Posted on: 22/08/2026
Roles & Responsibilities :
- Governance : Accountability for the management of information security within the member firm, with the mandate from senior leadership, including strategy and planning, monitoring and maintenance, investments, projects and communication.
- Information Security Risk Management : Oversight of information security risk management through risk assessment, including approval of key risks, involvement in information security related escalations, review of contractual terms, response to client questionnaires and RFP, accountability for review of suppliers and acquisitions.
- Compliance to Policies and Standards : Responsibility for supporting ongoing information security compliance initiatives, including policies and standards related to information security, technology, data governance and privacy.
- Technology Approvals : Accountability for the review and approval of technology in relation to information security risks, including involvement and review of technology projects, approval of significant changes to technology environments, approval of cloud environments, and approval of Global Technology Standard exceptions.
- Security Operations : Accountability for security operations, working with technology teams to ensure that technical & information security compliance standards are met on an ongoing basis.
- Incident Management : Coordinates the local Member Firm incident response processes, including escalation to global (GSOC) where necessary and conducting readiness rehearsals within the member firm.
- Awareness : Accountability for security awareness training program within the member firm, including the coordination of phishing campaigns. Also, accountability for awareness of external threats through the management of Threat Intelligence relate to the member firm or cluster of member firms.
Educational Qualifications :
- Minimum Bachelor's degree in Computer Science, Information Technology or MCA.
- Hold industry standard accreditation or certifications (i.e., CISSP, CISM, ISO 27001).
- Be familiar with current data privacy regulations, including GDPR, DPDPA.
Work Experience :
- Should have a minimum of 13 years experience within information security and risk management.
- Have understanding and experience with Secure SDLC and DevSecOps or security automation.
Tech Stack & Expertise :
- Expertise in ISO 27001, NIST, SOC2, GDPR, DPDPA, and related frameworks.
- Experience with Cloud Security, DevSecOps, Security Automation, Identity & Access Management, and Security Governance.
- Professional certifications such as CISSP, CISM, or ISO 27001 preferred.
- Knowledge of cloud security and governance tools, cloud access security brokers (CASBs), and server virtualization technologies.
- Strong experience with Directories, SSO, Federation, Delegated administration, API gateways.
- Good understanding of cloud computing architecture, technical design and implementations, including Infrastructure as a Service (IaaS), Platform as a Service (PaaS) and Software as a Service (SaaS) delivery models.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1665285