Deputy Director (Information and Communication Technology)
Deputy Director (Information and Communication Technology)
• Lead the ICT function independently and ensure that the ICT team delivers agreed objectives in alignment with the organisation's business direction and strategy.
• Develop, own and execute the organisation's ICT strategy, annual operating plan and technology roadmap, with clear priorities, timelines, responsibilities and measurable outcomes.
• Oversee the reliable, secure and efficient operation of the organisation's ICT infrastructure, including enterprise networks, LAN/WAN/Wi-Fi, firewalls, VPN, servers, cloud platforms, storage, backup, identity and access management, end-user computing and monitoring tools.
• Own the ICT change, release and configuration management processes for infrastructure, applications, equipment and facilities to minimise service disruption and operational risk.
• Establish and maintain resilient ICT architecture with appropriate capacity, redundancy, high availability, disaster recovery and business continuity arrangements.
• Ensure compliance with applicable laws, regulatory requirements, contractual obligations and internal governance standards relating to ICT, cybersecurity and data protection.
• Develop, maintain and enforce ICT, cybersecurity, access-control, data-protection and operational policies, procedures, standards and registers.
• Partner with business unit heads to review processes, define requirements, evaluate applications and vendors, and oversee system selection, implementation, integration and adoption.
• Own and manage the ICT project portfolio, ensuring that projects are properly scoped, governed and delivered on time, within budget and in accordance with agreed business, security and operational requirements.
• Lead technology risk assessments, resolve project and operational issues, maintain effective stakeholder communication, and escalate significant delays, incidents and risks promptly to the CFO/CTO
• Identify and implement practical technology innovations, automation and digital improvements that enhance business effectiveness, service delivery and cost efficiency.
• Act as Deputy Data Protection Officer and independently manage operational PDPA compliance, including data inventories, retention requirements, data- protection impact assessments, incident and breach assessments, vendor data-processing reviews, staff awareness and required escalation or regulatory notification.
• Act as the Management Representative for ISO27001 and independently manage the ISMS, internal audits, management reviews, surveillance and recertification audits, risk assessments, Statement of Applicability, audit evidence, non-conformities and corrective actions.
• Manage ICT financial resources, assets, licences, contracts and operations effectively, with appropriate controls over procurement, lifecycle management, utilisation and cost.
• Prepare and manage the annual ICT budget, business cases and investment proposals, and track expenditure, commitments, savings and benefits against approved plans.
• Set clear individual and team objectives, allocate work, monitor delivery, conduct performance reviews, address underperformance, coach and develop staff, implement succession and cross-training plans, and build a culture of accountability, documentation and timely delivery.
• Lead cybersecurity governance and improvement programmes, including vulnerability assessments, penetration testing, security monitoring, endpoint and email security, incident response, post-incident reviews and staff security awareness.
• Own ICT service management, including the service desk, incident, problem, change and release management, service-level monitoring, root-cause analysis and major-incident communication.
• Manage ICT vendors and contracts, including selection, due diligence, service levels, performance reviews, renewals, licence compliance, knowledge transfer and enforcement of contractual obligations.
• Provide regular management reporting and dashboards covering ICT projects, service performance, cybersecurity, ISO27001, PDPA, risks, incidents, budgets and vendor performance.
Others
• Any other ad-hoc duties as required by the company from time to time.
Requirements
• Degree in Computer Science, Information Technology or an equivalent discipline. Relevant certifications in networking, cloud, cybersecurity or ISO 27001 are preferred. ITIL and PRINCE2/PMP certification would be advantageous.
• At least 10 years of relevant ICT experience, including at least 5 years in a leadership or managerial role. Proven experience in enterprise networks and infrastructure, ICT operations, ISO 27001audits, cybersecurity, PDPA compliance, project delivery and vendor management is required
• Strong leadership and supervisory skills, with the ability to set clear expectations and hold the team accountable for delivery.
• Strong leadership and supervisory skills, with the ability to set clear expectations and hold the team accountable for delivery.
• Ability to delegate effectively, establish measurable goals and deadlines, monitor progress and intervene promptly where deliverables are at risk.
• Strong technical knowledge and practical experience in enterprise networks, firewalls, Wi-Fi, VPN, cloud and hybrid infrastructure, servers, storage, backup, disaster recovery, identity and access management, and infrastructure monitoring.
• Good working knowledge of enterprise applications, databases, integrations, APIs and data flows, with the ability to evaluate architecture, security, scalability, supportability and vendor solutions without needing to be an application-development specialist.
• Strong analytical, problem-solving and service-management skills, with the ability to manage incidents, problems, changes, service levels and root-cause remediation.
• Self-driven, decisive and able to work independently while collaborating effectively with business stakeholders, management and vendors.
• Able to prioritise competing demands, manage major incidents and deliver under pressure in a fast-paced environment.
• Strong project, vendor, contract, budget, risk-management and management-reporting skills.
• Required to provide leadership during major ICT incidents, audits and critical system implementations, including outside normal working hours where necessary
EA License No : 18C9228 REG No :R1324979 (Woo Kum Yoke)