VP Security Operations (Cybersecurity)
SBS Transit · Sengkang, North-East Region ·
- Work mode
- Onsite
- Seniority
- C level
- Employment
- Full time
- Category
- Security
- Experience
- 2+ years
SBS Transit · Sengkang, North-East Region ·
CIMB Group · Singapore
CIMB · Singapore
Capital Regional District
enovix · Penang, MY
Lead SBS Transit's cybersecurity operations, defending its IT and OT environments by managing EDR/XDR and SOC incident response, security tools, VAPT, vendor budgets, and compliance with standards like ISO27001 and CCoP 2.0. Core tech includes SIEM, firewalls/IPS-IDS, AWS, Azure, and M365.
Primary Objectives of Position
Lead the cybersecurity operations function to proactively defend SBST IT and OT environments against cyber threats, manage cyber incidents and security technologies, ensure regulatory compliance, and drive continuous improvement of cyber resilience.
Major Responsibilities
Lead, manage and work with team members on the following:
Involve in sector-wide cybersecurity programme and engagement.
Coordinate and contribute to various external and internal forums and meetings.
Manage, administrate and provide all cybersecurity operations, services (e.g. VAPT) and tools management.
Manage EDR/XDR (Endpoint Detection and Response/Extended
Detection and Response) tools and respond to incidents with the support of various SOC teams.
Identify cyber security threats to systems, detect security anomalous activities and perform analysis of security logs from multiple sources.
Identify emerging threats and vulnerabilities and recommend appropriate advisories, controls and solutions for implementation to enhance cybersecurity posture.
Formulate cybersecurity policies, procedures and documentation for IT and OT systems, ensuring compliance with regulatory requirements and industry best practices (e.g. Cybersecurity Code of Practice (CCoP 2.0), CP8, ISO27001 etc.).
Work closely with internal and external stakeholders regularly to draft and enhance cybersecurity incident response plans and playbooks to achieve cybersecurity readiness.
Responsible for the handing of cyber incident and crisis in accordance with procedures, which include triage and handling of all cybersecurity alerts and incidents across IT & OT environments.
Perform security analysis on cloud platforms such as AWS, Azure as well M365 services.
Support in regulatory and sectorial audits as and when necessary.
Involve in the planning, conducting and exercising of TTXs (tabletop exercises), penetration tests and other cybersecurity (e.g. red/purple/blue teaming) exercises as and when necessary.
Oversee the development, testing, and maintenance of cybersecurity measures to safeguard both IT and OT Critical Information Infrastructure (CII) assets.
Evaluate, manage and liaison with cybersecurity vendors to ensure fulfilment of cybersecurity services.
Plan and implement budgeted cybersecurity projects based on business requirements.
Job Requirement
Min. Degree in Computer Engineering or equivalent.
Trained in Cybersecurity, Information Security, Forensics or equivalent
Min. 15-25 years of direct and relevant full-time cybersecurity work experience in policy formulation, incident response, and management, regulatory oversight and compliane
CISSP/CISM/CISA/CEH/CRISC or equivalent certification
Strong domain knowledge of multiple cybersecurity practices (Email security solutions, vulnerability management, penetration testing, network security (firewall, IPS/IDS, SIEM, threat intelligence, etc.) and industry IT/OT and cybersecurity best practices.
Experience in Threat detection, Penetration testing and red/purple teaming
Knowledge in ISO27001 and IEC62443, NIST Cybersecurity Framework, CSA Code of Practice (CCoP).
Knowledge in Network, Web Security and Application Security would be highly valued.
Experience with information security tools (SIEM, anti-virus tools etc.).
Experience in forensics and incident management.
Strong leadership qualities & ability to work under pressure.
Self-motivated, a good team player and strong ability to multi-task.
Excellent verbal, written communication, presentation and analytical skills.
Ability to build strong and trusting relationships
Experience working in public transport and/or OT industry would be highly valued.
By submitting this application for this position, you acknowledge that you have read the Data Protection Policy for Job Applicants (the “Policy”) of SBS Transit Ltd and its subsidiaries, affiliates and related corporations (‘SBST”) and consent to:
a. The collection, use and disclosure of your personal data by SBST for the purposes of your application and potential employment with SBST and the purposes set out in the Policy: and
b. SBST’s retention of your personal data for 2 years for consideration of future job opportunities (where applicable) from the date of submission of application.
Boardroom Appointments · Johannesburg, GP, South Africa