Head of Information Security
Indexed description
Key Responsibilities
Security Governance and Regulatory Compliance
- Develop, maintain, and enforce enterprise information security policies, standards, procedures, and guidelines.
- Ensure compliance with SEC, BOT, AMLO, PDPA, and applicable cybersecurity regulations.
- Act as principal liaison for all security-related regulatory examinations and inspections.
- Prepare and maintain security documentation required for licensing and regulatory submissions.
- Coordinate internal and external security audits.
- Track remediation activities and evidence collection for audit findings.
- Present security risk reports to executive management, Risk Management Committee and the Board.
Cybersecurity Operation
- Operate and oversee daily cybersecurity monitoring activities.
- Review security alerts, event logs, vulnerability reports, and threat intelligence feeds.
- Manage endpoint security, identity and access management, privileged access controls, and network security configurations.
- Maintain secure baseline configurations across all corporate and production systems.
- Periodically validate effectiveness of security controls.
Digital Asset Custody Securit
- Design, maintain, and monitor security controls protecting customer digital assets.
- Oversee wallet security architecture including key management processes.
- Ensure secure operation of offline private key storage and associated custody infrastructure.
- Review transactional security controls and approval workflows.
- Implement and validate cryptographic control requirements.
- Maintain processes supporting segregation of duties and multi-party authorization controls.
Risk Management
- Establish and maintain enterprise technology and cybersecurity risk registers.
- Conduct periodic security risk assessments.
- Evaluate risks arising from vendors, outsourcing arrangements, cloud services, software providers, and technology partners.
- Track risk treatment plans and remediation activities.
- Develop security metrics and key risk indicators.
Incident Response and Crisis Management
- Own the cybersecurity incident response program
- Lead investigations involving security breaches, suspicious activity, fraud attempts, insider threats, or operational security incidents.
- Coordinate external forensic specialists where necessary.
- Conduct post-incident reviews and remediation planning.
- Manage security communications to executives, auditors, regulators, and affected stakeholders.
- Vulnerability and Security Testing
- Coordinate regular vulnerability assessments and penetration tests.
- Personally validate remediation of identified findings.
- Conduct ongoing security reviews of infrastructure, applications, and operational processes.
- Track security weaknesses and ensure timely resolution
Third Party and Vendor Security.
- Perform security due diligence for technology vendors and outsourcing partners.
- Assess contractual security obligations.
- Monitor vendor compliance with security requirements.
- Review SOC reports, independent assessments, and vendor certifications.
- Business Continuity and Operational Resilience.
- Maintain cyber resilience and disaster recovery capabilities.
- Develop and test incident response, disaster recovery, and business continuity plans.
- Participate in operational resilience exercises.
- Ensure critical custody operations remain resilient against cyber threats and disruptions.
Security Awareness
- Develop cybersecurity awareness programs.
- Deliver staff training and phishing simulations.
- Foster a security-first culture throughout the organization.
- Provide practical guidance to employees and management on secure operations
Qualification
- Minimum 8-12 years of information security experience
- Minimum 3-5 years in a senior security leadership position
- Prior experience within financial services, banking, securities, fintech, payment services, digital assets, or regulated institutions strongly preferer
- Demonstrated experience operating within highly regulated environment
Successful candidate may be subject to a criminal background check. Where consent is legally required, the Company will seek your consent prior to conducting such check. The Company reserves the right not to proceed with the hiring process if the background check cannot be conducted.
Orbix Holdings gives an important to Privacy Notice for candidates, we’ll always treat your data with the utmost care. Please click on the links below to find out more about our Privacy Notice for candidates: https://www.orbixholdings.com/docs/Privacy%20Notice%20for%20Candidate.pdf
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search