Manager, Group Infosecurity (Governance)

Singapore, Singapore

Applications have closed

Ninja Van

Ninja Van is Southeast Asia’s leading logistics provider, with the highest service coverage over 6 countries in the region. Experience the joy of hassle-free deliveries by shipping with Ninja Van today.

View company page

Ninja Van is a late-stage logtech startup that is disrupting a massive industry with innovation and cutting edge technology. Launched 2014 in Singapore, we have grown rapidly to become one of Southeast Asia's largest and fastest-growing express logistics companies. Since our inception, we’ve delivered to 100 million different customers across the region with added predictability, flexibility and convenience. Join us in our mission to connect shippers and shoppers across Southeast Asia to a world of new possibilities. 
More about us: - We process 250 million API requests and 3TB of data every day.- We deliver more than 1.5 million parcels every day.- 100% network coverage with 1000+ hubs and stations in 6 SEA markets (Singapore, Malaysia, Indonesia, Thailand, Vietnam and Philippines), reaching 500 million consumers.- 600,000 active shippers in all e-commerce segments, from the largest marketplaces to the individual social commerce sellers.- Raised US$400 million over four rounds.
We are looking for world-class talent to join our crack team of engineers, product managers and designers. We want people who are passionate about creating software that makes a difference to the world. We like people who are brimming with ideas and who take initiative rather than wait to be told what to do. We prize team-first mentality, personal responsibility and tenacity to solve hard problems and meet deadlines. As part of a small and lean team, you will have a very direct impact on the success of the company.

Role and responsibility

  • Assist and implement information security management framework and related IT Security policies within the organizations. 
  • Perform continuous assessment of IT security practices and policies to improve the security posture of the company
  • Demonstrate expertise in leading initiatives to assess the adequacy and effectiveness of IT controls and policies, ensuring that business users are compliant to the IS standards (ISO 27001 and etc).
  • Planning and implementation of Information Security, IT Risk Management, IT Audit and IT policy to improve the overall security posture for the organization across Asia. 
  • Drive information security governance projects across the geography
  • Define and implement ISMS risk management best practices across the organization.
  • Collect and maintain applicable IT Security Regulations for all relevant geographies.
  • Demonstrate expertise in Managing IT and IT security audits and assessments performed in the organization.
  • Assist in IT Audit report discussions with process owners and senior management
  • Demonstrate expertise in Managing third party security assessment across the organization.
  • Strong knowledge of understanding  business and security requirements and translating the requirements into effective and efficient policies and processes

Qualifications/ Experience

  • Masters in Information Security / STEM (science, technology, engineering and mathematics) degree
  • At least 8-10 years of experience in consulting and professional services
  • Experience in leading IT security, attestation and assurance audits globally
  • Professional security related qualification (e.g. CISM, CISA, CRISC.) will be favorable although not mandatory

Knowledge / Technical Skills

  • Knowledge of attestation standards (SOC 1. SOC 2, IT SOX etc.)
  • Knowledge of ISO 27001, NIST CSF
  • Excellent written and verbal communication skills and ability to escalate timely to management.
  • High degree of attention to detail and discipline in tracking and managing the closure of identified vulnerabilities and issues arising from audit
  • Effective influencing and negotiating skills and demonstrated sensitivity to working and interacting with senior stakeholders
  • Ability to work independently 
Tech Stack:
Backend: Play (Java 8+), Golang, Node.jsFrontend: AngularJS, ReactJSMobile: Android, Flutter, React NativeCache: Hazelcast, RedisData storage: MySQL, TiDB, Elasticsearch, Delta LakeInfrastructure monitoring: Prometheus, GrafanaOrchestrator: KubernetesContainerization: Docker, ContainerdCloud Provider: GCP, AWSData pipelines: Apache Kafka, Spark Streaming, MaxwellWorkflow manager: Apache AirflowQuery engines: Apache Spark, Trino
Submit a job applicationBy applying to the job, you acknowledge that you have read, understood and agreed to our Privacy Policy Notice (the “Notice”) and consent to the collection, use and/or disclosure of your personal data by Ninja Logistics Pte Ltd (the “Company”) for the purposes set out in the Notice. In the event that your job application or personal data was received from any third party pursuant to the purposes set out in the Notice, you warrant that such third party has been duly authorised by you to disclose your personal data to us for the purposes set out in the the Notice. 

Tags: Android APIs Audits CISA CISM CRISC Docker E-commerce Elasticsearch GCP Golang Governance ISMS ISO 27001 Java Mathematics Monitoring MySQL NIST Privacy Prometheus Risk management Security assessment SOC 1 SOC 2 STEM Vulnerabilities

Perks/benefits: Startup environment

Region: Asia/Pacific
Country: Singapore
Job stats:  8  0  0
Category: Leadership Jobs

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.