jobs in FENGHE FUND MANAGEMENT PTE. LTD.

全职 Cyber Risk - Operations Manager 工作, 薪水 up to SGD 7,000, FENGHE FUND MANAGEMENT PTE. LTD. Central Region (Singapore) 公司招聘中 - Ricebowl

Cyber Risk - Operations Manager

FENGHE FUND MANAGEMENT PTE. LTD.

SGD7,000 - SGD7,000 每月

Central Region (Singapore)

分享
保存

工作地点

  • 6 BATTERY ROAD Central Region (Singapore) Singapore

职位描述

岗位职责

Company Background

We are a leading Asian investment firm withapproximately USD 13 billion in assets under management across our funds.Our flagship FengHe Asia Fund is recognised as one ofthe most consistent and best-performing long-short equity funds in Asia.

For more information, please visit *************


Role & Responsibilities

Managed Services Provider Oversight

  • Act as the firm's primary point of accountability for the outsourced IT provider's security and risk performance
  • Define, negotiate, and enforce SLAs, security requirements, and reporting obligations; review the outsourced IT provider's deliverables, reports, and evidence with acritical eye rather than accepting them at face value
  • Run structured service and risk review meetings with the outsourced IT provider; track open issues, remediation items, and commitments to closure
  • Independently validate the outsourced IT provider's work where warranted.  E.g., commissioning third-party penetration tests, reviewing vulnerability scan results, sampling access reviews, and challenging patching and configuration practices
  • Review the outsourced IT provider's assurance materials (SOC 2 reports, certifications, subcontractor arrangements) and assess residual risk to the firm
  • Ensure the firm retains adequate knowledge, documentation, and exit options to avoid unhealthy dependency on any single provider

Cyber Risk Management & Governance

  • Own the firm's cyber and IT risk framework: risk register, risk assessments, key risk indicators, and risk appetite reporting
  • Maintain the firm's information security policies and ensure the outsourced IT provider's operations comply with them
  • Report regularly to senior management (and the board/investors as required) on the firm's cyber risk posture, outsourced IT provider performance, and emerging threats

Incident Leadership

  • Own the firm's incident response plan; ensure the outsourced IT provider's incident processes integrate well with it
  • Lead the firm's response to any cyber incident.  Direct and coordinate the outsourced IT provider, brief executives in real time, manage legal/regulatory/insurer notifications, and own investor and counterparty communications
  • Run tabletop exercises involving both the firm and the outsourced IT provider at least annually; drive lessons learned into concrete improvements

Resilience & Awareness

  • Ensure business continuity and disaster recovery arrangements delivered through the provider meet the firm's recovery objectives and are validated through regular testing
  • Run the firm's security awareness program, including phishing simulations and targeted training for high-risk functions

Job Requirements

  • 7+ years in cyber security, technology risk, or IT governance, ideally including experience overseeing managed service providers or outsourced IT arrangements
  • Financial services background strongly preferred (hedge fund, asset manager, fund administrator, or investment bank); familiarity with the outsourced managed-IT model common among hedge funds is a significant advantage
  • Strong technical fluency across the domains typically delivered by an outsourced IT provider: cloud infrastructure, identity and access management, EDR/SIEM, vulnerability management, network security, and backup/DR architectures

Skills & Attributes

  • Sophistication and judgment: strong understanding of what effective security assurance looks like, with the ability to hold a large vendor to a high standard
  • Gravitas and communication: credibly represents the firm in front of investors, regulators, boards, and vendor executives; translates technical risk into commercial language
  • Exceptional attention to detail: thorough in reviewing assurance reports, technical evidence, and documentation, with a strong eye for gaps
  • Composure under pressure: leads decisively during incidents in a high-intensity environment
  • Strong vendor management skills: builds a productive, collaborative working relationship with the provider while maintaining clear accountability
  • High integrity and discretion: handles highly sensitive information appropriately

重要安全守则

申请工作时,切勿提供您的银行或信用卡详细资料。不要转账或完成无关的在线调查问卷。如果您发现可疑内容,请举报此招聘广告。

了解更多