Search Jobs

Search by job, company or skills

Global Cybersecurity Director (Logistics MNC) - WCDT

Global Cybersecurity Director (Logistics MNC) - WCDT

wecruit pte. ltd.
10-13 Years
SGD 15,000 - 25,000 per month
  • Posted 2 hours ago
  • Be among the first 10 applicants

Job Description

Responsibilities

  • Define and implement the Group's global and regional cybersecurity operating model, including governance, decision-making authority, responsibilities, escalation thresholds, and cross-functional coordination across countries and regions.

  • Develop the Group's target cybersecurity architecture and strategic roadmap covering network segmentation, Zero Trust, endpoint and workload protection, email and web security, cloud security, and secrets management.

  • Establish and enforce consistent global security-control baselines across critical systems, operating entities, and privileged-access environments, supported by formal exception and risk-acceptance processes.

  • Provide technical security oversight for new platforms, system integrations, cloud migrations, and digital transformation initiatives, ensuring cybersecurity requirements are embedded throughout the technology delivery lifecycle.

  • Lead the Group's vulnerability and exposure management programme, including asset discovery, vulnerability assessments, risk-based prioritisation, patching standards, remediation tracking, and external attack-surface reduction.

  • Oversee threat detection and security operations, including SIEM and EDR engineering, detection-rule development, alert triage, threat hunting, threat intelligence, and the performance of managed Security Operations Centre (SOC) providers.

  • Establish and lead a global Cybersecurity Incident Response Team (CIRT), implementing standardised playbooks, command structures, incident severity classifications, escalation procedures, and follow-the-sun response capabilities.

  • Act as Incident Commander for major cybersecurity incidents, coordinating containment, recovery, forensic investigations, executive decision-making, and regulatory, customer, and stakeholder communications.

  • Strengthen enterprise cyber resilience by establishing immutable and segregated backup standards, conducting recovery-time testing for critical platforms, and developing manual operational contingencies for major technology outages.

  • Develop and implement cybersecurity controls for operational technology and logistics environments, including warehouse management systems, automation and robotics, transportation platforms, fleet devices, facility systems, and customer or carrier EDI/API integrations.

  • Lead identity, cloud, and data-security initiatives, including enterprise identity management, phishing-resistant multi-factor authentication, privileged access management, cloud security posture management, encryption, key management, data-loss prevention, and secure AI adoption.

  • Establish and maintain Group cybersecurity policies, standards, and control frameworks aligned with recognised standards such as ISO 27001, NIST Cybersecurity Framework, or equivalent industry frameworks.

  • Oversee cybersecurity awareness, employee security training, and phishing-resilience programmes to strengthen the Group's overall security culture.

  • Translate global, regional, and cross-border cybersecurity and data-protection requirements-including mainland China cybersecurity and data regulations, GDPR, Singapore's Cybersecurity Act and PDPA, and Hong Kong's PDPO-into practical technical and operational controls.

  • Lead third-party cybersecurity risk management, customer security assessments, cyber-insurance reviews, acquisition-related security due diligence, and post-acquisition cybersecurity integration.

  • Build and develop a high-performing global cybersecurity team, lead regional security specialists through a matrix structure, manage the Group's cybersecurity budget and external service providers, and provide executive-level risk reporting to the CIO and Group Risk & Audit Committee.

Requirements

  • Minimum 12 years of cybersecurity experience, including at least 5 years in leadership roles managing technical security teams across multiple countries or regions.

  • Strong hands-on technical expertise across cybersecurity architecture, network security, cloud security, identity and access management, endpoint protection, vulnerability management, SIEM, EDR, and security engineering.

  • Proven experience establishing, transforming, or maturing cybersecurity capabilities within geographically distributed organisations with varying levels of security maturity.

  • Demonstrated experience leading major cybersecurity incidents from initial detection and containment through recovery, executive communication, regulatory notification, and post-incident remediation.

  • Experience establishing or managing a distributed Cybersecurity Incident Response Team and coordinating internal security teams, external forensic specialists, legal advisers, and managed security service providers.

  • Proven ability to lead cybersecurity professionals within a matrix organisation, influence regional and country teams without direct reporting authority, and establish consistent security standards across diverse markets and cultures.

  • Working knowledge of at least two major cybersecurity or data-protection regulatory frameworks, preferably including mainland China's cybersecurity and data regulations, EU GDPR, Singapore's Cybersecurity Act and PDPA, or Hong Kong's PDPO.

  • Experience securing operational technology, industrial control systems, or business-critical environments where system availability is critical and conventional patching or endpoint-security controls may not always be practical.

  • Strong executive presence, communication, and stakeholder-management skills, with the ability to translate complex cybersecurity risks, technical issues, and investment requirements into clear business implications for senior management, regulators, customers, and Board-level committees.

  • Experience within logistics, freight forwarding, shipping, aviation, ports, rail, manufacturing, or other asset-intensive industries is strongly preferred.

  • Professional certifications such as CISSP, CISM, CCISO, GIAC, OSCP, or relevant cloud-security certifications will be an advantage.

    Wecruit Pte Ltd | 20C0270
    Tew Jie Wei | R22106822

More Info

Job Type:
Industry:
Function:
Employment Type:

About Company