
Vice President, IT Security & Platform
PCCW
About the role
Key Responsibilities
Cybersecurity Leadership & Governance
-
Develop and execute the enterprise cybersecurity strategy and roadmap
-
Establish security governance, policies, and control frameworks.
-
Lead cybersecurity transformation initiatives and continuous improvement programs.
-
Provide strategic direction for security technologies, and cybersecurity capabilities.
-
Establish and promote a cybersecurity awareness program across the organisation, including security training, phishing simulations, and awareness campaigns.
-
Present cybersecurity strategy, risk posture, and key initiatives to senior management, risk committees, and the Board where applicable.
Technology Risk Management
-
Establish and maintain the technology risk management framework.
-
Oversee technology risk and control assessments
-
Manage technology risk committees, risk reporting and Key Risk Indicators (KRIs).
-
Oversee IT exemption management and risk acceptance processes.
-
Manage IT audits, regulatory reviews, and other assessment engagements, and oversee the implementation of remediation programs.
-
Drive continuous improvement initiatives to enhance technology risk management and governance practices.
-
Lead and coordinate security drills and cyber resilience exercises.
Security Operations & Incident Response
- Provide executive oversight of Security Operations Centre (SOC) functions.
- Ensure effective 24x7 monitoring, threat detection, investigation, and incident response.
- Oversee security incident management, forensic investigations, root cause analysis, containment, and recovery activities.
- Direct threat intelligence, threat hunting, alert management, and use case development activities.
- Ensure timely management reporting on security events and operational effectiveness.
Security Engineering
-
Lead the implementation of security engineering to deploy new security tools and processes.
-
Ensure secure implementation of infrastructure security controls including firewalls, VPNs, endpoint security, and network security.
-
Conduct the security assessment for new initiatives
-
Oversee the operation of application security including DevSecOps, API security, container security, and CI/CD security.
-
Govern security tool implementation and optimization including SIEM, EDR, SOAR, DLP, and vulnerability management technologies.
-
Drive security automation, orchestration, and hardening initiatives.
-
Oversee vulnerability assessment, penetration testing and security validation
-
Provide security advisory
Identity & Access Management (IAM)
-
Establish IAM governance, strategy, and operational controls.
-
Oversee identity lifecycle management, authentication services, privileged access management, and access recertification programs.
-
Manage the administration of privileged accounts to ensure they’re secured.
-
Conduct day-to-day operation for user accounts including provisioning/deprovisioning, recertification, dormant ID management, etc
-
Ensure segregation of duties controls are effectively implemented and monitored.
-
Oversee key and certificate management operations.
-
Lead IAM transformation and integration initiatives across the enterprise.
Third-Party Security Management
- Conduct the third-party cybersecurity assessment for key service providers.
- Oversee security assessments of vendors and external service providers.
- Monitor third-party security risks and remediation activities
Secured Room Management
- Manage the operation and administration of physical access controls for secured rooms.
- Conduct periodic security reviews to verify compliance with physical security requirements for secured rooms.
- Develop and enhance automated workflow for physical access request, approval, provisioning, and revocation processes.
Qualifications & Experience
Education
- Degree in Computer Science, Information Systems and Technology, or related discipline.
Experience
- 8+ years of information security and technology risk management experience.
- 10+ years in a senior leadership role managing multi-disciplinary technology teams.
- Proven experience leading Security Operations, Security Engineering, IAM, and Technology Risk functions.
- Experience reporting cybersecurity risk posture to senior executives and risk committees.
- Proven track record in cybersecurity transformation and security program leadership.
- Experience within financial services, government, or highly regulated environments is highly desirable.
