Anthony Choy, Kum - Tong

Director, Cybersecurity GRC - Global
Singapore, SG.

About

Highly accomplished and pragmatic Director with over two decades of progressive experience in Cybersecurity GRC, IT Governance, and Program Management, seeking to leverage deep expertise in strategic planning, risk mitigation, and large-scale program delivery. Proven leader in establishing robust security postures, driving compliance initiatives (ISO27001, NIST, COBIT), and managing complex global IT transformations with a focus on measurable business value and operational excellence. Adept at leading cross-functional teams and integrating advanced security frameworks to safeguard critical assets and ensure regulatory adherence.

Work

Cognizant Technology Solutions (APAC) Pte Ltd
|

Assistant VP, Corporate & Business Info Security GRC – Global Strategy & Technology

Singapore, Singapore, Singapore

Summary

Led global IT Governance, Risk, and Compliance (GRC) strategy and implementation for Corporate & Business Info Security across APAC, ensuring alignment with global CISO directives and program objectives.

Highlights

Headed the establishment and P&L operation of IT Governance and Portfolio & Program Management Offices for Avaya and AT&T, building integral policies, standards, processes, controls, and metrics from inception.

Directed the program management and implementation of Organizational IT & Cyber Security Risks and Controls, enhancing the security postures of all ICT systems and operations.

Conducted comprehensive security gap analyses and technical reviews, identifying and mitigating critical IT & Cyber Security risks to improve organizational security posture and maturity.

Collated, validated, and reported key security matrices, risk indicators, and findings at the global level using Metric Stream GRC toolkit, providing transparent oversight.

Customized and executed annual ISO27001 ISMS, NIST, CISA, and CSTA Audits, Assurance & Reporting, ensuring compliance with corporate security policies and directive requirements.

Measured and improved organizational IT Portfolio & Program Management competency levels, elevating PMO Continuum from Monitored to Optimized, boosting customer confidence and business performance by up to 70%.

IT Contractor
|

Consulting and Competency & Capability Development Training

Global, Global, XX

Summary

Provided specialized IT and Program/Project Management consulting and training to corporate clients, focusing on enhancing capabilities and strategic alignment.

Highlights

Instructed and coached corporate clients on IT Program & Project Financials, Earned Value Management (EVM), and Program/Project Recovery methodologies.

Delivered training on ISO 38500 IT Governance, ISO 27001 ISMS Audit & Certification, NIST, CISA, COBIT Controls, and ISO9001 IT Quality Assurance & QMS frameworks.

Educated teams on PMI Organizational Program & Project Management Maturity Model (OPM3) and PMBOK Framework & Methodology for improved project delivery.

Assessed and guided organizational PMO competency, capability, and maturity using PMI OPM3 Product Suite® Toolkit for strategic improvement.

Avaya (Singapore) Pte Ltd / Avaya Inc.
|

Regional Director, IT Governance & Program Management Office – Global Services (APJ & EMEA)

Singapore, Singapore, Singapore

Summary

Directed IT Governance and Program Management Office activities across APJ & EMEA, leading strategic and tactical initiatives for IT and Cyber Security.

Highlights

Customized and implemented ISO38500, ISO27001, NIST, CIS, and CISA IT & Cyber Security Risks Audit & Assurance Frameworks, enhancing regional security postures.

Led the development and adoption of enterprise-wide Risk Frameworks, Directives, Methodologies, Processes, and Requirements, ensuring compliance with ISO27001, PCI-DSS, PDPA, and other privacy laws.

Provided strategic risks advisory and guidance to CXOs and stakeholders, actively shaping cyber risk strategies and roadmaps across the organization.

Program-managed and implemented the Enterprise Cyber Security Program, including Tabletop Simulation exercises, to safeguard against internal and external threats and vulnerabilities.

Planned, coordinated, and executed annual ISO 27001 ISMS / NIST / CIS / CISA audits, assessments, and reporting, verifying alignment with security architecture models.

Established and supervised formal vulnerability management, penetration testing, and security posture assessment programs, proactively identifying and addressing risks.

AT&T (Singapore) Pte Ltd / AT&T Inc.
|

Senior Manager, IT Portfolio & Program Office

Singapore, Singapore, Singapore

Summary

Managed the IT Portfolio & Program Office, overseeing strategic planning, financial oversight, and performance management for IT initiatives across APJ.

Highlights

Directed and P&L-executed Global/Regional multi-phased Systems & Software Integration and Telecoms programs with a Total Contract Value (TCV) of SGD 45M.

Ensured consistent, predictable, and transparent program delivery with minimal escalation across a portfolio of highly correlated and interdependent programs.

Managed IT PMO governance, methods, P&L operations, and reporting, optimizing demand fulfillment, resource scheduling, and workload balancing.

Implemented organizational IT Balanced Scorecard KPI Measurement & Reporting to align IT performance with strategic business objectives.

AT&T (Singapore) Pte Ltd / AT&T Inc.
|

Program Manager, Consulting & Integration Services Delivery

Singapore, Singapore, Singapore

Summary

Managed the end-to-end delivery of consulting and integration services programs, ensuring successful project execution and client satisfaction.

Highlights

Oversaw the full lifecycle of consulting and integration service delivery, from pre-contract and requirements analysis to scoping, planning, execution, and closure.

Managed project financials, costing, scheduling, and controls, ensuring projects remained within budget and on schedule.

Implemented robust monitoring, tracking, and reporting mechanisms for all program phases, providing transparent updates to stakeholders.

Facilitated seamless transitioning and handover of completed projects, ensuring operational continuity and client acceptance.

Digital Equipment Corporation (APAC) Pte Ltd
|

Consulting Manager, APAC Technology & Solutions

Singapore, Singapore, Singapore

Summary

Managed technology and solutions consulting engagements across the APAC region, driving client success through expert advisory and implementation.

Highlights

Led consulting teams in delivering complex technology solutions, advising clients on strategic IT initiatives and system optimizations.

Managed client relationships and project delivery, ensuring high levels of satisfaction and successful outcomes for technology implementations.

Developed and presented solution proposals, aligning technology capabilities with client business objectives to achieve tangible results.

Provided expert guidance on enterprise system and network architectures, enhancing client infrastructure and operational efficiency.

Digital Equipment Corporation (APAC) Pte Ltd
|

Senior Consultant, Enterprise System & Network – Banking & FSI

Singapore, Singapore, Singapore

Summary

Provided expert consulting for enterprise system and network solutions specifically for clients in the Banking & Financial Services Industry (FSI).

Highlights

Consulted with Banking & FSI clients on critical enterprise system and network infrastructure projects, ensuring high availability and security.

Designed and implemented robust network solutions, optimizing performance and reliability for financial transactions and data integrity.

Analyzed client requirements and recommended tailored technology solutions to meet specific industry regulations and business needs.

Collaborated with project teams to ensure seamless integration of new systems within complex financial environments.

Digital Equipment (Singapore) Pte Ltd
|

Software Specialist, JDE / ORACLE EBS ERP Integration – Manufacturing, Logistics & Supply Chain

Singapore, Singapore, Singapore

Summary

Specialized in JDE and Oracle EBS ERP integration, providing technical expertise for manufacturing, logistics, and supply chain operations.

Highlights

Implemented and integrated JDE and Oracle EBS ERP solutions, optimizing business processes in manufacturing, logistics, and supply chain.

Developed custom software modules and configurations to meet specific operational requirements and enhance system functionality.

Provided technical support and troubleshooting for ERP systems, ensuring smooth operations and minimal downtime.

Collaborated with cross-functional teams to analyze business needs and translate them into effective ERP system improvements.

Monsanto Company (Singapore) Pte Ltd
|

SW Analyst / Programmer, Business Planning & Control System (BPCS) ERP Implementation - Southern Asia

Singapore, Singapore, Singapore

Summary

Served as a Software Analyst/Programmer, focusing on the implementation of Business Planning & Control System (BPCS) ERP in Southern Asia.

Highlights

Implemented and configured BPCS ERP modules, streamlining business planning and control processes across Southern Asia operations.

Developed and maintained software applications, ensuring alignment with business requirements and improving operational efficiency.

Analyzed system performance and user needs, proposing and implementing enhancements to the ERP system.

Provided technical support and training to end-users, facilitating effective adoption of new ERP functionalities.

Education

University of Houston, Victoria, Texas
Victoria, Texas, United States of America

Bachelor of Business Administration (BBA)

Computer Science & Info Systems

Grade: 3.74 GPA (2nd Upper Honors)

Courses

Computer Science

Information Systems

British Computer Society
N/A, N/A, XX

UK Professional Higher Diploma, Part I

Computer & Info Science

Courses

Computer Science

Information Science

Languages

English
Cantonese
Mandarin
Bahasa Malay

Certificates

Certified Cloud Security Professional (CCSP®)

Issued By

(ISC)2

Certified Information Security Manager (CISM®)

Issued By

Information Systems Audit & Control Association (ISACA)

Google Cloud Computing Architectures, Core Infrastructures, Administration, Kubernetes Services and Security Training

Issued By

Google Cloud Program Academy

Certified in the Governance & Assurance of Enterprise IT (CGEIT®)

Issued By

IT Governance Institute (ITGI)

UK OGC Foundation & Advanced Certificates in IT Program and Project Support Office

Issued By

British Computer Society

PMI Certified Organizational Project Management Maturity Model (OPM3®) Consultant

Issued By

Project Management Institute (PMI)

Chartered IT Professional (CITP®)

Issued By

British Computer Society

UK OGC Practitioner Certificate in ISO 27001 ISMS & IT Security and Risks Assurance

Issued By

British Computer Society

PMI Certified Organizational Project Management Maturity Model (OPM3®) Assessor

Issued By

Project Management Institute (PMI)

Cisco Certified Inter-Network Professional (CCIP®) Service Provider

Issued By

Cisco Networking Academy

Cisco Certified Network Associate (CCNA®)

Issued By

Cisco Networking Academy

Skills

IT Governance & Compliance

ISO 38500, COBIT Controls, ISO 27001 ISMS, NIST-CSF, CIS Controls, CSA IT & Cyber Security Audit, SOX 404, PCI-DSS, FIPS, MAS TRM, SG & PRC Cybersecurity Act, SG PDPA, PRC PIPL, EU GDPR, IT Quality Assurance (ISO 9001), Compliance Auditing, Risk Management Frameworks.

Cybersecurity & Info Security

Cyber Security Audit, Security Posture Assessment, Risk Appetite, Security Architecture & Design, Security Gaps Analysis, Threat Intelligence Analysis, Incident Triage & Response, RCA, Forensic Investigations, SIEM (LogRythm, SolarWinds), SOAR (CrowdStrike), MITRE ATT&CK, Vulnerability Management, Penetration Testing, Secure Software Development Life Cycle (SSDLC), DAST, IAST, VSPT, Security-by-Design, Privacy-by-Design, Identity & Access Management, Zero Trust Network Architectures, CASBs, Cryptography, Network Security, Web Application Firewalling, Malware & APTs Detection, OS & Kernel Hardening, Red/Blue/Purple Teaming, Tabletop Simulation Exercises, Disaster Recovery, Business Continuity.

Program & Project Management

PMI Program & Project e2e Management, IT Portfolio & Program Management Office (PPMO), PMI OPM3 Toolkit, PMBOK Framework, Agile-SAFe, Project Financials & Costing, Scheduling, Execution, Controls & Audit, Monitoring & Tracking, Reporting, Transitioning & Handover, P&L Operations, Demand Fulfillment, Resource Planning, KPI Tracking & Reporting, Dashboard Reporting, Earned Value Management (EVM), Project Recovery.

Enterprise IT Solutions

ERP (BPCS, JDE, Oracle EBS & Fusion, SAP ECC, S4/HANA), CRM (Siebel, Salesforce), ITSM (BMC Remedy, HP OpenView), BSS/OSS (Amdocs, Clarity Telecoms), Cloud Computing (AWS, GCP, Kubernetes), Network Operations, Data Center Management, Infrastructure Programs, Virtualization, High-Availability Clustering.

Consulting & Strategy

Strategic IT Planning, Business & IT Alignment, Solutions Consulting, Scoping, Benefits & Values Selling, Presales & Solutions Engineering, Proposal & Bidding, Lab POCV Validation, Outsourcing (ITSM), Organizational Transition & Transformation Management.

Leadership & Stakeholder Management

Pragmatic Decision Making, Innovation, Chief Communicator, Empathic People Manager, Stakeholder Engagement, Cross-functional Collaboration, Mentoring, Training & Coaching, Strategic Prioritization, Executive Reporting.