SL2705 - Technology Information Security Officer (TISO)

FPT ASIA PACIFIC PTE. LTD.Singaporemycareersfuturepaskelbta 2026-10-07
Privaloma:AWSAzureCloudDevOpsAgileSecuritySeniorLead

About the Role

We are looking for an experienced Technology Information Security Officer (TISO) to provide security assessment, advisory, and oversight across technology initiatives and business applications.

As a senior individual contributor and Subject Matter Expert (SME), you will ensure that secure-by-design, secure-by-default, and secure operations principles are embedded across the organisation.

You will work closely with development, architecture, project, and technology teams to integrate security throughout the Software Development Life Cycle (SDLC), identify technology risks, recommend appropriate security controls, and ensure alignment with regulatory and industry requirements.

Key Responsibilities

Security Assessments & Risk Management

  • Conduct comprehensive technical security assessments to identify security risks, control gaps, and vulnerabilities.
  • Perform information security risk assessments for business applications throughout the development lifecycle.
  • Assess projects operating under SDLC, Agile, Iterative, DevOps, and DevSecOps methodologies.
  • Identify and communicate significant information security risks and control gaps.
  • Recommend appropriate technical and process controls to mitigate identified risks.
  • Review and approve security assessments for relevant projects and operational requirements.

Application & SDLC Security

  • Serve as a Subject Matter Expert for security throughout the application development lifecycle.
  • Provide security advice to development, engineering, architecture, and project teams.
  • Assess security requirements and controls throughout application design, development, testing, deployment, and operations.
  • Ensure security requirements are incorporated into application and system designs from the beginning.
  • Promote secure-by-design and secure-by-default practices across technology initiatives.
  • Support the implementation of security controls to strengthen application and SDLC security.

Security Architecture & Controls

  • Provide guidance across key security domains including authentication, authorisation, access control, entitlement management, cryptography, encryption, network security, application security, system security, and key management.
  • Assess API security and cloud security architectures across AWS and Azure environments.
  • Review vulnerability management practices against recognised frameworks and industry standards.
  • Provide independent technical security assessments and recommendations on proposed technology solutions.

Security Governance & Continuous Improvement

  • Drive initiatives to strengthen information security processes, policies, standards, and controls.
  • Promote information security best practices across technology teams.
  • Ensure security practices remain aligned with applicable regulatory requirements and industry frameworks.
  • Identify opportunities to improve security governance, assessment processes, and overall technology risk management.
  • Support the continuous improvement of the organisation's information security capabilities.

Stakeholder Management

  • Collaborate with domain architects, project managers, developers, engineers, and technology Subject Matter Experts.
  • Provide clear security guidance and help stakeholders understand their information security responsibilities.
  • Promote awareness of information security policies, standards, controls, and best practices.
  • Work with Risk, Internal Audit, External Audit, and regulatory stakeholders during security reviews and audits.
  • Provide supporting documentation, technical clarification, and security evidence where required.
  • Influence stakeholders and drive appropriate remediation of identified security risks.

Key Responsibilities & Decision-Making

  • Review and approve security assessments for applicable technology projects and operational requirements.
  • Provide independent assessment and advisory on technical and process-related information security matters.
  • Recommend security controls and remediation approaches based on identified technology risks.
  • Escalate significant security risks and control gaps where appropriate.
  • Serve as a senior security reference point for technology and information security matters.

Requirements

  • Minimum 7+ years of progressive experience in Information Security, Technology Risk, IT Audit, Cybersecurity, or related functions.
  • Strong experience within financial services or other highly regulated industries is preferred.
  • Strong knowledge of authentication, authorisation, access controls, entitlement management, cryptography, encryption, network security, application security, system security, and key management.
  • Strong understanding of vulnerability management and application security frameworks, including OWASP and SANS.
  • Hands-on knowledge of SDLC, Agile, DevOps, and DevSecOps methodologies and their associated security requirements.
  • Strong understanding of Singapore information security, technology risk, and data protection requirements, including MAS TRM and PDPA.
  • Familiarity with industry frameworks and standards such as ISO 27001, NIST CSF, and MITRE ATT&CK.
  • Strong knowledge of API security and cloud security architecture, particularly within AWS and/or Azure environments.
  • Strong analytical and problem-solving skills with the ability to assess complex security risks and recommend practical solutions.
  • Excellent written and verbal communication skills with the ability to influence, advise, and negotiate with technical and business stakeholders.
  • Ability to independently drive security initiatives and provide guidance or mentorship to other team members.

Education & Certifications

  • Bachelor's degree in Information Security, Computer Science, Engineering, or a related discipline.
  • Advanced qualifications are advantageous.
  • Relevant industry certifications such as CISSP, CISM, CISA, SANS/GIAC, AWS Security, Azure Security, or equivalent recognised cybersecurity certifications are required.

Key Stakeholders

You will work closely with internal technology teams, business stakeholders, Risk, Audit, Architecture, Engineering, Development, and other Information Security functions.

External stakeholders may include technology vendors, professional service providers, auditors, and other approved third parties.

Team Structure

This is a senior individual contributor / SME role within the Technology Information Security Officer team, reporting directly to the Lead Technology Information Security Officer (TISO).