ED, Cybersecurity Governance, Risk & Compliance Head, Information Security Services, Group Technology
DBS Bank Ltd
Group Technology enables and empowers the bank with an efficient, nimble, and resilient infrastructure through a strategic focus on productivity, quality & control, technology, people capability and innovation. In Group Technology, we manage most the Bank's operational processes and inspire to delight our business partners through our multiple banking delivery channels.
About the roleDBS operates a 3 Lines of Defence model for cybersecurity risk management. This role serves as Line 1, with responsibilities for driving regulatory compliance and governance, awareness and training and data protection for cybersecurity within the bank.
Cybersecurity Governance, Risk and ComplianceAs the 1st Line of Defence, the incumbent is responsible for driving the Bank’s compliance with the relevant cybersecurity legislation (e.g. Singapore’s Cybersecurity Act) and regulations (e.g. MAS).
The responsibilities include:
- Development of cybersecurity standards and guidelines,
- Assessment and validation of cyber risks and controls applic , and
- Reporting and providing assurance for the cybersecurity program to DBS risk committees.
The candidate is responsible for the development and delivery of the cybersecurity awareness and training program for the stakeholders within the Bank, including the design and development of targeted content to meet the training needs for the different roles in the Bank. The candidate is to continuously assess the efficacy of the training program, and improve and update the training content.
Data Protection ManagementThe incumbent will be responsible for the driving the data protection program including data loss management within the Bank. This includes the design of the data protection control environment, implementation and operations of the data protection technologies, and driving the data protection operations. The role also requires the candidate to drive the inhouse data analytics program to prioritize data loss events and identify potential misuse of the Bank’s applications and customer data. This role will be required to work closely with key stakeholders including the Enterprise Data Security and Data & AI Risk team.
Cybersecurity Governance, Risk and Compliance Responsibilities- Legislation, regulations and policies
- Review and assess the Bank’s cybersecurity policy architecture for compliance with new and emerging cyber security legislation, regulations and policies.
- Review and update information security standards to comply with the regulatory requirements as required
- Work with regional information security services teams in the core markets to monitor new cybersecurity legislation and/ or regulation, and assess the impact to and the compliance of the Bank’s security policy architecture
- Where necessary, work with Line of Business Technology units to drive change management to comply with the regulatory guidelines
- Security risk and compliance
- Work with key Line of Business Technology to manage material changes to critical systems, conduct risk control self assessment to assess key cybersecurity controls and risk areas and ensure continuous compliance with the cybersecurity legislation and regulations
- Engage Line of Business Technology units to conduct annual cybersecurity risk assessment for key bank systems as required under the prevailing regulations
- Engage external auditors and certification bodies to assess and audit key bank systems and control environment under the Cyber Trust Mark, ISO27000, SOC2 and Cybersecurity Act
- Focal point for international centres on information security matters
- Security metrics
- Develop and maintain a set of security metrics and visualization for the reporting of cybersecurity landscape to senior management and the Board
- Where possible, automate the extraction, transformation and loading of raw security events to generate the security metrics and graphs for the reporting
- Establish a framework to organize, manage and archive the security data used for the generation of security metrics and visualization
- Generate quarterly reports and insights to apprise senior management of the security trends and areas of concern
- Conduct regular phishing exercises and disseminate timely cybersecurity content to inculcate the cybersecurity hygiene and practices
- Develop targeted training content and collaborate with various control functions to deliver the content to meet the training needs for specific stakeholders
- Drive annual cybersecurity awareness campaign to promote cybersecurity culture and behavior
- Data Loss Prevention
- Design and implement data protection controls to mitigate the risk of data loss across various channels including web, email, network, endpoint etc.
- Work with Line of Business Technology to design and implement technology enablers to support the secure handling of Bank’s and customers’ data
- Review and investigate data loss events and refer substantiated events to HR for disciplinary actions
- Continuously review and enhance the data protection controls to improve the efficacy of data loss prevention
- Provide management reporting on data loss matters to the Bank’s risk committees.
- Unusual Employee Behavior Monitoring
- Drive the implementation of data analytics and machine learning techniques to
- Prioritize and highlight data loss events for review and investigation
- Identify suspicious activities and misuse of applications and customer data
- Oversee the inhouse development of the machine learning models and investigation platform
- Drive the development and implementation of data visualization techniques to improve the efficiency of the review and investigation process
- Drive the development and enhancement of the investigation platform to meet the users’ need
- Information security professional with 15 or more years of experience, with a background in a financial or technology environment.
- Experience in implementing a program the collation, management and reporting of security metrics such as open security vulnerabilities, penetration testing findings, security alerts and incidents, etc.
- Experienced in information security framework including ISO27000, NIST800-53 and regulations such as Cybersecurity Act, Technology Risk Management Guidelines and Personal Data Protection Act.
- Good working knowledge of enterprise security risk management methods and techniques to successfully deliver the security risk management and assessment outcome.
- Strong background on security technology solutions including IDS, IPS, anti-virus, content filtering, secure email solutions, network sniffing, log analysis, forensics and VPN
- Hands-on technical experience in the management of security data for the generation of security metrics and visualization
- Good working knowledge of data analytics, machine learning techniques and software development lifecycle
- Good verbal and written communication for the generation of security awareness content
- Proactive, analytical and independent worker with strong organization skills and performance-oriented, demonstrate effectiveness to track and follow up on the assigned projects
- Regional experience is a plus and the ability to travel on need-to basis
DBS Asia Hub
Job:Technology
Schedule:Regular
Employee Status:Full time
- ...Business Function Group Technology enables and... ...model for cybersecurity risk management. This... ...driving regulatory compliance and governance, awareness and... ...Data Security and Data & AI... ...Review and update information security standards... ...security services teams in the core...SuggestedFull time
- ...a specialized technical governance and risk management Specialist role... ...Architectural Risk & Compliance: Enforcing technical governance... ...in Computer Science, Information Technology, Engineering, or a related... ...relevant to the financial services industry, specifically regarding...SuggestedFull time
- ...part of OKG, a group that brings the... ...highly motivated Technology and Security Risk Manager within... ...Product, Risk, Compliance and Internal... ...assurance) and Cybersecurity (covering internal... ...enhancement of Governance, Risk, and... ...~8+ years in information security, with...SuggestedFull time
- ...Business Function Risk Management Group works closely with our business partners to manage the... ...Ensure integrity and accuracy of credit information prepared including but not limited to... ...risk infrastructure. Ensure compliance with all applicable credit policies and...SuggestedFull time
- ...Business Function Group Operations enables and empowers the bank with an efficient, nimble... ...on productivity, quality & control, technology, people capability and innovation. In Group... ...accurate and timely settlement processing. Risk Control, risk architecture and managed...SuggestedFull timeLocal area
- ...Mitsubishi UFJ Financial Group (MUFG), one of... ...in talent, technologies, and tools that empower... ...processes, governance frameworks, tools... ...You will oversee compliance activities in partnership... ...from Legal, Risk, Compliance, and... ...within financial services sector...Full timeFlexible hours
$150k - $220k
...leading Web3 security company focused... ...and AI-powered technology. Founded in 20... ...response, and compliance services for some of... ...and blockchain risk management. This... ...exchange, or government stakeholder. You... ...Officer, Head of Financial Crime... ..., genetic information, military and...Full timeContract workLocal area- ...Business Function Group Operations enables and empowers... ..., quality & control, technology, people capability and... ...managing operational risks & strongly... ...delivering excellent RED service to our customers. Responsibilities... ...inception, planning, information gathering and...Full time
- ...OKX is part of OKG, a group that brings the value... ...architecture for Payment Risk Operations - including... ..., engineering, and compliance teams to integrate risk... ...decision engines, modeling services, and risk analytics... ...from time to time, information on other sites may be...Full time
- ...infrastructure layer for financial services, and that BVNK is at the... ...: We’re looking for a Head of Risk – Singapore to lead risk... ...Reporting to our VP, Group Risk & Governance , you’ll be the senior risk... ...and teams across Risk, Compliance, Financial Crime, Legal, Product...Full timeLocal areaWorldwideFlexible hoursShift work
- ...quality & control, technology, people capability... ...innovation. In Group Operations, we manage... ...fixed income securities, including coupon,... ...activities. Ensure compliance with internal policies... ...potential risks and issues to management... ...deliver high service levels to all stakeholders...Full time
- ...strategically across the region, we are exposed to new and emerging risks that may have significant impact on a Country credit portfolio... ...events with requisite risk mitigation measures. Technology and Operational Process Acumen: Familiarity with Gen AI and Technology...Full time
- ...Bitdeer is a world-leading technology company for Bitcoin mining and... ...mining rigs, the Group handles complex processes involved... ...closely with Accounting, Finance, Compliance, IT/Security (for wallet and custody... ...Treasury Manager (Crypto) and Head of Back Office in process improvement...Full timeLocal area
- ...received from Product Team. ## Servicing of Reverse enquiry request from client... ...s approved list ## Ensure full compliance to all policies and regulations... ...On-time escalation of issues and risks to the Team leader or to the Department Head. ## Performs other duties that...Full time
- ...for every OK-er. OKX is part of OKG, a group that brings the value of Blockchain to... ...What You’ll Be Doing Plan and design risk monitoring and risk-related solutions for... ...third-party platforms from time to time, information on other sites may be inaccurate or outdated...Full time
- ...is part of OKG, a group that brings the... ...The Core Trading Risk Product team builds... ...parameter governance, agent-driven execution... ...Operations, Legal, Compliance, and regional... ...asset exchange, securities or futures exchange... ...from time to time, information on other sites...Full time
- ...About Bitdeer: Bitdeer is a world-leading technology company for Bitcoin mining and AI cloud.... ...and manufacturing mining rigs, the Group handles complex processes involved in computing... ...communication skills, strong sense of service,strong learning ability. Ability to...Full timeWork at officeLocal area
- ...related requirements, and other requests for information 4. Provide secretarial and... ...check, currency exposure, concentration risk, client restrictions, trades done, performance... ..., credit, operations, finance, compliance and controls. Good understanding of financial...Full time
- ...making transactions secure, simple, smart and accessible. Our technology and innovation,... ...set of products and services that help people, businesses and governments realize their... ...communication of risks and opportunities.... ...Mastercard assets, information, and networks comes...Full timeWorldwide
- ...Bitdeer is a world-leading technology company for Bitcoin... ...mining rigs, the Group handles complex processes... ...while maintaining strong governance and compliance. The Treasury Manager also supports the Head of Back Office on... ...internal/external audit and risk management reviews....Full timeLocal area
- ...Business Function Risk Management Group works closely with our business partners... ..., providing project governance and support, and delivering... ...financial requests from Credit heads and external stakeholders.... ...significant amounts of information with attention to detail and...Full timeWork experience placementWork at office
- ...opportunity to join DBS’ Group Tax team and build a... ...banking and financial services industry. You will be... ...for cross-border tax compliance and advisory matters to... ...processes, strengthen governance frameworks and proactively... ...operational tax risks. Support the Bank's...Full timeLocal area
- ...Mitsubishi UFJ Financial Group (MUFG), one of the... ...investing in talent, technologies, and tools that empower... ...source and share market information with GAFO on AF’s... ...that the transactions' risk profile fit the Bank's... ...monitor and ensure credit compliance for executed...Full timeWork experience placement
- ...Business Function Group Finance aims to deliver world-class standards... ...tax and accounting advisory services. The bank is also a... ...timely and accurate financial information for internal and external reporting... ...performance Ensure compliance with regulatory and statutory...Full timeWork experience placement
- ...As the Global Head of Financial Crimes Compliance, you are the architect... ...implement a group-level AML/CFT... ...of payments services, cards, and emerging... ...a consistent risk appetite across... ...Strategy & Governance: Develop and implement... ...: [ For more information visit [...Full timeLive inWork at officeLocal areaWorldwideFlexible hours3 days per week
- ...leverages cutting edge technology to offer liquidity to... ...offers in over 19,000 securities, at over 235 venues, in... ...traders, finance, compliance, brokers, custodians,... ...avoidance of unanticipated risk to both the firm and... ...detail and a customer service attitude YOU’RE JUST...Full timeWork experience placementWorldwideEarly shift
- ...infrastructure layer for financial services, and that BVNK is at... ...We’re looking for a Compliance Manager – Singapore to... ...submissions, information requests and examinations... ...Compliance, Legal, Risk, Financial Crime, Product... ...regulatory reporting, governance and documentation,...Full timeLocal areaWorldwideFlexible hoursShift work
- ..., transactional legal work, or a combination at a fast-growing technology company. ~ Strong proficiency drafting, reviewing, and negotiating... ...legal work. ~ Strong commercial judgment to balance legal risk against speed, customer needs, and business priorities. ~...Full timeWork at officeVisa sponsorshipRelocation package
- ...to work with Management from Head Office in Singapore as well as... ...efficiency as well as controls and risk management. 2. Engaging the... ...partners across business and technology lines throughout the bank to... ...relationships with major vendors and service providers. Engage in...Full timeTemporary work
- ...er. OKX is part of OKG, a group that brings the value of Blockchain... ..., partnering with the user risk team on high-risk user... ...improving partner engagement and service quality. ~ Strong data and... ...platforms from time to time, information on other sites may be inaccurate...Full timeLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to ED, Cybersecurity Governance, Risk & Compliance Head, Information Security Services, Group Technology. Be the first to apply!

