Global Cybersecurity Director (Logistics MNC) - WCDT
wecruit pte. ltd.- Posted 2 hours ago
- Be among the first 10 applicants
Job Description
Responsibilities
Define and implement the Group's global and regional cybersecurity operating model, including governance, decision-making authority, responsibilities, escalation thresholds, and cross-functional coordination across countries and regions.
Develop the Group's target cybersecurity architecture and strategic roadmap covering network segmentation, Zero Trust, endpoint and workload protection, email and web security, cloud security, and secrets management.
Establish and enforce consistent global security-control baselines across critical systems, operating entities, and privileged-access environments, supported by formal exception and risk-acceptance processes.
Provide technical security oversight for new platforms, system integrations, cloud migrations, and digital transformation initiatives, ensuring cybersecurity requirements are embedded throughout the technology delivery lifecycle.
Lead the Group's vulnerability and exposure management programme, including asset discovery, vulnerability assessments, risk-based prioritisation, patching standards, remediation tracking, and external attack-surface reduction.
Oversee threat detection and security operations, including SIEM and EDR engineering, detection-rule development, alert triage, threat hunting, threat intelligence, and the performance of managed Security Operations Centre (SOC) providers.
Establish and lead a global Cybersecurity Incident Response Team (CIRT), implementing standardised playbooks, command structures, incident severity classifications, escalation procedures, and follow-the-sun response capabilities.
Act as Incident Commander for major cybersecurity incidents, coordinating containment, recovery, forensic investigations, executive decision-making, and regulatory, customer, and stakeholder communications.
Strengthen enterprise cyber resilience by establishing immutable and segregated backup standards, conducting recovery-time testing for critical platforms, and developing manual operational contingencies for major technology outages.
Develop and implement cybersecurity controls for operational technology and logistics environments, including warehouse management systems, automation and robotics, transportation platforms, fleet devices, facility systems, and customer or carrier EDI/API integrations.
Lead identity, cloud, and data-security initiatives, including enterprise identity management, phishing-resistant multi-factor authentication, privileged access management, cloud security posture management, encryption, key management, data-loss prevention, and secure AI adoption.
Establish and maintain Group cybersecurity policies, standards, and control frameworks aligned with recognised standards such as ISO 27001, NIST Cybersecurity Framework, or equivalent industry frameworks.
Oversee cybersecurity awareness, employee security training, and phishing-resilience programmes to strengthen the Group's overall security culture.
Translate global, regional, and cross-border cybersecurity and data-protection requirements-including mainland China cybersecurity and data regulations, GDPR, Singapore's Cybersecurity Act and PDPA, and Hong Kong's PDPO-into practical technical and operational controls.
Lead third-party cybersecurity risk management, customer security assessments, cyber-insurance reviews, acquisition-related security due diligence, and post-acquisition cybersecurity integration.
Build and develop a high-performing global cybersecurity team, lead regional security specialists through a matrix structure, manage the Group's cybersecurity budget and external service providers, and provide executive-level risk reporting to the CIO and Group Risk & Audit Committee.
Requirements
Minimum 12 years of cybersecurity experience, including at least 5 years in leadership roles managing technical security teams across multiple countries or regions.
Strong hands-on technical expertise across cybersecurity architecture, network security, cloud security, identity and access management, endpoint protection, vulnerability management, SIEM, EDR, and security engineering.
Proven experience establishing, transforming, or maturing cybersecurity capabilities within geographically distributed organisations with varying levels of security maturity.
Demonstrated experience leading major cybersecurity incidents from initial detection and containment through recovery, executive communication, regulatory notification, and post-incident remediation.
Experience establishing or managing a distributed Cybersecurity Incident Response Team and coordinating internal security teams, external forensic specialists, legal advisers, and managed security service providers.
Proven ability to lead cybersecurity professionals within a matrix organisation, influence regional and country teams without direct reporting authority, and establish consistent security standards across diverse markets and cultures.
Working knowledge of at least two major cybersecurity or data-protection regulatory frameworks, preferably including mainland China's cybersecurity and data regulations, EU GDPR, Singapore's Cybersecurity Act and PDPA, or Hong Kong's PDPO.
Experience securing operational technology, industrial control systems, or business-critical environments where system availability is critical and conventional patching or endpoint-security controls may not always be practical.
Strong executive presence, communication, and stakeholder-management skills, with the ability to translate complex cybersecurity risks, technical issues, and investment requirements into clear business implications for senior management, regulators, customers, and Board-level committees.
Experience within logistics, freight forwarding, shipping, aviation, ports, rail, manufacturing, or other asset-intensive industries is strongly preferred.
Professional certifications such as CISSP, CISM, CCISO, GIAC, OSCP, or relevant cloud-security certifications will be an advantage.
Wecruit Pte Ltd | 20C0270
Tew Jie Wei | R22106822
More Info
Key Skills
cybersecurity policies
cybersecurity architecture
