
The Regional CISO - APAC serves as the primary security leader for the APAC region, reporting to the Group CISO and with a cross-functional reporting line to the APAC CIO This role is responsible for governing and overseeing the implementation of Group security policies and programs across APAC, ensuring adherence to global standards while meeting local regulatory obligations. The Regional CISO will govern the five security domains at the regional level, facilitate regulatory compliance, streamline reporting into the Group CISO governance framework, and coordinate with local security leaders, including the Local CISO in India. Additionally, the role ensures readiness for audits, regulatory reviews, and incident response, acting as a trusted advisor to regional leadership on cybersecurity risk and resilience.
Context
The Group Information Security function is dedicated to protecting the organization’s information assets through a unified, risk-based approach to cybersecurity. The function operates across five core domains: Security Governance, Security Architecture, Operations Security, Identity & Access Management (IAM), and Data Protection & Privacy Each domain is managed centrally by specialized teams under the Group CISO, ensuring global consistency and compliance. Regional CISOs play a critical role in extending this governance model to their respective geographies, ensuring alignment with Group standards while addressing local regulatory and business requirements. They act as the bridge between global strategy and regional execution, enabling effective risk management and regulatory compliance.
Key duties and responsibilities
Represent APAC in global security working groups and forums
Required experience & competencies
10+ years in cybersecurity, with at least 5 years in a leadership role covering multiple geographies.
Strong understanding of APAC regulatory frameworks (e.g., MAS TRM, IRDAI, CBIRC, APRA CPS 234).
CISSP, CISM, or equivalent; knowledge of ISO 27001, NIST CSF.
Ability to influence stakeholders and manage cross-functional teams in a matrix organization.
Required Education
Bachelor's degree in Information Security, Computer Science, or a related field.
Professional certifications such as CISSP, CISM, CRISC, or ISO 27001 Lead Implementer/Auditor are highly desirable.
As a leading global reinsurer, SCOR offers its clients a diversified and innovative range of reinsurance and insurance solutions and services to control and manage risk. Applying “The Art & Science of Risk,” SCOR uses its industry-recognized expertise and cutting-edge financial solutions to serve its clients and contribute to the welfare and resilience of society in around 160 countries worldwide.
Working at SCOR means engaging with some of the best minds in the industry – actuaries, data scientists, underwriters, risk modelers, engineers, and many others – as we work together to find solutions to pressing challenges facing societies.
As an international company, our common culture is defined by “The SCOR Way.” Serving both to build momentum that drives the Group forward and as a compass to guide our actions and choices, The SCOR Way is anchored by five core values, reflecting the input of employees at all levels of the Group. We care about clients, people, and societies. We perform with integrity. We act with courage. We encourage open minds. And we thrive through collaboration.
SCOR supports inclusion and the diversity of talents, and all positions are open to people with disabilities.

SCOR, one of the world's largest reinsurers, provides its clients with a diversified and innovative range of solutions to control and manage risk. Using its experience and expertise, “The Art & Science of Risk”, SCOR provides cutting-edge financial solutions, analytics tools and services in all areas related to risk – in Life & Health as well as in P&C.
The reinsurance industry is about combining technical expertise and experience with the developments of science. However many tools we use to conduct our activities (models, databases, pricing tools, reserving tools, and so on), we also need expert judgments and human experience to correctly underwrite. This is what we call the art of underwriting. Reinsurance is a knowledge industry. Expertise is an accumulation variable.
The most advanced tool will never replace the intuition of a seasoned underwriter facing a complex risk. Because at the end of the day, you have to make a decision, to sign, to underwrite. And what we have underwritten, we cannot overwrite - our word is our bond, as is our signature. This dimension of our business, linked to the art of underwriting, is more important than some observers would have people believe.
One way to acquire this art is to share experiences – both good and bad – and to share doubts and questions. Artists always belong to a school, from which they learn their craft.
Like artists, we have to learn, imitate, mimic, and then innovate, in order to find our own style and create our own distinctive work.