InfoSec Lead
Space Executive
Singapore, SingaporeInternship29 Jul 2026
About this internship
Our client is a fast-growing technology group spanning fintech, blockchain/Web3, payments, custody, stablecoins and they are hiring an InfoSec Lead to build and own security for the business as it scales into new regulated territory.
Role Overview
The Information Security Lead is a senior player-manager responsible for establishing and owning the information security policy framework and ISMS. This role leads ISO 27001:2022 certification, governs identity and access management, and ensures security standards are embedded across all engineering teams.
Key Responsibilities
Security Policy and ISMS Ownership
Establish and maintain the information security policy framework, ISMS risk register, risk treatment plan, and Statement of Applicability (SoA)
Lead the organisation through ISO 27001:2022 certification and ongoing surveillance audits; coordinate all departments on control implementation and evidence
Conduct periodic policy reviews to ensure alignment with regulatory requirements and evolving threat landscapes
Identity, Access and Secure Development
Design and implement IAM controls including SSO, MFA, and PAM; govern user provisioning and access review processes
Define secure development standards (e.g. OWASP); conduct security architecture reviews and threat modelling with the applications team
Configure and maintain email security gateways and endpoint protection platforms
Security Operations Oversight and Support
Provide strategic direction and escalation support to the Senior Security Engineer and SOC team
Review security incident post-mortems and ensure effective remediation
Manage security service providers and vendors, including MSSPs and penetration testing firms
On-call availability required to support 24x7 incident response coverage
Requirements
Experience
10+ years of progressive information security experience, with 3+ years in a lead or management role
Demonstrated experience designing and implementing an ISMS and leading ISO 27001:2022 certification programmes
Experience establishing IAM frameworks (SSO, MFA, PAM) and managing external audits and regulatory examinations
Proven experience leading incident response, containment, and post-incident reviews in a production environment
Experience managing MSSPs, penetration testing firms, and security tooling vendors; regulated industry background preferred
Technical Skills
ISMS design and operation: risk register, SoA, control framework, continual improvement
IAM platforms: SSO (e.g. Okta, Azure AD or equivalent), MFA, PAM (e.g. CyberArk, BeyondTrust, or equivalent)
Secure development frameworks: OWASP, SANS CWE Top 25
Security architecture review methodologies and threat modelling
Email security gateways and endpoint protection platforms
ISO 27001:2022 control framework implementation across all domains
Qualifications
Bachelor's degree or higher in Information Security, Computer Science, or a related discipline
CISSP or CISM strongly preferred