Head of Information Security
Role Summary The Head of Information Security (CISO) is responsible for developing, implementing, and maintaining the organization's information security strategy, governance framework, and cybersecurity programs. This role ensures the confidentiality, integrity, and availability of company information assets while supporting business growth, regulatory compliance, and risk management objectives. Key Responsibilities Security Strategy & Leadership Develop and execute the organization's information security strategy and roadmap. Establish cybersecurity policies, standards, and procedures aligned with business objectives. Advise executive leadership and senior management on cybersecurity risks and mitigation strategies. Foster a security-aware culture across the organization. Governance, Risk & Compliance Lead the enterprise information security governance framework. Conduct regular risk assessments and maintain the organization's cyber risk register. Ensure compliance with applicable laws, regulations, and industry standards (e.g., ISO 27001, SOC 2, NIST, GDPR, PDPA). Manage internal and external security audits. Cybersecurity Operations Oversee security monitoring, threat detection, and incident response capabilities. Lead investigations into security incidents and coordinate remediation activities. Ensure effective vulnerability management, penetration testing, and security assessments. Drive continuous improvement of security controls and technologies. Security Architecture & Technology Provide strategic direction on security architecture, cloud security, identity and access management, data protection, and network security. Evaluate and implement security solutions to address emerging threats. Ensure secure design principles are embedded into business processes and technology initiatives. Third-Party & Vendor Security Establish processes to assess and monitor third-party cybersecurity risks. Review vendor security controls and contractual security requirements. Manage security due diligence for new partnerships and technology implementations. Business Continuity & Resilience Oversee cybersecurity aspects of business continuity and disaster recovery planning. Conduct cyber incident simulations and tabletop exercises. Ensure organizational readiness for cyber threats and disruptions. Team Leadership Build, mentor, and lead the Information Security team. Manage security budgets, resources, and vendor relationships. Define performance objectives and professional development plans for team members. Qualifications & Experience Required Bachelor's degree in Information Security, Computer Science, Information Technology, or a related field. 12+ years of progressive experience in cybersecurity, information security, IT risk, or related disciplines. 5+ years in a senior leadership or management role. Strong knowledge of cybersecurity frameworks, standards, and regulations. Experience leading security programs in a complex enterprise environment. Proven experience managing cybersecurity incidents and regulatory compliance requirements. Key Competencies Strategic thinking and business acumen Leadership and stakeholder management Risk management and decision-making Incident response and crisis management Strong communication and influencing skills Regulatory and compliance expertise Vendor and budget management