Cybersecurity Governance Lead, Financial Services
Our client is looking for a Security Governance Lead to drive the governance, risk and assurance function within its cybersecurity programme. This role will be responsible for establishing robust governance practices, ensuring regulatory compliance, maintaining an effective control environment, and providing independent oversight of enterprise cybersecurity risks.
Working closely with security engineering and operations teams, the successful candidate will ensure governance processes evolve alongside the organisation’s cybersecurity capabilities. Given the lean team structure, this role requires someone who is comfortable balancing strategic governance with hands-on execution.
职责
Security Governance & Policy
- Develop, maintain and continuously improve enterprise cybersecurity policies, standards and governance documentation.
- Establish governance processes to ensure policies remain current, effective and aligned with business and regulatory requirements.
- Develop operational procedures that enable consistent execution of governance and assurance activities.
- Partner with technology teams to ensure security requirements are embedded into day-to-day operations.
Technology Risk Management
- Manage the enterprise cybersecurity risk register, ensuring risks are appropriately assessed, tracked and remediated.
- Lead risk assessments across technology platforms, operational processes, cloud services and third-party providers.
- Oversee security exception governance, including compensating controls, approvals, review cycles and risk acceptance.
- Work with technology teams to translate identified risks into practical remediation plans.
Assurance & Regulatory Compliance
- Maintain alignment with applicable regulatory requirements and recognised cybersecurity frameworks.
- Design and manage a continuous control assurance programme through control testing, evidence validation and periodic reviews.
- Maintain an audit-ready evidence repository supporting internal audits, external assessments and regulatory reviews.
- Coordinate audit responses and oversee remediation activities arising from assurance engagements.
Third-Party Security
- Lead third-party cybersecurity due diligence covering technology vendors, software platforms and emerging technologies.
- Maintain oversight of supplier risk throughout the vendor lifecycle, including periodic reassessments.
- Partner with procurement and legal teams to strengthen contractual security requirements and supplier governance.
Reporting & Stakeholder Management
- Develop meaningful cybersecurity risk metrics, KRIs and governance dashboards for senior management.
- Support governance committees through agenda preparation, risk reporting and action tracking.
- Prepare executive updates covering cyber risk posture, compliance status and key security initiatives.
要求:
- 6-10 years of experience in cybersecurity governance, technology risk, compliance or information security assurance.
- Experience operating within a regulated environment with exposure to regulatory frameworks and technology risk management.
- Proven experience developing governance frameworks, managing enterprise risk registers and leading control assurance programmes.
- Strong experience preparing policies, audit responses, executive reporting and regulatory documentation.
- Good understanding of cybersecurity frameworks and enterprise risk management practices.
- Experience performing control testing, evidence validation and compliance assessments.
- Knowledge of third-party risk management and supplier security assurance.
- Familiarity with cloud security governance and emerging technology risks, including AI, would be advantageous.
申请
If you’re interested to apply or find out more, please share across your CV or reach out to Chen Yi at cy@kerryconsulting.com for a discussion. Due to anticipated high volume of applications, we regret to inform that only shortlisted candidates will be notified.
Reg: R1876389
Lic: 16S8060

An organisation operating within a large, complex and mission-critical environment is seeking an experienced leader to head its...
An international financial institution is seeking an experienced leader to head its local Information Security Coordination and...
The Head of Cyber Operations will lead the organisation’s cyber defence capability, overseeing 24×7 Security Operations, Threat Intelligence, Threat Hunting, Detection Engineering and Incident...
We are seeking an experienced and forward-thinking AI Security Engineering SME to lead the design, development, and implementation of enterprise-grade AI security solutions. This role sits at the intersection...
We are looking for an experienced Lead Data Security Engineer to design, implement, and enhance enterprise data security capabilities across on-premises and cloud environments. This...
We are seeking an experienced Head of IT & Cybersecurity to lead the strategy, operations, and continuous improvement of the organisation’s IT infrastructure and cybersecurity posture. This...
We are seeking a Cybersecurity Architect to join a lean and highly collaborative cybersecurity team. This role will be responsible for defining, designing, and driving the implementation of security...
We are partnering with a leading Singapore-based organization seeking a senior Application Security Architecture leader to drive secure-by-design practices, enterprise security architecture and AI security...
We are looking to hire a Cybersecurity Policy Developer to strengthen the organisation’s cyber governance and policy capabilities. This role sits at the intersection of cybersecurity strategy,...
Our client is seeking an experienced cybersecurity leader to drive enterprise security governance, technology risk and data protection...
A leading multinational organisation is seeking an experienced Security Architect to drive secure architecture and technology initiatives across a regional environment.
This role will be responsible...
The Head of Cyber Operations will lead the organisation’s cyber defence capability, overseeing 24×7 Security Operations, Threat Intelligence, Threat Hunting, Detection...
We are seeking an experienced and forward-thinking AI Security Engineering SME to lead the design, development, and implementation of enterprise-grade AI security solutions. This role sits at the intersection...
We are looking for an experienced Lead Data Security Engineer to design, implement, and enhance enterprise data security capabilities across on-premises and cloud...
We are seeking experienced Technology Risk & Controls lead to join the first-line governance and controls function within a highly regulated financial services environment....
In this role, you will be responsible for assessing, monitoring, and managing IT and cybersecurity risks associated with third-party vendors and service providers. You will work closely with cross-functional...
Industry: Multiple Sectors (Financial Services, Technology, Critical Infrastructure, Commercial and Others)
We are currently partnering...
A leading multinational organisation is seeking an experienced Security Architect to drive secure architecture and technology initiatives across a regional environment.
A leading global organisation is looking to hire a Technology Risk & Controls professional to support its enterprise technology environment. This role sits within the Technology function and works...
Our client is a leading organisation operating within a regulated environment, and is seeking an experienced Head of Cybersecurity and Technology Risk to lead its enterprise-wide technology risk and...
This is a hands-on cybersecurity role that sits across security engineering, operations, and design. The position focuses on strengthening the organisation’s security posture by embedding controls...
We are seeking an experienced and forward-thinking AI Security Engineering SME to lead the design, development, and implementation of enterprise-grade AI security solutions. This role sits at the intersection...
We are partnering with a leading Singapore-based organization seeking a senior Security Architecture leader to drive secure-by-design practices, enterprise security architecture...
