finseats

Singapore CISO, WRB & Markets Managing Directornew

Standard Chartered (StanChart) · Bank

  • Grade MD

Job Summary

Within Technology & Operations (T&O), the Information & Cyber Security (ICS) function is delivering a Target Operating Model within the ICS 1st line of defence to drive more accountability across our services, to optimise operations as well as to accelerate the delivery of risk reduction across the Bank. This will enable the ICS organisation to invest in new capabilities to stay ahead of evolving cyber threats and ensure the delivery of the Group ICS Strategy.


The CISO for WRB & Markets will lead the Wealth and Retail Banking (WRB) business alignment to the Group ICS Strategy, risk mitigation and remediation including maturing the 1st line ICS operating model. In addition, this role will assume responsibility for the ICS risk for the clusters / regions except for Europe & Americas. This will involve providing oversight over the relevant cluster CISOs and ensuring that the applicable markets are adhering to the risk management framework and associated processes in order to facilitate appropriate risk management.

Key Responsibilities

Strategy
•    Defining WRB & Markets / Countries Information and Cyber Security strategy and socialize to enhance awareness within WRB & Markets, working closely with WRB & Markets CIO and COO’s and countries CEOs
•    Determining key ICS threats and risks to WRB business and their mitigation plans
•    Supporting the business achieving its outcome considering ICS journey
•    Track and align ICS adoption and execution to the ICS risk reduction initiatives with key enterprise programmes (Obsolescence remediation, Cloud Adoption, etc.)
•    Identify and independently drive strategic change initiatives to deliver on the ICS agenda with a forward-looking view to support business growth areas 
•    Develop insightful strategies for engaging WRB & Markets on information security matters, ensure investments are prioritised and funding is approved.

 

Business
•    Support the WRB business to autonomously dynamically manage the ICS PRT within appetite
•    Heading the WRB ICS Program supporting WRB in risk remediation
•    Identify and manage ICS risk within the WRB business and represent ICS risk to WRB Risk Committee, Regional/Country Risk Forums/Committees and key in scope regulators/ industry bodies (as required)
•    Supporting WRB & Markets in ICS risk remediation
•    Supporting other Group Businesses (CIB - Corporate and Investment Banking) and Functions from a cluster / Markets perspective in meeting their risk reduction targets
•    Establish communication channels and information flows with Business, Regional and Country MTs, various first and second-line teams mobilised to deliver ICS risk reduction for WRB & Markets
•    Educate Senior executives regarding ICS Risks to drive accountability across the business
•    Accountability for operation of the ongoing risk framework including new and ongoing ICS obligations including regulatory requirements 

Processes
•    Accountable for WRB ICS and PCD program governance and assurance, including finance oversight
•    Focal Point for OTCR, GIA and external audit engagements regarding WRB & Markets ICS matters

 

People & Talent
•    Excellent organisation and leadership skills with ability to manage multiple deadlines and effectively prioritise
•    Exceptional engagement skills with ability to motivate and influence other leaders towards a collective positive outcome for the Business.
•    Excellent communication skills
•    Employ, retain, and develop WRB & Markets ICS talent with succession plans
•    Mature the 1st line ICS Operating Model for WRB & Markets. Ensure the right talent and skill sets are in place 
•    Provide leadership, management and coaching to direct reports to ensure they are highly engaged and performing to their potential.  
•    Ensure the 1st line ICS organisation is adequately resourced and staffed by competent staff to ensure successful delivery 
•   Maintain strong stakeholder engagement with Group, Cluster and Country IT, Function, COO, OCTR, Risk & Control stakeholders to bring alignment across stakeholder groups in conjunction with ICS risk management.

Risk Management
•    Responsible for ICS risk end-to-end on behalf of Group CISO.
•    Support CEO, WRB to dynamically manage the ICS PRT
•    Direct accountability and responsibility for ICS Risk and its management within appetite for the region and countries on behalf of Group CISO
•    Identity and assess ICS risks, including controls mitigation across NIST domain and SCB ICS Framework and prioritise remediation actions.
•    Deliver ICS risk reduction and mitigation working with OTCR, CISO and ICS domains.
•    Drive compliance of Group policies and standards across WRB and ensure that business take into consideration ICS regulatory requirements.
•    Recommend additions/enhancements/changes to the ICS policy, procedures, and RTF (Risk Type Framework)
•    Understand and assess the impact of changes in the policy or procedures on the respective Business / Cluster and engage with the respective Business / Cluster Heads to ensure the impact is understood.
•    Provide oversight over ICS control adoption and execution to the ICS risk reduction initiatives with key enterprise programmes (Obsolescence remediation, Cloud Adoption, Azure DevOPS, etc.)
•    Provide deep consulting expertise on complex projects, delivering workable and risk/threat-driven solutions
•    Provide thought leadership on emerging technologies and how they can be secured

 

Governance
•    Establish and drive ICS Risk Governance Forums for WRB & Markets
•    Ensure key risk and issues are monitored and appropriately addressed by key stakeholders
•    Govern ICS across WRB and report on progress to various committees
•    Lead 1st line ICS representation to Risk Committees, key regulators and industry bodies.

Regulatory & Business Conduct
•    Display exemplary conduct and live by the Group’s Values and Code of Conduct. 
•    Take personal responsibility for embedding the highest standards of ethics, including regulatory and business conduct, across the Bank. This includes understanding and ensuring compliance with, in letter and spirit, all applicable laws, regulations, guidelines and the Group Code of Conduct.
•    Lead WRB & Markets to achieve the outcomes set out in the Bank’s Conduct Principles 
•    Effectively and collaboratively identify, escalate, mitigate and resolve risk, conduct and compliance matters.
•    Engage external agencies / third parties to understand the threat environment and reported events; assess impact for the WRB domain

 

Key stakeholders
•    Group CISO
•    WRB / Clusters / Countries CEO
•    WRB / Clusters / Countries Risk Committee Members (Legal, Audit, Compliance, Conduct, Op Risk, Business Heads etc.)
•    OTCR
•    WRB / Clusters COO
•    WRB Global Head, Business Risk Management
•    WRB / Cluster CIO and LT
•    WRB / Cluster and Countries CIOs
•    WRB / Cluster and Countries COOs
•    WRB OTCR
•    ICS MT
•    T&O MT
•    CTOO Clusters

Our Ideal Candidate

•    Degree in Engineering, Computer Science/Information Technology, or equivalent
•    Understanding of the Cyber landscape and ICS Controls 
•    Proven ability to lead highly complex, global, pan-bank, multi-year programmes by driving collaboration and participation by functions, Regions and countries. 
•    Extensive change and programme management experience, ideally gained in the financial industry
•    Strong knowledge of the underlying technologies supporting Cyber Security capabilities
•    Experience in Information Security and Banking and Financial Services
•    Strong knowledge of ICS products and operations will be preferred
•    Strong knowledge of cyber security frameworks, information security principles, architecture, and cryptography
•    Exposure or hands-on experience in infrastructure / web application penetration testing and vulnerability assessments is preferred
•   Ability to articulate gross and residual risk with specific ability to clearly, concisely and accurately communicate complex technology and process risk to non-technical stakeholders in a lucid way
•    Strong interpersonal and stakeholder management skills, across various levels in the organisation including senior leadership teams, in influencing key decisions taken in the business and in support teams.
•    Strong communications – oral, written and presentation. Sound knowledge of MS Office Suite.
•    Must be a self-starter who is able to initiate and successfully drive programs and projects to completion with little or no management supervision
•    Strong analytical skills and ability to prioritise, make decisions, and work to tight timeframes.
•    Strong business acumen and deep knowledge and experience in the ICS field
•    Proven ability to lead complex, global activities through influence and credibility rather the command and control
•    Ability to both access strategic priorities and to focus on details aspects of a function in order to drive effective delivery.
•    Strong integrity, independence and resilience.

Certifications
•    One or more of the following certifications will be preferred:
o    Certified Information Security Manager (CISM)
o    Certified Information Systems Security Professional (CISSP)
o    SANS Global Information Assurance Certifications (GIAC)
o    Certified in Risk & Information Systems Control (CRISC)
o    Certified Information Systems Auditor (CISA)

About Standard Chartered

We're an international bank, nimble enough to act, big enough for impact. For more than 170 years, we've worked to make a positive difference for our clients, communities, and each other. We question the status quo, love a challenge and enjoy finding new opportunities to grow and do better than before. If you're looking for a career with purpose and you want to work for a bank making a difference, we want to hear from you. You can count on us to celebrate your unique talents and we can't wait to see the talents you can bring us.

Our purpose, to drive commerce and prosperity through our unique diversity, together with our brand promise, to be here for good are achieved by how we each live our valued behaviours. When you work with us, you'll see how we value difference and advocate inclusion.

Together we:

  • Do the right thing and are assertive, challenge one another, and live with integrity, while putting the client at the heart of what we do
  • Never settle, continuously striving to improve and innovate, keeping things simple and learning from doing well, and not so well
  • Are better together, we can be ourselves, be inclusive, see more good in others, and work collectively to build for the long term

What we offer

In line with our Fair Pay Charter, we offer a competitive salary and benefits to support your mental, physical, financial and social wellbeing.

  • Core bank funding for retirement savings, medical and life insurance, with flexible and voluntary benefits available in some locations.
  • Time-off including annual leave, parental/maternity (20 weeks), sabbatical (12 months maximum) and volunteering leave (3 days), along with minimum global standards for annual and public holiday, which is combined to 30 days minimum.
  • Flexible working options based around home and office locations, with flexible working patterns.
  • Proactive wellbeing support through Unmind, a market-leading digital wellbeing platform, development courses for resilience and other human skills, global Employee Assistance Programme, sick leave, mental health first-aiders and all sorts of self-help toolkits
  • A continuous learning culture to support your growth, with opportunities to reskill and upskill and access to physical, virtual and digital learning.
  • Being part of an inclusive and values driven organisation, one that embraces and celebrates our unique diversity, across our teams, business functions and geographies - everyone feels respected and can realise their full potential.

Related finance jobs