About the role
The VP, Security Operations (AI Transformation) Lead will own the strategic evolution of the bank's Security Operations Centre, driving it towards a highly automated, intelligence-led, and resilient cyber defense capability. This executive role is accountable for setting the SOC vision, defining its multi-year transformation roadmap, and ensuring alignment with the bank's business objectives and regulatory obligations.
BankingOnsite
Key Responsibilities
- Define and lead the SOC transformation strategy and roadmap, aligning with enterprise security strategy, risk appetite, and regulatory requirements (e.g. MAS TRM, NIST, ISO 27001, MITRE ATT&CK).
- Oversee end-to-end Security Operations functions (monitoring, detection, incident response, threat intelligence integration, and SOC tooling) with a focus on capability uplift and scalability.
- Drive modernization initiatives including SOAR implementation, Agentic SOC, advanced analytics, and automation to increase efficiency, reduce mean time to detect/respond, and improve quality of investigations.
- Partner with data and platform teams to design and leverage modern data lake architecture for centralized security telemetry, advanced analytics, and long-term hunting and forensics.
- Introduce and govern agentic capabilities (e.g. autonomous or semi-autonomous analytic and response agents) to augment analysts, orchestrate complex workflows, and enable continuous threat detection and response at scale.
- Establish and govern SOC performance frameworks, including KPIs, KRIs, and maturity models, providing regular reporting and insight to senior management and risk committees.
Requirements
- Degree in Information Security, Computer Science, Engineering, Data Science, or related field
- Strong cybersecurity experience, with significant tenure leading Security Operations or cyber defense functions, including prior experience at VP level or equivalent preferably within financial or large enterprise environments.
- Proven track record delivering large-scale SOC modernization or transformation programme covering tooling, operating model, and talent uplift in a complex or regulated environment, preferably banking or financial services.
- Demonstrated experience working with modern data platforms (e.g. security data lakes, big data pipelines, streaming architectures) to aggregate, analyze, and operationalize large volumes of security telemetry.
- Practical experience conceptualizing or deploying agentic or AI-driven capabilities in Security Operations, such as autonomous playbooks, investigative copilots, or AI-assisted detection and response.
- Deep expertise in SOC technologies (SIEM, EDR, IDS/IPS, SOAR, threat intelligence platforms) and their integration into an enterprise security stack.