problem solving.
- Awareness and understanding of common exploits and vulnerabilities, system hardening and cloud architecture.
- Good communication and analytical skills.
- Sound knowledge of Information Security management frameworks and guidelines such as NIST, ISO 27001, CIS baselines & best practices.
Official account of Jobstore.