Job Description
Purpose
Reporting to the APAC RISO, the GI APAC RISO serves as the dedicated cybersecurity partner for Chubb's General Insurance business across Asia Pacific, spanning 14 markets.
The role sits at the intersection of the APAC Security leadership team and GI Technology leadership, providing a direct security interface to the GI CIOs, COOs, CROs, and country Business Leaders.
As a leading global insurer operating across complex regulatory environments, Chubb faces a range of information security risks, including sophisticated attacks, intellectual property theft, as well as a range of commoditized threats.
The key responsibilities will include overseeing the delivery of the company’s Cybersecurity Programme, performing risk assessments and assurance activities, monitoring cybersecurity vulnerabilities and threats, and acting as trusted security risk advisor to the regional executives and business organizations. The focus of the role will be on developing a heightened security culture within the region. This will include fostering broad-based knowledge and ownership of security by staff throughout the General Insurance business lines and subsidiaries in the Asia Pacific region.
This role will involve working at all levels of the organization, including engaging with the business executive team and country Board of Directors to increase their awareness of security matters and obtain their support with CISO risk priorities.
The RISO is responsible for leading and developing a high-performance security team that can support the region's current and future requirements. The incumbent will lead a team of 5 information security managers covering country security and will closely collaborate with group function security roles.
Responsibilities
GIS Programme Deployment
- Govern and assure the Security programme across the 14-market APAC General Insurance portfolio, ensuring effective deployment and monitoring of Chubb's GIS requirements.
- Monitor implementation of CISO risk priorities owned by General Insurance CIOs and IT delivery teams
- Ensure business requirements and operational context are represented in global security plans, and roadmaps.
- Provide the APAC RISO with visibility and insights on program deployment, risk posture, and emerging security requirements.
Incident Response
- Collaborate with the Global SOC, Privacy function, APAC RISO, and COG executive teams in response to information security incidents. .
- Plan, coordinate, and facilitate cyber resiliency Tabletop Exercises (TTX) for COG markets in alignment with APAC RISO and Global CISO frameworks.
Assurance, Assessment, and Advisory
- Assess and evaluate the cyber risk and control position across APAC COG markets
- Manage security assurance over IT project delivery across the COG portfolio, including oversight of technology security reviews, penetration testing, vulnerability assessments, and red teaming.
- Ensure cybersecurity regulatory requirements specific to COG markets are understood, tracked, and met; lead regulatory inquiries and reviews as the security authority.
- Advise business leadership on external cyber control enquiries from regulators, brokers, and partners.
- Provide security audit expertise for audits impacting the COG portfolio and ensure RISO-owned findings are systematically remediated.
Cyber Governance and Risk Reporting
- Maintain and report on cybersecurity metrics, escalating material risks and issues to the APAC RISO and COG technology leadership.
- Lead COG security governance forums, producing quality materials and driving improvement outcomes.
- Present cyber risk posture, priorities, and programme status to COG regional business reviews, Risk Management Committees, and country Board meetings.
- Support Third-Party Cyber Risk Management assurance activities across the COG portfolio, partnering with the Group program.
- Manage and oversee security policy exceptions and derogations for the COG portfolio.
- Monitor the external threat landscape and ensure COG executive leadership are regularly informed of relevant emerging threats and vulnerabilities.
Security Culture and Awareness
- Drive security culture and awareness within COG APAC, partnering with the global security awareness programme to address COG-specific themes, behaviours, and regional requirements.
Transformation and Integration
- Provide security expertise to COG executive management on transformation programs, technology integration, and M&A activities affecting the COG portfolio.
Stakeholder Management
- Maintain effective relationships with COG senior business leaders across the region, including CIOs, COOs, CROs, country Presidents, and Business Executives.
- Influence COG regional executives to prioritise and support cybersecurity risk management improvements.
- Engage with Data Protection & Privacy, Compliance, Legal, and 2nd Line Risk on information and cyber security matters affecting the COG portfolio.
- Represent COG security interests in APAC RISO leadership team discussions and relevant Group security forums.
Leadership
- Lead and develop a team of country information security managers across the COG APAC portfolio, setting clear accountabilities, expectations, and performance standards.
- Collaborate closely with the APAC Technical Security and Cyber Risk & Assurance teams to leverage regional capabilities and ensure consistent security delivery across the COG portfolio.
- Foster a culture of continuous improvement, inclusivity, and high performance within the COG security team.
- Build a pipeline of internal security talent through coaching, leadership, and feedback.
- Bachelor’s degree in Computer Science, Information Systems, Information Technology, or other related disciplines (Desired).
- Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM) and/or equivalent. (Desired).
- Cybersecurity Fundamentals (CSX) certificate (Desired).
- Knowledge of Insurance Business (Desired).
- 15+ years, hands-on, broad-based information security experience.
- Demonstrated experience leading security teams across multiple markets
- Experience presenting cyber risk to executive leadership, Risk Management Committees, and Boards of Directors.
- Strong Information & Cyber security expertise with in-depth understanding of industry standards and practice: ISO 27000, NIST SP 800 / CSF, ISF SoGP.
- Previous experience in implementing and leading Information Security programs across geographic portfolios aligning country to region and global requirements.
- A self-starter with strong interpersonal skills and the ability to work independently and in a matrixed format.
- Experience working in large multinational organisations.
- Strong verbal and written communication and presentation skills, including providing technical information effectively with non-technical audiences.
- Strong ability to influence a variety of stakeholders in relation to Chubb’s GIS Program requirements including Country and Geographic Business Lines leadership and country Technology management.
- Experience with Asia region related regulatory compliance for Information and Cyber security.
- Technical security expertise and understanding of cyber controls and processes.
- Threat and Vulnerability Management: Security analysis and vulnerability assessment – Application scans, Security Patching & Vulnerability assessments.
- Ability to approach security problems and drive positive outcomes in relation to Application Security, Infrastructure Security, Vulnerability Management is critical.
- The successful candidate will also need to be familiar with working effectively in AGILE, fast-paced environments.