Conduct physical safety inspections of EPF buildings/branches to assess weaknesses that need to be improved.
Responsible for procuring approved budget items, planning and budgeting operational security equipment, developing and enhancing electronic security control systems, and maintaining security platforms including CAMS, ACTAS, CCTV, TSCM, and related technologies, including but not limited to AI-powered security control systems, maintaining enterprise platforms including advanced threat detection, identity and access management, and AI-driven analytics for anomaly detection and incident response.
Establish a network with the PDRM to ensure that security information is always up-to-date and maintain a high level of security.
...
Sales Presentations: Prepare and deliver persuasive proposals and presentations that highlight our trained personnel, technology integration, and response times.
Contract Negotiation: Lead the negotiation of contract terms, pricing, and service-level agreements (SLAs) to ensure a win-win partnership.
Pipeline Management: Maintain an accurate and up-to-date sales pipeline within our CRM to track progress and forecast revenue.
...
Interfaces and collaborate with other teams for incident escalations and resolution
Work closely with SOC Head to better security operations and address identified deficiencies
Perform due diligence and in-depth analysis on escalated security alert from Level-1 analyst and escalate to respective team for further action in timely manner
...
Provide independent, strategic IT security and risk advisory to the Group CTO, Senior Management, Board and relevant committees to enable informed risk‑based decisions
Establish, maintain and enforce Group IT Security policies, standards, and frameworks, ensuring consistent adoption across Head Office and regional offices
Champion and cultivate a strong security and compliance culture across technology and business stakeholders
...
Attend end-of-audit discussions with auditees to confirm findings, root causes, and agreed recommendations
Review draft audit reports to ensure all significant findings, their underlying risks, and impacts are properly reported with effective recommendations to strengthen internal controls
Monitor and follow up with auditees on the timely implementation of audit recommendations and address matters arising from deliberations at Management Audit Committee (MAC) meetings
...
Audit: Drive audit readiness by acting as a point of contact for all internal and external IT security audits and regulatory reviews (including BNM, HKMA, and MAS), ensuring the bank demonstrates high maturity levels and audit readiness at all times. Drive the end-to-end audit lifecycle including PCI-DSS and PwC engagements by coordinating evidence collection, justifying control effectiveness, and tracking all findings to verified closure to minimize compliance risks.
Projects & Change: Enable strategic IT security integration by participating in IT and Business project meetings. Conduct security reviews, risk assessments, and review User Acceptance Testing (UAT) to ensure all deliverables meet necessary security requirements with proper sign-off before deployment.
Housekeeping: Ensure a timely deletion and housekeeping of resigned, dormant, or unused user IDs based on HR cessation notifications to minimize the attack surface.
...
Perform event correlation and analysis to detect emerging threats and security anomalies.
Participate in cybersecurity incident response activities, including identification, containment, eradication, recovery, and post-incident reviews.
Conduct threat hunting activities to proactively identify malicious behaviors, attack techniques, and hidden threats within the environment. Support forensic investigations by collecting and analyzing logs, system artifacts, and security evidence.
...
Perform event correlation and analysis to detect emerging threats and security anomalies.
Participate in cybersecurity incident response activities, including identification, containment, eradication, recovery, and post-incident reviews.
Conduct threat hunting activities to proactively identify malicious behaviors, attack techniques, and hidden threats within the environment. Support forensic investigations by collecting and analyzing logs, system artifacts, and security evidence.
...
Investigate incidents: Conduct preliminary incident investigations to gather relevant information, document findings, and ensure accurate reporting of security incidents
Promote workplace safety: Encourage adherence to safety protocols and best practices among team members
Provide security back up: Step in to fulfill security officer responsibilities as required
...