The aspiring candidate will have the following responsibilities: -
Ensure that Circles and its group entities always maintain a robust, sustainable and adequate governance practices and compliance which spans across.
• [Governance] Develop, mature and operationalize cybersecurity framework, policies, procedures, guidelines and baseline standards within the Group.
• [Governance] Ensure cybersecurity best practices are embedded within new initiatives, ongoing change management and evaluate the security impact of the initiatives.
• [Governance] Identify, risk assess and drive adoption of administrative, technical and procedural measures to safeguard the information assets across the Enterprise.
• [Assurance] Ensure organizational crown jewels are adequately protected in accordance with regulatory and data protection regulations such as ISO27701, PCI-DSS, Market specific Data Protection regulations including PDPA, GDPR.
• [Assurance] Drive internal Risk Assessment including 3rd Party Due Diligence (3PDD) reviews, cybersecurity assurance activities, as well as audit readiness reviews and drive timely resolution of potential gaps.
• [Assurance] Proactively support in organizational roadmap towards maintaining relevant credentials including ISO27001 compliance, DPTM, APEC CBPR and establishing SOC2 compliance report.
• [Data Protection] Develop data privacy and protection framework, enhance existing policies and work programs to align with expectation of relevant data privacy laws.
• [Data Protection] Support the day-to-day functioning of the Data Privacy Office by:
•
Serving as a point of contact within group on issues related to data privacy & protection;
•
Support privacy impact assessments, maintain records of processing activities; Serving as subject matter expert to stakeholders on privacy and data security matters; and
•
Participate in investigation of data privacy incidents.
• [Data Protection] Drive cybersecurity and privacy awareness within the Group, formulating learning curriculum, rolling out training modules ensuring completion remains above agreed metrics. Devise focused training across staff who are involved in data handling and processing.
• [Data Protection] Promote a culture of Security, information protection and compliance mindset across the Group.
• [Artificial Intelligence] Drive relevant and necessary initiatives to enable the stakeholders to adopt artificial intelligence related initiatives in an ethical and responsible manner.
• [Advisory] Provide advisory services on information security, privacy and cybersecurity matters for internal stakeholders as laid out in subsequent sections.