Principal / Senior Information Security Consultant (Risk Management, Security Architecture and Production Security)
Sony
·Today
- Location
- Sony SGP HQ, Perennial Business City, Singapore
- Type
- Full-time
- Department
- Engineering
- Seniority
- Senior
- Experience
- 8+ years
- Source
- Workday
Description
We look for the risk-takers, the collaborators, the inspired and the inspirational. We want the people who are brave enough to work at the cutting edge and create solutions that will enrich and improve the lives of people across the globe. So, if you want to make the world say wow, let's talk.
The conversation starts here. If this role matches your ambitions and skillset, let's get started with your application. Take a look at our other open positions too. Our many opportunities can lead to infinite possibilities.
The Principal/Senior Information Security Consultant provides regional subject-matter leadership and trusted advisory services across risk management, security architecture and production security. The role enables Asia Pacific operating companies to identify, assess and manage information security risks, implement effective controls, and make informed risk decisions that protect Sony information assets and support resilient business operations.
The scope covers business applications and infrastructure, manufacturing and operational technology environments, critical information assets, and third-party suppliers and services. The role works with regional and global information security teams and advises supported operating companies on compliance with applicable Sony information security policies, standards and risk requirements.
What you will be doing
Deliver regional security services: Plan and execute assigned business-as-usual services and initiatives in accordance with approved priorities, service standards, key performance indicators and information security requirements.
Assess and manage risk: Lead business, technical and third-party security assessments; evaluate threats, vulnerabilities, control effectiveness and business impact; document risk findings; and recommend proportionate treatment options.
Provide security architecture and production-security advice: Review new projects, technology designs, infrastructure and manufacturing environments to ensure security requirements are incorporated and practical mitigation measures are defined.
Act as a subject-matter expert: Provide authoritative guidance in one or more information security domains, including complex, emerging or non-standard environments, and maintain current knowledge of relevant threats, technologies and practices.
Enable policy compliance: Advise supported operating companies on applicable Sony information security policies, standards and control requirements; identify implementation gaps; and support risk acceptance or policy-exception processes where required.
Lead initiatives and improve capability: Take end-to-end ownership of assigned regional or global initiatives, coordinate cross-functional contributors, monitor delivery and quality, and improve methods, templates and ways of working.
Influence stakeholders: Translate technical findings into clear business risk implications and recommendations for operating-company management, Information Systems, Legal, Privacy, Human Resources, Finance, Procurement and other stakeholders.
Maintain effective partnerships: Build productive working relationships with regional ISO teams, CISD and other global information security functions, operating-company information security managers, business owners and relevant third parties.
What you should have
Bachelor’s Degree in Information Security, Computer Science, Information Systems, Engineering or a related discipline, or equivalent relevant professional experience.
At least 8 years of progressive experience in information security, including substantial hands-on work in risk management, security architecture, production or operational technology security, governance, assurance or related disciplines.
Strong knowledge of risk assessment and treatment, security-control evaluation, governance and compliance frameworks, third-party risk management, and the management of remediation plans and residual risk.
Broad understanding of information security domains, with demonstrated expertise in at least three areas such as enterprise risk, cloud security, network security, application security, identity and access management, vulnerability management, manufacturing or operational technology security, or supplier security.
Expertise in latest AI tools and technology deployment is preferred
Experience assessing complex business and technical environments, analysing incomplete or conflicting information, and translating findings into practical, risk-based recommendations.
Working knowledge of governance, risk and compliance platforms, reporting and analytical tools, and standard productivity applications.
Proven ability to lead cross-functional initiatives, manage multiple priorities and deliver high-quality outcomes in a geographically distributed, multicultural environment.
Excellent written and spoken English, with strong facilitation, influencing, negotiation and executive-level communication skills; additional regional language capability is advantageous.
Professional certifications such as CISSP, CISM, CRISC, CCSP, ISO/IEC 27001 or equivalent are preferred.
Benefits you will have
Flexible work arrangement (because we understand Life happens)
Comprehensive medical benefits (including physical health screenings and term life insurance benefits)
AWS and variable bonus
Special staff purchase rates
Flexible benefits (so you can claim for that staycay or gym membership you’ve been eyeing)
Corporate social responsibility time off for 1 day each year to volunteer for a charity of your choice
Milestone gifts (such as long service award and marriage gift because we want to celebrate both your professional and personal milestones)
Wellness activities to promote healthy lifestyles
Curated training programmes to encourage continuous professional development
At Sony, we strive to create a place for you to realise your potential and inspire you to make positive impact through innovation, smart collaboration and boundless curiosity. We are looking for people who believe that they can enrich lives and help us achieve our purpose – fill the world with emotion, through the power of creativity and technology.