AI, Governance & Incident Management Lead - Tech Security Operations
Liberty Specialty Markets AI, Governance & Incident Management Lead - Tech Security Operations
Job Summary:
We're hiring a multi-disciplinary cybersecurity professional to own security operations, incident management, GRC, and AI-driven automation across our APAC insurance markets — running penetration tests, coordinating incident response with the global CSOC, bridging APAC threat intelligence, leading local regulatory procedures, and building AI/automation solutions that scale security operations regionally. You'll work with market CISOs and global policy owners to translate global standards into procedures that satisfy local regulators while staying enterprise-aligned, using AI and automation to reduce manual effort and speed detection and response.
Markets & Regulators: Singapore (MAS), Hong Kong (HKIA), Australia (APRA), Malaysia (BNM), China (NFRA), India (IRDAI)
Job Responsibilities:
Penetration Testing & Offensive Security — Plan and execute pen tests across web/API, mobile, cloud, and network environments; run purple team exercises with the CSOC; document findings with remediation guidance and verify fixes; manage external pen-test vendors, including regulator-mandated testing (APRA CPS 234, MAS TRM); explore AI-assisted tools for vulnerability discovery and attack path analysis.
Incident Response & Coordination — Act as APAC's regional incident coordinator through triage, containment, eradication, and recovery; drive incident bridges and post-incident reports; maintain IR runbooks reflecting each regulator's notification timelines (MAS 1-hour, APRA CPS 234, HKIA, BNM, NFRA, IRDAI); partner with Legal, Compliance, and Privacy on regulatory submissions; maintain a full incident evidence trail and use AI-powered triage/correlation to reduce MTTR.
Threat Intelligence & CSOC Liaison — Serve as the two-way link between APAC markets and the global CSOC/threat intel teams; curate and share region-specific threat intelligence; escalate local indicators and emerging threats; build relationships with peer organizations, ISACs, CERTs, and law enforcement across APAC.
AI & Security Automation — Design and implement AI/automation use cases using SOAR platforms, Python/PowerShell, and low-code tools (Power Automate, Logic Apps); build AI/ML solutions for threat detection, anomaly identification, alert enrichment, and predictive risk scoring; integrate LLMs/GenAI for report generation, drafting assistance, and natural-language querying; automate log analysis, alert triage, phishing analysis, vulnerability correlation, and compliance monitoring/evidence collection; build CISO dashboards and AI-driven user behaviour analytics; ensure all deployments meet AI governance requirements (e.g., MAS FEAT) with documented models and drift/bias monitoring.
Governance, Risk & Compliance — Develop and version-control local procedures/SOPs per market against global policy baselines; perform gap analyses and maintain a traceability matrix to policies and regulatory clauses; track and interpret requirements from MAS, HKIA, APRA, BNM, NFRA, and IRDAI via a per-market regulatory obligations register; drive closure of audit/regulatory findings through to evidence and sign-off; coordinate regulatory inquiries, audits, and incident notifications, keeping programs continuously audit-ready.
Stakeholder Engagement & Reporting — Partner with market CISOs on the security, automation, and compliance roadmap; report periodically on posture, findings, incident trends, automation ROI, and compliance status; coordinate across CSOC, threat intel, GRC, AI/ML, IT, Legal, HR, and risk functions; escalate blockers with decision-ready context; support training and rollout of new procedures/workflows.
Job Requirements:
7+ years combined experience across penetration testing, incident response, security operations, or GRC; Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience)
Hands-on offensive security skills (web/API, network, privilege escalation, post-exploitation) with tools such as Burp Suite, Metasploit, Cobalt Strike, Nmap, BloodHound, and SIEM/SOAR/EDR platforms
Solid grasp of the IR lifecycle (NIST 800-61) with experience coordinating incidents end-to-end, and experience building automation workflows (SOAR, Python/PowerShell) and drafting policies/SOPs in a regulated industry
Working knowledge of the APAC threat landscape (MITRE ATT&CK, Diamond Model) and one or more regulators/frameworks: MAS (Notice 655/127, TRM), HKIA (GL20), APRA (CPS 230/234), BNM (RMiT), NFRA, IRDAI
Familiarity with control frameworks (ISO 27001, NIST CSF, SOC 2, COBIT) and experience translating gap assessments into remediation plans
Excellent executive/technical/regulator communication and stakeholder management across cultures, time zones, and seniority levels; highly organized across parallel market workstreams
Nice to Have
Certifications (OSCP, OSEP, CISA, CRISC, CISM, CIPP/A, ISO 27001 LA/LI) or AI/ML certifications (Microsoft AI Engineer, Google ML Engineer)
AI/ML in cybersecurity (LLMs, NLP, anomaly detection), SOAR platforms (XSOAR, Splunk SOAR, Microsoft Sentinel), and GenAI integration (Copilot for Security, OpenAI APIs); familiarity with AI governance frameworks (MAS FEAT, Singapore Model AI Governance Framework, OECD AI Principles)
Insurance/financial services background; cloud security/IR experience (AWS, Azure); experience with regulatory notifications, inspections, and thematic reviews
Experience harmonizing security/GRC frameworks across countries; infrastructure-as-code/DevSecOps exposure
Skills
- AI
- Analytics
- Anomaly Detection
- API
- Automation
- AWS
- Azure
- Burp Suite
- Cism
- Cloud
- Cloud Security
- Cybersecurity
- DevSecOps
- EDR
- Generative AI
- Infrastructure as Code
- ISO 27001
- LLM
- Machine Learning
- Metasploit
- Nist
- NLP
- Nmap
- OpenAI
- Penetration Testing
- Power Automate
- PowerShell
- Python
- SIEM
- SOC 2
- Splunk
- Stakeholder Management
- Version Control