
SVP, Head of Non-Human Identity Policy, Information Security Services, Group Technology
- Singapore
- Permanent
- Full-time
- Own and drive the bank’s non-human identity strategy, policy, and governance framework
- Develop and enforce standards, procedures, and controls for non-human identity lifecycle management
- Ensure compliance with regulatory requirements, internal policies, and industry best practices
- Serve as the primary point of contact and subject matter expert for non-human identity management
- Architect, engineer and operate the implementation of scalable, resilient, and secure IAM solutions for non-human identities
- Collaborate with IT, DevOps, and business units to integrate IAM controls into application and infrastructure pipelines
- Evaluate and recommend IAM technologies, tools, and automation to enhance security posture and operational efficiency
- Lead the day-to-day operations of non-human identity management, including provisioning, de-provisioning, monitoring, and incident response
- Develop and execute resiliency plans to ensure continuity and rapid recovery of IAM services
- Monitor and report on key metrics, risks, and incidents related to non-human identities
- Build and nurture relationships with senior executives, auditors, regulators, and internal stakeholders
- Lead, mentor, and develop a team of IAM engineers and analysts, fostering a culture of excellence and continuous improvement
- Communicate complex technical concepts to non-technical audiences and influence decision-making at all levels
- Bachelor’s or Master’s degree in Computer Science, Information Security, or related field
- 10+ years of experience in information security, with at least 5 years in IAM architecture and operations
- Proven expertise in non-human identity management, including secrets management, privileged access, and automation
- Strong background in security and resiliency engineering within large, regulated environments (preferably banking or financial services)
- In-depth knowledge of IAM technologies (e.g., CyberArk, HashiCorp Vault, Azure AD, AWS IAM), protocols, and standards
- Experience with regulatory frameworks (e.g., MAS, PCI DSS, SOX, GDPR) and risk management
- Experience in management of regulatory inspections or audits
- Exceptional interpersonal and communication skills, with demonstrated ability to influence and collaborate with senior management, peers, and technical teams
- Relevant certifications (CISSP, CISM, CCSP, or equivalent) are highly desirable
- Strategic thinking and vision
- Technical leadership and hands-on expertise
- Security and resiliency mindset
- Strong analytical and problem-solving abilities
- Excellent stakeholder management and team leadership