BAT is evolving at pace into a global multi-category business. Our purpose is to create A Better Tomorrow™ by Building a Smokeless World.
To achieve our ambition, we are looking for colleagues who are ready to join us on this journey! Tomorrow can’t wait, let’s shape it together!
British American TobaccoDBShas an exciting opportunity for an APMEA Regional Information Security Officer in Sunway City
The APMEA Regional Information Security Officer plays a pivotal role in managing and supporting Cyber risk and compliance activities across APMEA. This role ensures that cyber and IT risks are effectively identified, assessed, mitigated, and monitored, while maintaining alignment with internal standards and regulatory requirements (e.g. SOx, GDPR, SWIFT, PCI-DSS). The position involves close collaboration with APMEA, IDT Services, senior leadership, and external collaborators to embed a culture of proactive risk management and cybersecurity awareness.
Your key responsibilities will include:
- Lead a team of 2 employees to manage day-to-day cyber risk management, ensuring risks are recorded in the risk management tool (IRM) and integrated into enterprise risk frameworks (ERM risk reporting, GRMC, Control Navigator).
- Ensure the risk assessment process is based on cybersecurity best practise and standards, supporting the team to conduct risk assessments (SATs) for all new and existing technology, supporting the business to implement and run appropriate controls.
- Conduct business process cyber risk assessments, monitor emerging threats, and oversee mitigation activities.
- Provide expert advice on cybersecurity standard processes and risk management strategies, guiding the integration of security controls across technical and non-technical departments.
- Ensure compliance with internal policies, industry standards, and regulatory requirements.
- Lead cyber engagement activities for 1 DBS LT member. Provide detailed risk reporting (e.g. KRIs, risk status, remediation status) through risk reporting forums, maintain governance processes to ensure visibility and accountability.
- Support internal and external audit readiness.
- Promote cybersecurity awareness through training programmes and staff engagement. Ensure regional and functional training awareness programmes are in place and integrated with the global awareness and training programme.
- Participate in incident response and post-incident evaluations.
- Collaborate with team members across Business, IDT, Legal, Compliance, and Audit functions.
- Collaborate with central Cyber functions (GRC, Cyber Defence Centre, Architecture & Engineering, and Cyber OT) to ensure strategic cyber processes and tools are successfully implemented across the business. Cascade implementation requirements to team members and oversee delivery for APMEA.
What are we looking for?
- 10+ years of professional experience in cyber security/IT with a record of increasing scope and responsibility.
- Experience leading teams.
- Experience managing and communicating with global teams.
- Ability to translate technical language into readily understandable language for business users.
- Experience assessing cyber risks of projects, vendors and technologies.
- Experience with and understanding of cyber security management, technologies, architecture and audits.
- Knowledgeable of cyber security aspects related to networking, application development, ops, incident response, 3rd party vendor management and OT.
- Understanding cloud and SaaS configuration management and risk reduction (focus on Azure and AWS) and how to protect and detect potential threats in those environments.
- Ability to think clearly, prioritise and make decisions under time-sensitive and high-pressure conditions.
- Business insight, ability to articulate both businesses, commercial and technical ideas clearly and simply.
- Familiarity with network and system administration, including configuring and maintaining secure network infrastructure.
- Understanding of encryption technologies, secure coding practices, and security architecture design.
- Understanding of configuration for network devices, security tools, such as firewalls, intrusion detection systems, and antivirus software.
- Project Management experience in cyber security or IT.
What we offer you?
- We offer a market leading annual performance bonus (subject to eligibility)
- Our range of benefits varies by country and includes diverse health plans, initiatives for work-life balance, transportation support, and a flexible holiday plan with additional incentives
- Your journey with us isn't limited by boundaries; it's propelled by your aspirations. Join us at BAT and become a part of an environment that thrives on internal advancement, where your career progression isn't just a statement – it's a reality we're eager to build together. Seize the opportunity and own your development; your next chapter starts here.
- You'll have access to online learning platforms and personalized growth programs to nurture your leadership skills
- We prioritise continuous improvement within a transformative environment, preparing for ongoing changes
WHY JOIN BAT?
We’re one of the few companies named as a Global Top Employer by the Top Employers Institute – certified in offering excellent employee conditions.
Collaboration, inclusion and partnership underpin everything we do here at BAT. We are looking forward to enabling every individual to thrive, regardless of gender, sexual orientation, marital or civil partnership status, gender reassignment, race, religion or belief, colour, nationality, ethnic or national origin, disability, age, skills, experience, education, socio-economic and professional background, veteran status, perspectives and thinking styles. We know that embracing talent from all backgrounds is what makes us stronger and best prepared to meet our business goals.
We see the career breaks as opportunities not obstacles. Through The Global Returners program, we support professionals looking to restart their careers after an extended absence from the workforce (e.g. time out caring for family, parental leave, national service, sabbatical and/or starting an own venture).
Come bring your difference and see what is possible for you at BAT. Learn more about our culture and our award winning employee experience here.
If you require any reasonable adjustments or accommodations to help you perform at your best during the recruitment process, you are encouraged to notify us. We are fully committed to support you by making appropriate arrangements for you to demonstrate your full potential.