Report to: Chief Information Officer (CIO)
· Job content:
‒ Accountable for the IT Security management with significant country stakeholders; and working with the respective in-country CIOs and across the region / group.
Collaborate with peers in IT and the country partners for the delivery of goals for IT Security within country.
‒ Communicate IT Security technical controls and to drive IT security improvement / outcomes.
‒ Drive key IT Security implementations within the specific country.
‒ Be an ambassador for IT Security and driving IT Security controls, improvements and awareness.
‒ Act as first point of contact for any IT security requests from local Chief Information Officer, Chief Operating Officer, business etc.
‒ Validate and direct country specific requests to appropriate global contact point in IT Security.
‒ Address and help drive IT Security improvements in-country and across the region (risk management).
‒ Represent IT Security at the local IT and business risk committees to articulate the progress of key IT Security risk remediation projects.
‒ Lead / contribute to any local regulation or certification work (Internal or External Audit, etc.).
‒ Proactive awareness of IT Security regulatory requirements in-country.
‒ Participate in the IT Security community to share information and response to local issues, local regulatory requests, best practice etc.
‒ Establish a local IT Security governance meeting with the in-country CIO to proactively drive / address IT Security issues (monthly). This includes audit, regulatory, IT Security and other issues.
– Proactively identify key IT Security risks and control gaps and work to implement solutions to address the risk (group controls).
– Provide timely updates and education / awareness on how the IT Security programme is actively improving our maturity and how the projects contribute to the overall bank’s risk reduction.
– Proactive contribution across Asia Pacific for the support and improvement of IT Security processes and controls.
– Create a collaboration environment within the team, and externally with other teams (such as other related parties of Information Technology, Information Security Risk in Risk, Audit, etc)