
Cybersecurity and technology risk leader with 25+ years at global banks
Send a job offer directly to this candidate
Cybersecurity and technology risk leader with 25+ years at global banks, including Standard Chartered and JP Morgan Chase. Head of Information Cyber Security and Technology Risk Transformation at SCB. Leads enterprise cyber strategy, technology risk governance, and operational resilience, and reports to the CISO, CIO, and board risk committees. Built and led multidisciplinary security teams across APAC and global functions.
Signature outcomes: governed access for 5.2M+ accounts across 500+ applications; cut cyber recovery times by 68% across 1,200+ mission-critical applications; and achieved ~85% vulnerability remediation within SLA across 1,500+ applications at JP Morgan.
Regulatory, Legal Teams, Public affairs experience, policy influence and regulatory advocacy also consultations with MAS, HKMA, APRA, RBI, and FSA. Works across NIST, ISO 27001, COBIT, and MITRE ATT&CK. Chaired and lead, Cyber Risk agenda across the bank, not limited to the existing scope, due to vast experience in Cyber Security and Resiliency agendas. Strong expertise across cybersecurity governance, incident response, architecture risk assessment, and security testing.
Head – Information Cyber Security & Technology Risk Transformation at Standard Chartered Bank (2021-07 – Present)
Capacity of Key Lead, enterprise-wide cybersecurity and technology risk initiatives across global banking platforms and digital transformation programs. Define and drive cybersecurity strategy, policies, and governance frameworks, aligning with regulatory expectations and organisational risk appetite via Legal Teams, Public affairs engagements. Provide strategic advisory to senior leadership on cyber posture, risk exposure, and control effectiveness.
As a key contributor to Risk Management, with end goal to establish and oversee technology risk monitoring frameworks, ensuring visibility into emerging threats, vulnerabilities, and systemic risks. Drive proactive risk identification and mitigation strategies, strengthening organisational resilience against evolving cyber threats. Enhance early warning mechanisms and risk intelligence capabilities (driving Proactive than detective agenda across the bank) across the enterprise.
Perform threat-based risk assessments across application, infrastructure, and cloud architectures. Review and endorse secure system designs, ensuring adherence to security-by-design principles. Assess risks including ransomware, data leakage, insider threats, and account compromise across enterprise systems.
Key contributor for enterprise incident response and crisis management, coordinating cross-functional teams during major cyber and technology incidents. Oversee post-incident reviews and remediation programs, embedding lessons learned into control frameworks. Strengthen business continuity and cyber resilience capabilities across critical systems.
Conduct tabletop exercises, simulations, and cyber drills to strengthen organizational resilience. Collaborate with SOC, threat intelligence, and red teams to enhance detection and response capabilities. Establish and enhance technology risk and cybersecurity frameworks, ensuring alignment with ISO 27001, NIST, and internal governance standards.
Oversee control effectiveness, risk assessments, and remediation programs across applications, infrastructure, and cloud environments. Ensure robust risk governance and reporting to senior leadership and risk committees. Embed security controls into CI/CD pipelines, including SAST, DAST, SCA, and secrets management.
Infrastructure / Application Code and automated deployment pipelines in collaboration with engineering teams. Drive shift-left security practices, reducing vulnerabilities early in development lifecycle. Engage with Regulators, Legal Teams, Public affairs, audit bodies, and industry stakeholders, representing the organisation in cybersecurity and risk forums.
Collaborate with external partners and vendors to strengthen ecosystem resilience and third-party risk management. Lead and chaired, develop high-performing, multidisciplinary cybersecurity and risk teams. Develop and deliver cybersecurity awareness and training programs across business and technology teams.
Promote a strong security culture and improve organizational cyber hygiene.
Head of Information & Cyber Security Resilience at Standard Chartered Bank (2019-05 – 2021-06)
Master's in Information Technology (IT)