Morgan McKinley

Chief Information Security Officer (CISO)

Morgan McKinley

Singapore · Full Time

Be the first to apply

Experience
15+ yrs
Salary
Openings
1
Posted
1 week ago
Work mode
In office
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

Role Overview

We are looking for a seasoned Chief Information Security Officer (CISO) to spearhead the cybersecurity vision, strategy, and technical direction of a leading tech organisation operating within a cloud-native, AI-enhanced ecosystem. This role demands a blend of strategic guidance and hands-on technical command to embed security protocols throughout cloud infrastructure, software development, AI platforms, and data resources. The CISO will collaborate extensively with Technology, Engineering, Data, and AI leadership to establish a scalable, resilient, and forward-thinking security framework.

Key Responsibilities

  • Develop and drive a cybersecurity strategy and roadmap that aligns tightly with company business and technological goals.
  • Lead and mentor teams in Security Engineering, Cloud Security, Application Security, Security Operations, and Threat Management.
  • Define security architecture standards and embed secure-by-design principles within all technological processes.
  • Serve as the primary technical cybersecurity consultant to CTO, CIO, and executive management.
  • Shape security strategies across AWS, Azure, and/or GCP cloud platforms, enhancing identity management, network defense, workload security, and data protection.
  • Manage cloud security posture, vulnerability assessments, monitoring, logging, and crisis resilience.
  • Integrate security into cloud transformation and platform engineering projects.
  • Establish and oversee the organisation's AI security framework addressing Generative AI, AI agents, machine learning models, and AI applications.
  • Identify and mitigate AI-specific risks such as prompt injection, model tampering, data leakage, supply-chain vulnerabilities, and insecure AI integrations.
  • Collaborate closely with Data Science and AI Engineering teams to ensure AI development adheres to secure-by-design architectures.
  • Champion DevSecOps and security-oriented practices throughout software development lifecycles, including CI/CD, infrastructure-as-code, API, and container security.
  • Lead automation efforts to continuously detect and address security threats.
  • Direct Security Operations, Incident Response, Threat Intelligence, and Hunting with a proactive stance on threat landscape management.
  • Handle major cybersecurity incidents with thorough post-incident evaluations and remediation strategies.
  • Implement strong governance policies, manage risk assessments, penetration tests, compliance adherence, and third-party risk evaluations.
  • Enhance cyber resilience, disaster recovery, and crisis management preparedness.

Qualifications and Experience

  • Over 15 years of cybersecurity expertise, including leadership of technical security teams.
  • Track record as a CISO, Deputy CISO, or comparable leadership in Security Engineering or Cloud Security roles.
  • Deep knowledge of cloud security, application protection, DevSecOps, security architecture, and cyber defense.
  • Extensive experience securing environments hosted on AWS, Azure, and/or Google Cloud Platform.
  • Strong familiarity with AI and machine learning security challenges, especially regarding Generative AI risks and securing AI-driven systems.
  • Hands-on experience with advanced security solutions such as CNAPP/CSPM, Endpoint Detection and Response (EDR), Security Information and Event Management (SIEM), Identity and Access Management (IAM), Web Application Firewalls (WAF), API security, container and Kubernetes security, and security automation tools.
  • In-depth understanding of cybersecurity frameworks like NIST CSF, CIS Controls, ISO 27001, and MITRE ATT&CK.
  • Proven success driving cybersecurity transformations in fast-evolving, technology-intensive businesses.
  • Excellent communication and stakeholder engagement capabilities, able to translate intricate technical threats into understandable business risks.
  • Relevant certifications such as CISSP, CISM, CCSP, or GIAC are preferred.

Additional Information

Location: Singapore (Onsite).

Employment Type: Full-time.

How they work

Communication Problem Solving Leadership Strategic Thinking Relationship Building
🤖
Online · instant AI help
Broxer