Point your AI agent at freehire and let it find you a job.

Get the CLI →

KLN Logistics

Director – Global Cybersecurity

Posted Updated 1 view
Discussion

Responsibilities:

  • Define and implement the global–regional cybersecurity operating model, including decision rights, responsibilities, escalation thresholds and functional coordination across regions and countries.

  • Develop the Group’s target security architecture and implementation roadmap covering network segmentation, zero-trust access, endpoint and workload protection, email and web security, cloud security and secrets management.

  • Establish and enforce consistent global security-control baselines across critical systems, operating entities and privileged-access environments, with formal exception and risk-acceptance processes.

  • Provide technical security oversight for new platforms, system integrations, cloud migrations and digital initiatives, ensuring security requirements are incorporated throughout the technology-delivery lifecycle.

  • Lead the Group’s vulnerability and exposure-management programme, including asset discovery, vulnerability scanning, risk-based prioritisation, patching standards and external attack-surface reduction.

  • Oversee threat detection and security operations, including SIEM and EDR engineering, detection-rule development, alert triage, threat hunting, threat intelligence and the performance of the managed Security Operations Centre.

  • Establish and lead a wide Cybersecurity Incident Response Team with a common playbook, command structure, severity classification, escalation process and follow-the-sun response capability.

  • Serve as Incident Commander for material cybersecurity incidents, coordinating containment, recovery, forensic investigation, executive decision-making and regulatory, customer and stakeholder communications.

  • Strengthen cyber resilience by establishing immutable and segregated backup standards, testing recovery times for critical platforms and developing manual operational fallbacks for major system outages.

  • Develop and implement security controls for operational technology and logistics systems, including warehouse systems, automation equipment, robotics, transport platforms, fleet devices, facility systems and customer or carrier EDI/API integrations.

  • Lead identity, cloud and data-security initiatives, including consolidated identity management, phishing-resistant multifactor authentication, privileged-access management, cloud-security posture, encryption, key management, data-loss prevention and secure AI adoption.

  • Establish and maintain Group cybersecurity policies and control standards aligned with recognised frameworks such as ISO 27001, NIST Cybersecurity Framework or equivalent, while overseeing security awareness and phishing-resilience programmes.

  • Translate global regulatory and cross-border data requirements—including mainland China cybersecurity and data laws, GDPR, Singapore’s Cybersecurity Act and PDPA, and Hong Kong’s PDPO—into practical technical and operational controls.

  • Lead third-party cybersecurity risk management, customer security reviews, cyber-insurance assessments, security due diligence for acquisitions and post-acquisition security integration.

  • Build and develop a small global cybersecurity team, lead regional security experts through a matrix structure, manage the Group cybersecurity budget and external providers, and provide decision-ready risk reporting to the CIO and Group Risk & Audit Committee.

Requirements:

  • Minimum 12 years of cybersecurity experience, including at least five years leading technical security teams across multiple countries or regions.

  • Strong hands-on technical knowledge of security architecture, network security, cloud security, identity and access management, endpoint protection, vulnerability management, SIEM, EDR and security engineering.

  • Demonstrated experience building or transforming cybersecurity capabilities within a geographically distributed organisation with varying levels of security maturity.

  • Proven experience leading major cybersecurity incidents from detection and containment through recovery, executive communication, regulatory notification and post-incident remediation.

  • Experience establishing or operating a distributed Cybersecurity Incident Response Team and coordinating internal responders, external forensic specialists, legal advisers and managed-security providers.

  • Proven ability to lead cybersecurity professionals through a matrix structure, influence regional and country teams without direct authority, and establish common standards across diverse markets and cultures.

  • Working knowledge of at least two major cybersecurity or data-protection regimes, preferably including mainland China’s cybersecurity and data laws, EU GDPR, Singapore’s Cybersecurity Act and PDPA, or Hong Kong’s PDPO.

  • Experience securing operational technology, industrial systems or environments where system availability is critical and conventional patching or endpoint controls may not be practical.

  • Strong executive presence, communication and stakeholder-management skills, with the ability to explain complex cyber risks and investment decisions clearly to senior management, regulators, customers and Board committees.

  • Experience in logistics, freight forwarding, shipping, aviation, ports, rail or manufacturing is strongly preferred; relevant certifications such as CISSP, CISM, CCISO, GIAC, OSCP or cloud-security certifications, would be advantageous.


Skills

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available