EFG International Logo

EFG International

Information Security & BCM Head (Asia)

Posted 7 Days Ago
Be an Early Applicant
In-Office or Remote
Hiring Remotely in Singapore, SGP
Expert/Leader
In-Office or Remote
Hiring Remotely in Singapore, SGP
Expert/Leader
Lead regional information security and business continuity for Singapore and Hong Kong. Identify and mitigate regional risks, ensure regulatory compliance, manage incidents and BCM, oversee access governance, run security awareness programs, coordinate with Group CISO, and manage budgets and local security resources.
The summary above was generated by AI

General Info
-    Department: Global CISO
-    Work time Percentage: 100%
-    Location: Singapore ideally or Hong-Kong

Our Company
EFG International is a global private banking group, offering private banking and asset management services. We serve clients in over 40 locations worldwide. EFG International offers a stimulating and dynamic work environment and strives to be an employer of choice. 
EFG is committed to providing an equitable and inclusive working environment that is founded on the principle of mutual respect. Joining our team means experiencing a supportive environment, where your contributions are valued and recognised. We strongly believe that the diversity of our teams gives us a competitive advantage by fostering better decision-making and greater innovation.
 

Our Purpose and Mission
Empowering entrepreneurial minds to create value – today and for the future.

We are a private bank, offering personalised solutions on a global scale to private and institutional clients. Our sustainable success is based on our talents and on how we partner with our clients and communities to create lasting value.

Job Description
EFG’s Information Security and BCM team, led by the Group CISO, sets and coordinates global information security strategy, initiatives, and standards across EFG International. The team conducts security risk assessments, manages vulnerability and threat programs, and owns security awareness and training. It safeguards EFG’s infrastructure, applications, and data against breaches, malware, third‑party risks, and cyber-attacks. Additionally, it strengthens the bank’s defence through robust Business Continuity Management, supporting operational resilience and coordinated incident response

The Information Security & BCM Head Asia reports to the Regional COO with a functional line to the Group CISO, and will (i) identify regional risks, threats, and vulnerabilities across the SG and HK branches; (ii) address gaps against local laws, regulations, and industry practices; (iii) develop and tailor information security controls to the region’s risks, adapt policies and procedures to local culture and laws, and facilitate Group strategic initiatives; and (iv) ensure adherence to global Business Continuity Management policies while adopting BCM best practices per local regulatory requirements.

Main responsibilities
 

Strategy, governance, and leadership

  • Support and implement EFG’s information security strategy and programs, ensuring alignment with local business objectives.

    • Provide regional leadership on information security across SG and HK; serve as the Singapore and Hong Kong Information Security Officer.

    • Manage information security programs directed by Head Office and act as the primary contact for regulatory inquiries, reviews, and inspections.

    • Stay current on regulatory changes and industry trends; perform gap analyses on regulatory papers, circulars, and directives, and recommend improvements.

Risk management, compliance, and audit

  • Identify, evaluate, and manage regional information security risks and vulnerabilities; ensure preventative actions close risk gaps.

    • Conduct regular security assessments and audits to ensure compliance with internal, regulatory, and industry requirements; ensure timely closure of audit items.

    • Develop and maintain local security policies, procedures, and standards aligned with Head Office and regulators.

    • Collaborate on Operational Resilience and Business Continuity (BCP); act as local BCM referant ensuring internal and external requirements (e.g., HKMA OR-2) are met.

Incident management and monitoring

  • Lead and coordinate incident response locally and regionally in close collaboration with the Head Office CISRT, including investigation, root cause analysis, and treatment plans.

    • Review data security breaches, implement remediation, and design and lead the annual cyber-security incident drill for SG & HK.

    • Collaborate with Group Information Security to deploy monitoring tools safeguarding bank information.

Access governance and secure operations

  • Oversee timely completion of local and regional user access recertifications.

    • Approve and periodically review privileged access for business and IT users; recertify IT administrator and technical account access on locally and regionally managed infrastructure.

    • Serve as gatekeeper for data extraction from secure zones.

Stakeholder engagement, communications, and training

  • Build and maintain relationships with stakeholders, clients, leadership, regulators, and Head Office teams.

    • Monitor and manage security communications from Head Office and regulators.

    • Lead security awareness and training programs for employees and relevant stakeholders.

Technology, assessments, and continuous improvement

  • Support assessments for infrastructure and applications; perform periodic security reviews and audits.

    • Recommend enhancements to controls and processes based on emerging threats and best practices.

Reporting, budgeting, and resource management

  • Report timely status of projects, programs, risks, events, and incidents to the Group CISO.

    • Prepare spending proposals; manage local security budgets and resources effectively.


 

Skills and experience
•    Bachelor’s degree in Computer Science, Information Technology, or a related field.
•    10+ years in information security with strong knowledge of security principles, practices, and technologies.
•    Proven experience designing and implementing enterprise security programs.
•    Hands-on incident management and incident response expertise.
•    Demonstrated leadership, including managing and influencing virtual/remote teams.
•    Excellent communication and stakeholder engagement skills.
•    Successful track record working with regulators and regulatory bodies.
•    Experience in ICT Risk Management and Business Continuity.
•    Industry certifications (e.g., CISSP, CISM, CRISC) preferred.

Our Values
    Accountability: Taking ownership for tasks and challenges, as well as seeking continuous improvement
    Hands-on: Being proactive to rapidly deliver high-quality results
    Passionate: Being committed and striving for excellence
    Solution-driven: Focusing on client outcomes and treating clients fairly with a risk-aware mindset
    Partnership-oriented: Promoting collaboration and teamwork. Working together with an entrepreneurial spirit.
 

Please ensure to attach a cover letter to your CV when filling the application.
Application
Should you wish to apply for this position use this link to apply.
 

Similar Jobs

Entry level
Financial Services
Participate in an in-person business case challenge focused on operations, data analytics, and process improvement. Collaborate with other students to develop and present a creative group solution using analytical, critical-thinking, and problem-solving skills. Successful participants may receive priority consideration for the 2027 Corporate Analyst Development Program internship assessment center. The program develops foundational capabilities across analytics, project management, and process improvement.
Top Skills: MS Office
Senior level
Artificial Intelligence • Fintech • Payments • Business Intelligence • Financial Services • Generative AI
Lead and optimize offline acquiring operations (POS/terminal deployments, merchant onboarding, settlement, chargebacks). Design SOPs, drive automation, manage vendor relationships, monitor KPIs, ensure PCI and scheme compliance, and collaborate with Product, Risk, Sales, Finance, and Treasury.
Top Skills: Core Banking SystemsMastercardPayment Service PlatformsPci P2PePin PadsPos SystemsReceipt PrintersSettlement And Reconciliation ToolsTerminal ManagementVisa
10 Hours Ago
Remote or Hybrid
Senior level
Senior level
AdTech • Big Data • Digital Media • Marketing Tech
The Advertising Account Manager leads agency partnerships, focusing on digital ad optimization and performance growth through data insights and campaign execution.
Top Skills: ExcelGoogle Advertising PlatformMeta Advertising Platform

What you need to know about the Singapore Tech Scene

The digital revolution has driven a constant demand for tech professionals across industries like software development, data analytics and cybersecurity. In Singapore, one of the largest cities in Southeast Asia, the demand for tech talent is so high that the government continues to invest millions into programs designed to develop a talent pipeline directly from universities while also scaling efforts in pre-employment training and mid-career upskilling to expand and elevate its workforce.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account