Back to search
Secretlab Linkedin · Posted 2d ago

Head of Information Security (Technical)

Petaling Jaya

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

Secretlab is an international gaming chair brand seating over three million users worldwide, with our key markets in the United States, Europe and Singapore, where we are headquartered.


The Head of Information Security (HoIS) is responsible for establishing, leading, and continuously maturing the enterprise-wide information security, data protection, and cyber risk management program. This role provides strategic direction and executive oversight to ensure the confidentiality, integrity, and availability of information assets while enabling business growth, regulatory compliance, and market trust.


Reporting to the General Counsel, the HoIS serves as a strategic advisor to senior leadership, translating cyber and data risks into business and legal impact, and ensuring security-by-design is embedded across technology, product development, and operations. The role balances governance and risk leadership with pragmatic execution through strong delegation to specialist security managers.


Responsibilities

  • Implement secure architecture, cloud security, and ensure secure development practices are embedded across the organization
  • Lead complex incident response, threat containment, and crisis management strategies—including technical root-cause analysis, advanced tabletop simulations, data breach mitigation, and regulatory forensics—requiring extensive hands-on technical IR expertise and deep tactical experience
  • Oversee data protection and privacy-by-design practices in collaboration with Legal, Compliance, Data and business stakeholders
  • Direct and mentor Information Security Managers across application security, security operations, GRC, and privacy domains, leveraging advanced technical depth to drive engineering skill set enhancements and operational maturity
  • Conduct periodic vulnerability assessments and penetration testing across infrastructure, developing actionable remediation roadmaps and infrastructure hardening plans
  • Own third-party and supply-chain security risk management, ensuring vendors meet contractual, regulatory, and security requirements
  • Build and promote a strong security culture through awareness, training, and executive and technical engagement
  • Define and execute the enterprise information security and cyber risk strategy aligned with business objectives, legal obligations, and regulatory expectations
  • Establish and oversee security governance, policies, standards, and metrics aligned with recognized frameworks (ISO 27001, NIST, SOC 2, PCI-DSS)
  • Provide executive-level risk reporting and advisory to senior management on cyber threats, data protection risks, and control effectiveness


Requirements

  • Demonstrated experience architecting and maintaining robust Identity and Access Management (IAM) systems and privileged access management (PAM) workflows.
  • Demonstrate operational expertise in securing containerized environments (Kubernetes/Docker) and CI/CD pipelines to ensure DevSecOps maturity.
  • Lead advanced threat hunting activities, including log analysis, anomaly detection, and forensic investigation of complex security incidents.
  • Define and implement network security configurations, including Zero Trust architecture principles, micro-segmentation, and secure VPN/SD-WAN implementations.
  • Demonstrate a proven ability to thrive in a fast-paced environment, comfortable tackling complex security challenges and driving strategic initiatives with a lean and agile team.
Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search