jobs in Bond Financial Group

全职 Information Security Lead 工作, 薪水, Bond Financial Group 公司招聘中 - Ricebowl

Information Security Lead

Bond Financial Group

Undisclosed

Singapore

分享
保存

工作地点

  • Singapore

职位描述

岗位职责

The Information Security (InfoSec) Lead is a senior player-manager responsible for establishing and owning the information security policy framework and ISMS. This role leads ISO 27001:2022 certification, governs identity and access management, and ensures security standards are embedded across all engineering teams.


Key Responsibilities

Security Policy and ISMS Ownership

  • Establish and maintain the information security policy framework, ISMS risk register, risk treatment plan, and Statement of Applicability (SoA).
  • Lead the organisation through ISO 27001:2022 certification and ongoing surveillance audits; coordinate all departments on control implementation and evidence.
  • Conduct periodic policy reviews to ensure alignment with regulatory requirements and evolving threat landscapes.


Identity, Access and Secure Development

  • Design and implement IAM controls including SSO, MFA, and PAM; govern user provisioning and access review processes.
  • Define secure development standards (e.g. OWASP); conduct security architecture reviews with the Applications Lead.
  • Configure and maintain email security gateways and endpoint protection platforms.


Security Operations Oversight and Support

  • Provide strategic direction and escalation support to the Senior Security Engineer and SoC team.
  • Review security incident post-mortems and ensure effective remediation.
  • Manage security service providers and vendors, including MSSPs and penetration testing firms.
  • On-call availability is required to support 24x7 incident response coverage.


Requirements

Experience

  • 10+ years of progressive information security experience, with 3+ years in a lead or management role.
  • Demonstrated experience designing and implementing an ISMS and leading ISO 27001:2022 certification programmes.
  • Experience establishing IAM frameworks (SSO, MFA, PAM) and managing external audits and regulatory examinations.
  • Proven experience leading incident response, containment, and post-incident reviews in a production environment.
  • Experience managing MSSPs, penetration testing firms, and security tooling vendors; regulated industry background preferred.


Technical Skills

  • ISMS design and operation: risk register, SoA, control framework, continual improvement
  • IAM platforms: SSO (e.g. Okta, Azure AD or equivalent), MFA, PAM (e.g. CyberArk, BeyondTrust, or equivalent)
  • Secure development frameworks: OWASP, SANS CWE Top 25
  • Security architecture review methodologies and threat modelling
  • Email security gateways and endpoint protection platforms
  • ISO 27001:2022 control framework implementation across all domains


Qualifications

  • Bachelor's degree or higher in Information Security, Computer Science, or a related discipline.
  • CISSP or CISM strongly preferred.

重要安全守则

申请工作时,切勿提供您的银行或信用卡详细资料。不要转账或完成无关的在线调查问卷。如果您发现可疑内容,请举报此招聘广告。

了解更多