Our client is a global investment-focused organization operating a highly critical, 24×7 technology environment that supports core functions across investment management, trading, operations, and risk.
The organization focuses on building and managing secure, resilient, and scalable technology platforms that enable its global business operations. Its technology teams are responsible for designing and delivering robust infrastructure, applications, and integrated solutions while continuously evaluating emerging technologies and innovative approaches to strengthen business capabilities.
The client operates in a highly regulated and technology-intensive environment, where reliability, security, operational resilience, and performance are critical to supporting global investment activities.
Role Description:
- You'll be empowered to be at the top of your game by providing strategic partnership, and innovative technology solutions that supports our client vision of being a tech-driven, global, long-term investment firm.
Responsibilities:
What will you do as an VP, Enterprise Cybersecurity Engineering, Cybersecurity Platform Engineer?
- Identify and recommend improvement areas in existing enterprise security architecture to address evolving cybersecurity threats
- Align and balance business requirements with cybersecurity, information, and technology requirements, based on the organization’s risk appetite
- Evaluate, perform proof-of-value/proof-of-concept, design, build and implement enterprise-class cybersecurity systems
- Develop integrated security operating models and documentations to ensure operational efficiency, scalability, and sustainability
- Act as a domain expert and trusted partner in Cyber Security & Resilience; work closely with stakeholders in Technology Group and other business groups on cybersecurity engineering related matters
Requirements:
What qualifications or skills should you possess in this role?
- Bachelor’s degree in Information Technology, Computer Science, or a related discipline.
- At least 10 years of relevant experience preferably in financial services or asset management industries, with minimum 7 years in Cyber Security or Information Security.
- Proven experience in implementing and operationalizing enterprise cybersecurity platforms, including:
- Security Operations Tooling: EDR, NDR, SIEM, SOAR, XDR, Threat Intelligence Platforms (TIPs).
- Email Security: Secure email gateways (SEG) and Integrated Cloud Email Security (ICES), anti-phishing and anti-malware controls, DMARC/DKIM/SPF authentication, and email threat detection and response.
- Continuous Threat Exposure Management (CTEM): Attack surface assessment, vulnerability assessment, data aggregation and risk-based prioritization, threat exposure management, and attack simulation/validation (e.g., BAS).
- Experience operationalizing a CTEM program or equivalent risk-based exposure management framework preferred.
- Working knowledge of cloud security controls and reference architectures across AWS, Azure, and Google Cloud Platform.
- Scripting and coding skills, with proficiency in Java, Python, C#, or similar programming languages, and good understanding of REST API’s and JSON.
- Ability to produce detailed documentation, including design diagrams and process flows.
- Must be meticulous, versatile, and inquisitive, having strong attention to detail with an analytical mind and outstanding problem-solving skills.
- Desire to learn, working in a diverse environment, interacting with multiple teams and functions to support strategic goals. Be a good team player and excellent communicator.
- Professional qualification in information security, such as CISSP / CISM / CEH will be advantageous.