VP, Cyber Security Engineering (Data Security & Protection Engineer), Technology Group
Posted Updated
Summary
VP-level data security engineer at a sovereign wealth fund, responsible for designing and implementing enterprise cybersecurity systems focused on data protection—DLP, encryption, HSMs, and cloud security across AWS, Azure, and GCP.
GIC is one of the world's largest sovereign wealth funds. With over 2,000 employees across 11 locations around the world, we invest in more than 40 countries globally across asset classes and businesses. Working at GIC gives you exposure to an extraordinary network of the world's industry leaders. As a leading global long-term investor, we Work at the Point of Impact for Singapore's financial future, and the communities we invest in worldwide. Technology Group The Technology Group (TG) is a key enabler to keep our business moving forward and is constantly exploiting state-of-the-art information technologies to enhance GIC's ability to be the leading global long-term investment firm. We aim to provide users with empowering and transformational capabilities, and to create an inclusive, innovative and integrated work environment. What impact can you make in this role You'll be empowered to be at the top of your game by providing strategic partnership, and innovative technology solutions that supports GIC's vision of being a tech-driven, global, long-term investment firm. What will you do as an VP, Data Security and Protection Engineer:
Our PRIME Values GIC is a values driven organization. GIC's PRIME Values act as our compass, enabling us to fulfil our fundamental purpose and objectives. It is the foundational bedrock which governs our behaviors, our decision making, and our focus. It informs both our long-term strategy as a firm, and the way we relate to our Client, business partners and employees. PRIME stands for Prudence, Respect, Integrity, Merit and Excellence.
- Identify and recommend improvement areas in existing enterprise security architecture to address evolving cybersecurity threats
- Align and balance business requirements with cybersecurity, information, and technology requirements, based on the organization's risk appetite
- Evaluate, perform proof-of-value/proof-of-concept, design, build and implement enterprise-class cybersecurity systems
- Develop integrated security operating models and documentations to ensure operational efficiency, scalability, and sustainability
- Act as a domain expert and trusted partner in Cyber Security & Resilience; work closely with stakeholders in Technology Group and other business groups on cybersecurity engineering related matters.
- Bachelor's Degree in Information Technology, Computer Engineering or equivalent.
- At least 10 years of relevant experience preferably in financial services or asset management industries, with minimum 7 years in Cyber Security or Information Security.
- Hands-on experience in implementing and operationalizing data security solutions and data protection, for both structured and un-structured data. Specifically:
- Data discovery, classification, and labelling
- Data encryption, masking, tokenization
- Data Loss Prevention (DLP)
- Enterprise Digital Rights Management / Information Rights Management
- Privacy Enhancing Technologies and Confidential Computing
- Key and certificate management
- Hardware Security Modules (HSM)
- Access controls
- Secure file transfer and data store (including SaaS solutions)
- Familiarity with cloud security and data security and protection in cloud environments (e.g., AWS, Azure, Google Cloud).
- Scripting and coding skills, with proficiency in Java, Python, C#, or similar programming languages, and good understanding of REST API's and JSON.
- Familiarity with cloud security and data security and protection in cloud environments (e.g., AWS, Azure, Google Cloud).
- Working experience with other cybersecurity products such as SIEM, threat intelligence, security incident response and forensic investigation, network and endpoint protection, and others, would be advantageous.
- Ability to produce detailed documentation, including design diagrams and process flows.
- Must be meticulous, versatile, and inquisitive, having strong attention to detail with an analytical mind and outstanding problem-solving skills.
- Desire to learn, working in a diverse environment, interacting with multiple teams and functions to support strategic goals. Be a good team player and excellent communicator.
- Professional qualification in information security, such as CISSP / CISM / CEH will be advantageous.
Our PRIME Values GIC is a values driven organization. GIC's PRIME Values act as our compass, enabling us to fulfil our fundamental purpose and objectives. It is the foundational bedrock which governs our behaviors, our decision making, and our focus. It informs both our long-term strategy as a firm, and the way we relate to our Client, business partners and employees. PRIME stands for Prudence, Respect, Integrity, Merit and Excellence.
What they ask for
Required
- Bachelor's Degree in Information Technology, Computer Engineering or equivalent
- At least 10 years of relevant experience preferably in financial services or asset management
- Minimum 7 years in Cyber Security or Information Security
- Hands-on experience implementing data security solutions for structured and unstructured data
- Data discovery, classification, and labelling
- Data encryption, masking, tokenization
- Data Loss Prevention (DLP)
- Enterprise Digital Rights Management / Information Rights Management
- Privacy Enhancing Technologies and Confidential Computing
- Key and certificate management
- Hardware Security Modules (HSM)
- Access controls
- Secure file transfer and data store including SaaS solutions
- Cloud security and data protection in AWS, Azure, Google Cloud
- Scripting/coding proficiency in Java, Python, C#, or similar
- Good understanding of REST APIs and JSON
- Ability to produce detailed documentation including design diagrams and process flows
Preferred
- SIEM, threat intelligence, security incident response and forensic investigation
- Network and endpoint protection experience
- Professional qualification such as CISSP / CISM / CEH