Information Security Officer

  • Negotiable
  • Singapore Singapore Singapore SG
  • Permanent, Full time
  • Cavenagh Bridge , EA Licence No: 17S8504
  • 20 Apr 18 2018-04-20

Cavenagh Bridge were founded in Singapore in 2017 as a specialist Technology recruitment consultancy with a key focus on the FinTech & Tech Start-up domain in the Asia-Pacific region. We aim to work with high-quality permanent and contract professionals from around the world to match with our ever growing client base. We are a boutique recruitment business, with a tailored approach to match our passion for technology and market expertise.


  • Develop and maintain the APAC’s Information Security Management System (ISMS)to assure continuous compliance with regulations, laws and contractual obligations by adopting and deploying industry and market standards and accepted best practices.
  • Develop and maintain a security control framework to ensure that security management systems and policies are effective, providing recommendation and remediation.
  • Develop and maintain a standard security contract framework for ITO outsourcing to ensure a harmonised and consistent security control framework.
  • Develop emergency procedures and oversee incident responses as well as the investigation of security breaches and assist with disciplinary and legal matters associated with such breaches as required.
  • Develop and maintain a security awareness program to assure a widespread culture of information security awareness.
  • Manage the development and implementation of security policies, standards, guidelines and processes to ensure the ongoing maintenance of physical and logical security.
  • Participate in the security operational risk management activities as part of the Enterprise Risk Management to identify threats and institute appropriate security programs.
  • Conduct independent security audits and risk management assessments to verify and provide an opinion on the security posture.



  • Minimum of 5 to 10 years of experience in a similar role, i.e. in a combination role of security risk, information security and IT.
  • Proven experience in analysis, identifying, monitoring and controlling security risks
  • Experience in managing Identity / Access management, Intrusion Detection / Prevention, Data Protection and Data Leakage Prevention applications / devices including installation, configuration and its availability
  • Extended knowledge of relevant international security standards (ISO/IEC 27000-series), best practices (CobiT, ITIL), third party reporting (ISAE3402, SOC), trends and legal and regulatory requirements for data protection and outsourcing in the financial sector