Skip to content
← Back to job listings

Senior Business Information Security Officer

I13 Western Union Svcs Singapore · SGP, Singapore

IT - Network / Systems / DB AdminExternal listingfull-timeabout 2 hours ago

About The Role

Senior Manager, Business Information Security Officer (BISO), Singapore

Role Responsibilities

The Senior Manager, Business Information Security Officer (BISO) serves as the Global CISO’s designated cybersecurity representative for the APAC region, based in Singapore. This is a senior technical leadership role within Cybersecurity, acting as the primary bridge between global cybersecurity and regional business. The role combines enterprise program ownership with hands‑on technical acumen and local CISO responsibilities, ensuring that cybersecurity risks, controls, and initiatives are effectively delivered across APAC, and that the region has a single, credible point of contact for business leaders and regulators, particularly during cyber incidents.

Leadership Responsibilities

  • Serve as the Global CISO’s cybersecurity representative for the APAC region, articulating cyber risk posture, threat landscape, control effectiveness, and strategic initiatives to regional executives, boards, and regulators.
  • Provide senior technical leadership and direction for business aligned information security activities across APAC, ensuring alignment with the global cybersecurity strategy, architecture, and control framework.
  • Design, implement, and continuously improve regional information security governance processes to ensure consistent, effective risk management and regulatory alignment.
  • Own regional oversight of cybersecurity regulatory activities as knowledge expert and escalation contact, translating technical control requirements into business language for senior stakeholders.
  • Drive adoption and effective execution of global information security and cybersecurity policies, standards, and technical controls within the APAC region.
  • Develop and mature regular reporting and metrics on the state of cybersecurity risk, control effectiveness, and key technical issues impacting the APAC region.
  • Coach regional business and technology stakeholders on cyber risks, secure design principles, secure architecture, and engineering best practices, reinforcing a sustainable security‑aware culture.

Business Information Security & Local CISO Responsibilities

  • Act as the local CISO and primary cybersecurity point of contact for the business, IT, legal, compliance, audit, operations, product teams, and regulators across Singapore and the broader APAC region.
  • Establish and maintain a deep technical understanding of APAC entities, including business processes, applications, infrastructure, cloud environments, data flows, customers, and third‑party dependencies, to inform risk‑based decision‑making.
  • Direct the identification, assessment, and ongoing monitoring of local cybersecurity risks and technical control gaps, including differences between global security requirements and APAC specific regulatory or supervisory obligations (e.g., Singapore MAS, Bank Indonesia Cyber Resilience, Australia APRA, Philippines BSP IT Risk Management Framework, and equivalents).
  • Lead the regional cybersecurity initiative portfolio, partnering with engineering, infrastructure, and product teams to prioritize, sequence, and deliver technical remediation and security uplift projects.
  • Hold accountability for compliance with applicable local laws, regulations, and supervisory expectations related to information security, serving as a senior point of engagement with regulators, auditors, and internal stakeholders.
  • Serve as the regional point of contact for the business and regulators during cybersecurity incidents; lead regional incident coordination with the Global Incident Response Team, drive containment and recovery decisions, and manage stakeholder and regulatory notifications.
  • Provide technical assurance on security architecture reviews, threat models, penetration test findings, and vulnerability management outcomes for APAC applications and infrastructure.

Role Requirement

  • Bachelor’s degree in Computer Science, Information Security, Engineering, or related discipline required; advanced degree preferred.
  • 8+ years of progressive experience in information security, cybersecurity engineering, or technical risk management, including time in a hands‑on technical role (e.g., security architecture, security operations, application or cloud security).
  • Demonstrated experience leading cybersecurity activities in the APAC region, engaging directly with country regulators such as Singapore, Australia, Philippines, or equivalent, and managing regional cyber incidents.
  • Strong working knowledge of cloud platforms (AWS, Azure), identity and access management, network and endpoint security, application security, and modern threat detection and response practices.
  • Knowledgeable across a broad range of cybersecurity and regulatory concepts, including NIST CSF, ISO 27001/27002, PCI DSS, MITRE ATT&CK, secure SDLC, and third‑party risk management.
  • Experience interacting and managing geographically diverse, technical teams.
  • Professional security certifications such as CISSP, CISM, CCSP, CISA, CRISC, ISO 27001 Lead Implementer/Auditor, or equivalent are strongly preferred.

Key Attributes

  • Trusted technical advisor mindset with the ability to influence senior business, technology, and regulatory stakeholders.
  • Strong written and verbal communication, able to translate complex technical topics into clear business and regulatory narratives.
  • Strong ownership, accountability, and calm judgment under pressure, particularly during live incidents.
  • Balances cybersecurity risk management with business enablement and pragmatic delivery.
  • Demonstrated ability to work effectively with all levels of an organization across cultures and time zones.

Workplace Option

Western Union values in-person collaboration, problem solving, and ideation whenever possible. We believe this fosters common ways of working and supports how we execute initiatives for our customers. The expectation is to work from the office a minimum of three days a week.

BENEFITS AND OTHER DETAILS

Benefits

You will also have access to short-term incentives, accident and life insurance, and access to best-in-class development platforms, to name a few (https://careers.westernunion.com/global-benefits/). Please see the location-specific benefits below and note that your Recruiter may share additional role-specific benefits during your interview process or in an offer of employment.

Your Singapore specific benefits include

  • Paid Time Offs
  • Employee Assistance Programs
  • Global Recognition and Rewards Programs
  • Employee Wellness

We are passionate about honoring our employee's identity and fostering a feeling of belonging. Our commitment is to provide an inclusive culture that celebrates the unique backgrounds and perspectives of our global teams while reflecting the communities we serve. We do not discriminate based on race, color, national origin, religion, political affiliation, sex (including pregnancy), sexual orientation, gender identity, age, disability, marital status, or veteran status. The company will provide accommodation to applicants, including those with disabilities, during the recruitment process, following applicable laws.

#LI-Hybrid #LI-HR1

Estimated Job Posting End Date

09-18-2026 This application window is a good-faith estimate of the time that this posting will remain open. This posting will be promptly updated if the deadline is extended or the role is filled.

This is an external listing. JobSpring does not represent or verify the employer. Report this listing