Senior Manager, Information Security

Prudential’s purpose is to be partners for every life and protectors for every future. Our purpose encourages everything we do by creating a culture in which diversity is celebrated and inclusion assured, for our people, customers, and partners. We provide a platform for our people to do their best work and make an impact to the business, and we support our people’s career ambitions. We pledge to make Prudential a place where you can Connect, Grow, and Succeed.

The incumbent is responsible to deliver exceptional PRUexperience service that sets us apart and make customer service a strategic advantage:

- Implement tools, technologies, and other countermeasures that can be used to protect information, especially from exterior threats on actionable assets that will drive continuous growth and improvement of end-to-end customer experiences;

- Adopt master data management platforms for 7-sisters data sets

- Data strategy, policies and alignment of regional processes with local business units are implemented accordingly

- Protection of information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide confidentiality, integrity, and availability.

KEY RESPONSIBILITIES:

  • Provides local leadership to drive the implementation of the organization’s information security initiatives, aligned with Group directives, industry frameworks and applicable regulatory requirements (i.e BNM RMiT, BNM MCIPD, NIST, PDPA, PCI DSS).

  • Identify, assess and manage information security and cybersecurity risks, ensuring appropriate mitigation measures are implemented

  • Support security related internal and external audits, ensuring timely remediation and closure of findings

  • Oversee security monitoring, incident response and threat management capabilities, ensuring effective detection, escalation and response of security incidents

  • Drive the implementation of security improvement projects and initiatives to strengthen the organization’s security posture

  • Review and approve secure design and deployment of applications and infrastructure in line with security standards

  • Provide security advisory and guidance to support the organization’s transformation initiatives and business-as-usual operations

  • Support cyber resilience and business continuity initiatives

  • Provide security insights to support management in risk-based decision making

  • Drive continuous improvement of security controls, processes and awareness across the organization

QUALIFICATIONS & REQUIREMENTS :

a. Qualifications
Minimum tertiary education. Professional certification such as CISM, CISSP is desired but not a must.

b. Experience

  • Minimum 8-10 years of relevant experience in information security or cybersecurity roles.

  • Proven track record in driving and delivering security initiatives to strengthen the organization’s security posture

c. Knowledge

  • Possess a strong understanding of key security frameworks and standards including NIST Cybersecurity Framework, ISO/IEC 27001, CIS Critical Security Controls, as well as applicable local regulatory requirements such as BNM RMiT, BNM MCIPD, and PCI DSS

  • Demonstrate knowledge of threat intelligence and assessment

  • Familiar with security tools and their core functionalities support effective security monitoring and incident response, including SIEM, EDR, DLP and IAM

  • Possess strong understanding and practical application of security controls aligned with the organization’s risk appetite, internal policies and standards and regulatory requirements

Prudential is an equal opportunity employer. We provide equality of opportunity of benefits for all who apply and who perform work for our organisation irrespective of sex, race, age, ethnic origin, educational, social and cultural background, marital status, pregnancy and maternity, religion or belief, disability or part-time / fixed-term work, or any other status protected by applicable law. We encourage the same standards from our recruitment and third-party suppliers taking into account the context of grade, job and location. We also allow for reasonable adjustments to support people with individual physical or mental health requirements.