496 Cybersecurity Risk jobs in Singapore
Cybersecurity Risk Mgr
Posted today
Job Viewed
Job Description
Company description:
Synapxe is the national HealthTech agency inspiring tomorrow's health. The nexus of HealthTech, we connect people and systems to power a healthier Singapore.
Together with partners, we create intelligent technological solutions to improve the health of millions of people every day, everywhere. Reimagine the future of health together with us at
Job description:
Position Overview
The Senior Manager, Risk & Compliance supports the effective management of cybersecurity and IT risks across Cluster. The role is responsible for maintaining the risk register, coordinating audits, ensuring compliance with regulatory and internal requirements, and driving timely closure of risk and compliance issues. The position also plays a critical role in supporting the Cybersecurity Management Committee (CMC) and acts as a bridge between operational teams, regulators, auditors, and management to provide visibility and assurance on Clusters' cybersecurity risk posture.
Role & Responsibilities
Cybersecurity Management Committee (CMC) Secretariat
- Serve as the secretariat to the CMC, coordinating agendas, materials, and minutes.
- Ensure timely maintenance and reporting of the Cybersecurity Risk Register to the CMC.
- Track and follow up on risk-related action items arising from CMC meetings.
- Support CMC reporting obligations to senior management, MOH, and other authorities.
Risk Assessment & Tracking
- Maintain and update the Cybersecurity Risk Register, ensuring no overdue risks.
- Support and review risk assessments for IT, OT, and Medical Devices.
- Track remediation plans and escalate where delays or risks remain unresolved.
- Facilitate the annual CII risk assessment and submission to CSA.
Audit Coordination & Risk Remediation
- Coordinate internal and external audits (CCoP, AGO, etc.).
- Prepare reports, track follow-ups, and ensure timely closure of findings.
- Act as a point of contact with CRO, internal teams, and regulators for audit matters.
Policy Compliance & Governance
- Monitor compliance against MOH, CSA, and other sectoral requirements.
- Support the design and rollout of a cluster-wide compliance programme.
- Record and manage policy deviations, ensuring recertification is performed.
- Provide inputs to MOH on policy development and ensure alignment with sectoral policies.
Operational Risk & Oversight
- Support thematic reviews, annual planning, and SOP/policy updates.
- Assist in annual ERM Control Self-Assessments, including validation of results.
- Track IT/security-related findings from AGO and sectoral reviews.
- Support oversight of Synapxe 2LoD actions and reporting.
- Manage reviews and follow-ups of cybersecurity controls for PDPC breach cases.
Stakeholder Engagement & Reporting
- Build effective working relationships with regulators, auditors, and internal stakeholders.
- Prepare dashboards and compliance reports to update senior management.
- Act as a subject matter resource for operational teams on risk and compliance issues.
Requirements
- Experience:
- 8-10 years in Information Security, IT Risk, Audit, or related fields.
- Knowledge: Strong understanding of cybersecurity risk management, compliance frameworks, and sectoral regulations (CSA, MOH, PDPC).
- Certifications (preferred): CISSP, CISA, CISM, CRISC.
- Skills:
- Strong organisational and coordination abilities.
- Able to track and drive closure of risk, audit, and compliance matters.
- Good communication and stakeholder management skills.
- Analytical with strong attention to detail.
Apply Now
NOTE: It only takes a few minutes to apply for a meaningful career in HealthTech - GO FOR IT
LI-SYNX13Cybersecurity Risk Analyst
Posted today
Job Viewed
Job Description
Assurity Trusted Solutions (ATS) is a wholly owned subsidiary of the Government Technology Agency (GovTech). As a Trusted Partner over the last decade, ATS offers a comprehensive suite of products and services ranging from infrastructure and operational services, authentication services, governance and assurance services as well as managed processes. In a dynamic digital and cyber landscape, where trust & collaboration are key, ATS continues to drive mutually beneficial business outcomes through collaboration with GovTech, government agencies and commercial partners to mitigate cyber risks and bolster security postures.
As the Cybersecurity Risk Analyst, you will be involved in security risk analysis engagements or function independently in individual security risk analysis engagements.
Responsibilities:
- Perform threat modelling assessment to establish threat scenarios, actors and vectors.
- Assist in developing technical methodology to ensure high technological standards in risk analysis teams
- Perform comprehensive cybersecurity risk assessments to identify security gaps and recommend actionable remediation and mitigations.
- Provide expert security consulting, offering insights and guidance to customers on improving their overall cybersecurity posture.
- Create detailed technical reports and documentation outlining identified threats, potential impact, risk assessment findings, and recommended remediation steps.
- Engage relevant stakeholders.
- Stay current with emerging threats, vulnerabilities, and industry trends, continuously enhancing the organization's risk analysis capabilities.
Requirements
- Minimum of 3 years of experience in cybersecurity, with a focus on risk assessments, consultancy and GRC.
- Proven track record in leading and conducting security consultancy, including customer engagement, team management, and business development.
- Strong understanding of cybersecurity principles, frameworks, and best practices.
- Experience with industry standard threat modelling methodologies, such as OWASP, NIST, MITRE ATT&CK, STRIDE-LM.
- Good technical understanding of cloud platforms and technology.
- Excellent communication and interpersonal skills, with the ability to effectively interact with customers, team members, and senior management.
- Some prior experience in VAPT or red teaming will be a plus.
- Relevant certifications such as CISSP, CISSP-ISAAP, OSCP, or similar are highly desirable.
Join us and discover a meaningful and exciting career with Assurity Trusted Solutions
The remuneration package will commensurate with your qualifications and experience. Interested applicants, please click "Apply Now".
We thank you for your interest and please note that only shortlisted candidates will be notified.
By submitting your application, you agree that your personal data may be collected, used and disclosed by Assurity Trusted Solutions Pte. Ltd. (ATS), GovTech and their service providers and agents in accordance with ATS's privacy statement which can be found at: or such other successor site.
Benefits
- A wholly-owned subsidiary of GovTech.
- We promote a learning culture and encourage you to grow and learn.
Cybersecurity Risk Manager
Posted today
Job Viewed
Job Description
Job Title: Cybersecurity Risk Manager
We are seeking an experienced Cybersecurity Risk Manager to join our team. This is a key role that will be responsible for ensuring the robustness of our IT governance, cyber security, and regulatory compliance across our branch and with our Head Office in China.
Key Responsibilities:
- Compliance & Risk Evaluation: Review and assess our compliance with local regulatory obligations and Head Office requirements for IT risk management and cyber security.
- Ongoing Risk Management & Security Governance: Continuously monitor and evaluate IT risk exposures to ensure effective mitigation strategies that align with business goals and our organization's risk appetite.
- Policy Development & Implementation: Develop and implement IT security policies and procedures in compliance with MAS, PDPA, and Head Office requirements.
- Audit & Regulatory Coordination: Liaise with internal and external auditors, as well as regulatory bodies (e.g., MAS), to ensure full compliance with both Singapore and Chinese IT risk and cyber security regulations.
- Reporting: Prepare and present regular reports to senior management and Head Office on IT governance status, compliance initiatives, audit findings, and risk remediation progress.
Requirements:
- Education: Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field.
- Experience: Minimum of 8 years of experience in IT risk management, IT security, or IT audits within the banking industry.
- Regulatory Knowledge: Strong familiarity with local and Chinese regulations, including MAS TRM Guidelines, Cyber Hygiene requirements, PDPA, and China's IT risk and cyber security standards.
- Language Skills: Strong proficiency in written and spoken Chinese is required to interpret Head Office policies, draft reports, and liaise effectively with stakeholders in China.
- Certifications: Professional certifications in IT governance, risk management, or compliance (e.g., CISA, CISM, CRISC) are advantageous.
- Soft Skills: Strong problem-solving and collaboration skills, with a proven ability to work cross-functionally to implement effective IT risk and compliance strategies.
Cybersecurity Risk Specialist
Posted today
Job Viewed
Job Description
This is a critical position that requires an experienced cybersecurity expert to analyze and mitigate advanced threats targeting our client's web platforms.
- You will analyze large volumes of web traffic, identify patterns and anomalies, and collaborate with multiple stakeholders to implement effective mitigation strategies.
- Working closely with internal teams, you will deliver intelligence that informs product enhancements and maintains deep expertise in bot mitigation techniques and evolving threat landscapes.
The ideal candidate will have a strong analytical mindset, excellent communication skills, and a passion for cybersecurity. A bachelor's degree in Computer Science, Computer Engineer, IT, or related fields is required, along with a minimum 3 years of relevant working experience in Information Security Analyst.
Key responsibilities include:
- Analyzing web traffic data to detect and isolate advanced bot behaviors and automated attack patterns.
- Investigating anomalies and providing detailed reports to clients.
- Collaborating with clients to understand the business impact of automated threats and developing tailored mitigation strategies.
- Responding to incidents according to premium service-level agreements (SLAs).
- Presenting findings and guiding strategic decisions through regular client meetings.
We are looking for someone who can drive positive change and contribute to our team's success by applying their knowledge and skills in the field of cybersecurity.
Cybersecurity Risk Analyst
Posted today
Job Viewed
Job Description
Overview
Assurity Trusted Solutions (ATS) is a wholly owned subsidiary of the Government Technology Agency (GovTech). As a Trusted Partner over the last decade, ATS offers a comprehensive suite of products and services ranging from infrastructure and operational services, authentication services, governance and assurance services as well as managed processes. In a dynamic digital and cyber landscape, where trust & collaboration are key, ATS continues to drive mutually beneficial business outcomes through collaboration with GovTech, government agencies and commercial partners to mitigate cyber risks and bolster security postures.
Responsibilities
Perform threat modelling assessment to establish threat scenarios, actors and vectors.
Assist in developing technical methodology to ensure high technological standards in risk analysis teams
Perform comprehensive cybersecurity risk assessments to identify security gaps and recommend actionable remediation and mitigations.
Provide expert security consulting, offering insights and guidance to customers on improving their overall cybersecurity posture.
Create detailed technical reports and documentation outlining identified threats, potential impact, risk assessment findings, and recommended remediation steps.
Engage relevant stakeholders.
Stay current with emerging threats, vulnerabilities, and industry trends, continuously enhancing the organization's risk analysis capabilities.
Requirements
Minimum of 3 years of experience in cybersecurity, with a focus on risk assessments, consultancy and GRC.
Proven track record in leading and conducting security consultancy, including customer engagement, team management, and business development.
Strong understanding of cybersecurity principles, frameworks, and best practices.
Experience with industry standard threat modelling methodologies, such as OWASP, NIST, MITRE ATT&CK, STRIDE-LM.
Good technical understanding of cloud platforms and technology.
Excellent communication and interpersonal skills, with the ability to effectively interact with customers, team members, and senior management.
Some prior experience in VAPT or red teaming will be a plus.
Relevant certifications such as CISSP, CISSP-ISAAP, OSCP, or similar are highly desirable.
Join us and discover a meaningful and exciting career with Assurity Trusted Solutions!
The remuneration package will commensurate with your qualifications and experience. Interested applicants, please click "Apply Now".
We thank you for your interest and please note that only shortlisted candidates will be notified.
By submitting your application, you agree that your personal data may be collected, used and disclosed by Assurity Trusted Solutions Pte. Ltd. (ATS), GovTech and their service providers and agents in accordance with ATS’s privacy statement which can be found at: or such other successor site.
Benefits
A wholly-owned subsidiary of GovTech.
We promote a learning culture and encourage you to grow and learn.
#J-18808-Ljbffr
Manager, CyberSecurity & Risk Management
Posted today
Job Viewed
Job Description
At Otis, it’s our people that make us different. Come and join OTIS today and be part of the Forbes 2024 World's Best Employers!
Join the Otis family where collaboration, innovation, and empowerment help each individual and the company reach new heights.
Key Responsibilities
Execute the IAM/IGA vision:
Execute the Identity and Access Management (IAM) program roadmap that aligns with business objectives and risk tolerance
Manage the team:
Manage an outsourced team of identity specialists, engineers, and support fostering a culture of continuous improvement
Focus on continuous improvement , automation, and standardization of IAM processes
Vendor Management : Manage the on and offboarding of managed service provider personnel and oversee operations procedures
Vendor Orchestration:
Oversee and prioritize service delivery for four Managed Service and five Identity Product Vendors (OKTA, HYPR, Delinea, Saviynt, Entrust) and a host of cross-functional teams in infrastructure and business areas
Reporting and Communication:
Create and present reports and dashboards for senior management and other stakeholders on vendor performance, spending metrics, and compliance posture
Operational and Technical Oversight : Coordinate with Identity Engineering and Operations teams to understand vendor tasks and ensure third-party capabilities are aligned with internal initiatives
Oversee delivery of projects
and initiatives related to IAM systems upgrades, integrations, and automation
Monitor and enforce policies and standards:
Enforce policies and standards related to IAM, ensuring they meet both internal requirements and external regulations.
Oversee access review operations:
Lead and automate periodic access reviews and certification campaigns to validate that users still have appropriate permissions, reducing the risk of "privilege creep"
Ensure compliance:
Collaborate with audit and compliance teams to ensure adherence to relevant regulations and standards, such as GDPR, SOX, and NIST
Requirement
Min. 5 years of experience in cybersecurity, with significant time dedicated to IAM and identity governance (IGA)
Certified in CISSP/ CIAM/ CISM/ CRISC is highly preferred
Hands-on experience with major IAM /IGA platforms (e.g., Saviynt, Okta, Azure AD), on-premise and private/public cloud IaaS, PaaS platforms (e.g., Entra, Google Cloud)
Strong knowledge of security concepts, risk management, architecture, and regulatory frameworks (e.g., NIST, ISO 27001)
Excellent analytical and problem-solving abilities to troubleshoot and resolve complex issues and assess vendor performance, manage risks, and make data-driven decisions
Demonstrate ability to build consensus with a variety of key stakeholders, including business and technology leaders, to influence successful outcomes
Apply today to join us and build what’s next!
#J-18808-Ljbffr
Manager, CyberSecurity & Risk Management
Posted today
Job Viewed
Job Description
At Otis, it’s our people that make us different. Come and join OTIS today and be part of the Forbes 2024 World's Best Employers!
Join the Otis family where collaboration, innovation, and empowerment help each individual and the company reach new heights.
Responsibilities
Execute the IAM/IGA vision:
Execute the Identity and Access Management (IAM) program roadmap that aligns with business objectives and risk tolerance
Manage the team:
Manage an outsourced team of identity specialists, engineers, and support fostering a culture of continuous improvement
Focus on continuous improvement , automation, and standardization of IAM processes
Vendor Management : Manage the on and offboarding of managed service provider personnel and oversee operations procedures
Vendor Orchestration:
Oversee and prioritize service delivery for four Managed Service and five Identity Product Vendors (OKTA, HYPR, Delinea, Saviynt, Entrust) and a host of cross-functional teams in infrastructure and business areas
Reporting and Communication:
Create and present reports and dashboards for senior management and other stakeholders on vendor performance, spending metrics, and compliance posture
Operational and Technical Oversight : Coordinate with Identity Engineering and Operations teams to understand vendor tasks and ensure third-party capabilities are aligned with internal initiatives
Oversee delivery of projects
and initiatives related to IAM systems upgrades, integrations, and automation
Monitor and enforce policies and standards:
Enforce policies and standards related to IAM, ensuring they meet both internal requirements and external regulations.
Oversee access review operations:
Lead and automate periodic access reviews and certification campaigns to validate that users still have appropriate permissions, reducing the risk of "privilege creep"
Ensure compliance:
Collaborate with audit and compliance teams to ensure adherence to relevant regulations and standards, such as GDPR, SOX, and NIST
Qualifications
Min. 5 years of experience in cybersecurity, with significant time dedicated to IAM and identity governance (IGA)
Certified in CISSP/ CIAM/ CISM/ CRISC is highly preferred
Hands-on experience with major IAM /IGA platforms (e.g., Saviynt, Okta, Azure AD), on-premise and private/public cloud IaaS, PaaS platforms (e.g., Entra, Google Cloud)
Strong knowledge of security concepts, risk management, architecture, and regulatory frameworks (e.g., NIST, ISO 27001)
Excellent analytical and problem-solving abilities to troubleshoot and resolve complex issues and assess vendor performance, manage risks, and make data-driven decisions
Demonstrate ability to build consensus with a variety of key stakeholders, including business and technology leaders, to influence successful outcomes
Apply today to join us and build what’s next!
#J-18808-Ljbffr
Be The First To Know
About the latest Cybersecurity risk Jobs in Singapore !
Senior / Lead Cybersecurity Risk Analyst
Posted today
Job Viewed
Job Description
Assurity Trusted Solutions (ATS) is a wholly owned subsidiary of the Government Technology Agency (GovTech). As a Trusted Partner over the last decade, ATS offers a comprehensive suite of products and services ranging from infrastructure and operational services, authentication services, governance and assurance services as well as managed processes. In a dynamic digital and cyber landscape, where trust & collaboration are key, ATS continues to drive mutually beneficial business outcomes through collaboration with GovTech, government agencies and commercial partners to mitigate cyber risks and bolster security postures.
As the Cybersecurity Risk Analyst, you will be leading a team in security testing engagements or function independently in individual security testing engagements.
Responsibilities:
- Lead threat modelling assessment to establish threat scenarios, actors and vectors.
- Develop technical methodology to ensure high technological standards in risk analysis teams
- Mentor junior risk analysts during engagements to upskill them
- Perform comprehensive cybersecurity risk assessments to identify security gaps and recommend actionable remediation and mitigations.
- Provide expert security consulting, offering insights and guidance to customers on improving their overall cybersecurity posture.
- Create detailed technical reports and documentation outlining identified threats, potential impact, risk assessment findings, and recommended remediation steps.
- Engage relevant stakeholders.
- Stay current with emerging threats, vulnerabilities, and industry trends, continuously enhancing the organization's risk analysis capabilities.
Requirements
- Minimum of 8 years of experience in cybersecurity, with a focus on risk assessments, consultancy and GRC.
- Proven track record in leading and conducting security consultancy, including customer engagement, team management, and business development.
- Strong understanding of cybersecurity principles, frameworks, and best practices.
- Experience with industry standard threat modelling methodologies, such as OWASP, NIST, MITRE ATT&CK, STRIDE-LM.
- Good technical understanding of cloud platforms and technology.
- Excellent communication and interpersonal skills, with the ability to effectively interact with customers, team members, and senior management.
- Some prior experience in VAPT or red teaming will be a plus.
- Relevant certifications such as CISSP, CISSP-ISAAP, OSCP, or similar are highly desirable.
Join us and discover a meaningful and exciting career with Assurity Trusted Solutions
The remuneration package will commensurate with your qualifications and experience. Interested applicants, please click "Apply Now".
We thank you for your interest and please note that only shortlisted candidates will be notified.
By submitting your application, you agree that your personal data may be collected, used and disclosed by Assurity Trusted Solutions Pte. Ltd. (ATS), GovTech and their service providers and agents in accordance with ATS's privacy statement which can be found at: or such other successor site.
Benefits
- A wholly-owned subsidiary of GovTech.
- We promote a learning culture and encourage you to grow and learn.
VP / AVP, Specialist, Technology Risk (Cybersecurity), Risk Management Group
Posted today
Job Viewed
Job Description
Business Function
Risk Management Group works closely with our business partners to manage the bank's risk exposure by balancing its objective to maximise returns against an acceptable risk profile. We partner with origination teams to provide financing, investments and hedging opportunities to our customers. To manage risk effectively and run a successful business, we invest significantly in our people and infrastructure.
Technology is key to enabling the DBS vision of being the leading bank in Asia. We are constantly challenged by ever changing technology landscape, increasing customer sophistication / demands and introduction of new / updated regulatory requirements. We need passionate Technology Risk Managers who play a high impact role as second line function in enhancing the bank's technology risk and cybersecurity posture.
This includes identifying potential technology and cybersecurity risks associated with existing, evolving and new technology systems and business processes, assessing potential impacts and engaging with other technology leaders on the risk treatment options based on enterprise risk appetite. Risks and mitigation plans are reported to senior leadership for review and attention.
The Role
Experience in Cybersecurity principles, solutions and processes are essential for this position. The incumbent is a driven, self-starter, who plays an active role working in a dynamic environment with the Technology risk teams to conduct independent assurance of risk management and drive IT risk management initiatives. The role is expected to have a proven record of positively influencing stakeholders at all levels of the organisation and is responsible to promote risk culture.
Additionally, the incumbent needs to have analytical skills to assess information and identify potential risks, possess problem-solving skills to be able to determine how to reduce those risks, and introduce more forward-looking measures of risk.
The Incumbent should be inquisitive on risks and controls issues and rationalize their mitigation. Communication skills are important to inform management about potential risk issues, provide actionable reports, including articulating impact on policy changes. There will be frequent opportunities to represent Technology Risk's view in risk forums and different levels of risk committees. The demands and high-visibility nature of this position require an expert with a proven ability to work independently in a fast-paced environment and who can begin contributing immediately.
Responsibilities
- Work with stakeholders across Group Technology to manage Technology Risks relating to cybersecurity.
- Partner with first line peers to succinctly assess, frame and report on cybersecurity risks relative to risk appetite.
- Ability to review and challenge cybersecurity design, define and initiate stress testing against various risk scenarios.
- Ability to use analytical thinking to identify security gaps, risks, control issues and propose / review mitigation strategies.
- Conduct independent assurance to evaluate effectiveness of IT controls.
- Perform thematic second line assurance reviews, including short and targeted focused reviews for areas of topical and key concern.
- Oversight of remediation of issues arising from first line identification of control deficiencies, internal and external incidents, including deep dive reviews to identify root cause.
- Demonstrate strong judgment to balance being both a trusted advisor to the business and driving effective challenge.
- Champion risk awareness and best practices with various stakeholders to uplift risk culture in the organisation.
- Enhance the business' understanding of regulatory/compliance requirements and the implications to individual initiatives and the broader firm.
- Provide robust risk management oversight in supporting various internal, external audits and regulatory inspections / examinations.
- Monitor outstanding risk items and audit issues to ensure proper ownership and follow-up.
- Ability to work independently, prepare and write comprehensive reports for senior management on technology risk management activities and risk events for presentation to risk committees.
- Ability to communicate complex technology risk concepts in a clear and concise manner.
- Mentor more junior members of the team.
- Stay current on emerging cyber threats and potential implications to the organisation.
Requirements
- Degree holder in Information Technology, Computer Science or related discipline.
- Minimum 8-12 years of working experience in relevant field.
- Professional memberships and security or risk management certifications would be considered favourably (e.g., CISA, CRISC, CISSP, CISM, CCSP, etc.):
- (1) Technical Experience
- IT professional with good understanding of technology platform with specialisation in security domains
- Familiar with assessing or designing controls for AWS, GCP, Azure or other cloud services.
- Experienced with technical security solutions surrounding various technologies such as but not limited to: IDS, IPS, firewall management, anti-virus, content filtering, secure email solutions, network sniffing, log management & analysis, forensics, VPN, load balancing, routing, switching and network management.
- Prior experience in either banking, IT risk management, or security-related.
- Sound knowledge in regulatory requirements (e.g. MAS Notice 644, 655, and TRM guidelines) and industry standards/ frameworks such as ITIL, SANS, COBIT, NIST, ISO 27001/2, Cyber Security Act, Banking Act, Personal Data Protection Act.
- (2) Non-Technical Experience
- Superb interpersonal and communication skills that include active listening, writing and executive presentation skills.
- Excellent influencing and persuasion skills
- Proven critical analytical, including and the ability to express a point of view supported by data (with both technical and non-technical audiences)
- Comfort raising concerns early and knows when to escalate, including the ability to raise issues and facilitate constructive problem-solving at all levels of the organization.
- Experience in a first-line role at a financial institution or regulatory agency (preferred)
- Good planning and other project management skills, including strong organisation skills.
- Must be solutions oriented; ability to work with all levels of management and staff.
- Self-driven, passionate about hands-on learning on emerging technologies and its risks.
- Self-starter, performance-oriented individuals
- Passionate about driving change through innovation.
- General understanding of overall banking business
- (3) Work Relationship
- Support the Head of Unit in discharging the responsibilities of the team.
- Strong ability in knowledge sharing with peers.
- Contribute as a member of Team and collaborate with fellow team members and technology managers.
- Develop relationships with peer in the technology organisation.
Apply Now
We offer a competitive salary and benefits package and the professional advantages of a dynamic environment that supports your development and recognises your achievements.
VP / AVP, Specialist, Technology Risk (Cybersecurity), Risk Management Group
Posted today
Job Viewed
Job Description
Business FunctionRisk Management Group works closely with our business partners to manage the bank's risk exposure by balancing its objective to maximise returns against an acceptable risk profile. We partner with origination teams to provide financing, investments and hedging opportunities to our customers. To manage risk effectively and run a successful business, we invest significantly in our people and infrastructure.Technology is key to enabling the DBS vision of being the leading bank in Asia. We are constantly challenged by ever changing technology landscape, increasing customer sophistication / demands and introduction of new / updated regulatory requirements.
We need passionate Technology Risk Managers who play a high impact role as second line function in enhancing the bank's technology risk and cybersecurity posture.This includes identifying potential technology and cybersecurity risks associated with existing, evolving and new technology systems and business processes, assessing potential impacts and engaging with other technology leaders on the risk treatment options based on enterprise risk appetite. Risks and mitigation plans are reported to senior leadership for review and attention. The RoleExperience in Cybersecurity principles, solutions and processes are essential for this position. The incumbent is a driven, self-starter, who plays an active role working in a dynamic environment with the Technology risk teams to conduct independent assurance of risk management and drive IT risk management initiatives.
The role is expected to have a proven record of positively influencing stakeholders at all levels of the organisation and is responsible to promote risk culture.Additionally, the incumbent needs to have analytical skills to assess information and identify potential risks, possess problem-solving skills to be able to determine how to reduce those risks, and introduce more forward-looking measures of risk.The Incumbent should be inquisitive on risks and controls issues and rationalize their mitigation. Communication skills are important to inform management about potential risk issues, provide actionable reports, including articulating impact on policy changes. There will be frequent opportunities to represent Technology Risk's view in risk forums and different levels of risk committees. The demands and high-visibility nature of this position require an expert with a proven ability to work independently in a fast-paced environment and who can begin contributing immediately.
Responsibilities* Work with stakeholders across Group Technology to manage Technology Risks relating to cybersecurity.* Partner with first line peers to succinctly assess, frame and report on cybersecurity risks relative to risk appetite.* Ability to review and challenge cybersecurity design, define and initiate stress testing against various risk scenarios.* Ability to use analytical thinking to identify security gaps, risks, control issues and propose / review mitigation strategies.* Conduct independent assurance to evaluate effectiveness of IT controls.* Perform thematic second line assurance reviews, including short and targeted focused reviews for areas of topical and key concern.* Oversight of remediation of issues arising from first line identification of control deficiencies, internal and external incidents, including deep dive reviews to identify root cause.* Demonstrate strong judgment to balance being both a trusted advisor to the business and driving effective challenge.* Champion risk awareness and best practices with various stakeholders to uplift risk culture in the organisation.* Enhance the business' understanding of regulatory/compliance requirements and the implications to individual initiatives and the broader firm.* Provide robust risk management oversight in supporting various internal, external audits and regulatory inspections / examinations.* Monitor outstanding risk items and audit issues to ensure proper ownership and follow-up.* Ability to work independently, prepare and write comprehensive reports for senior management on technology risk management activities and risk events for presentation to risk committees.* Ability to communicate complex technology risk concepts in a clear and concise manner.* Mentor more junior members of the team.* Stay current on emerging cyber threats and potential implications to the organisation. Requirements* Degree holder in Information Technology, Computer Science or related discipline.* Minimum 8-12 years of working experience in relevant field.* Professional memberships and security or risk management certifications would be considered favourably (e.g., CISA, CRISC, CISSP, CISM, CCSP, etc.): * (1) Technical Experience* IT professional with good understanding of technology platform with specialisation in security domains* Familiar with assessing or designing controls for AWS, GCP, Azure or other cloud services.* Experienced with technical security solutions surrounding various technologies such as but not limited to: IDS, IPS, firewall management, anti-virus, content filtering, secure email solutions, network sniffing, log management & analysis, forensics, VPN, load balancing, routing, switching and network management.* Prior experience in either banking, IT risk management, or security-related.* Sound knowledge in regulatory requirements (e.g. MAS Notice 644, 655, and TRM guidelines) and industry standards/ frameworks such as ITIL, SANS, COBIT, NIST, ISO 27001/2, Cyber Security Act, Banking Act, Personal Data Protection Act.* (2) Non-Technical Experience* Superb interpersonal and communication skills that include active listening, writing and executive presentation skills.* Excellent influencing and persuasion skills* Proven critical analytical, including and the ability to express a point of view supported by data (with both technical and non-technical audiences)* Comfort raising concerns early and knows when to escalate, including the ability to raise issues and facilitate constructive problem-solving at all levels of the organization.* Experience in a first-line role at a financial institution or regulatory agency (preferred)* Good planning and other project management skills, including strong organisation skills.* Must be solutions oriented; ability to work with all levels of management and staff.* Self-driven, passionate about hands-on learning on emerging technologies and its risks.* Self-starter, performance-oriented individuals* Passionate about driving change through innovation.* General understanding of overall banking business* (3) Work Relationship* Support the Head of Unit in discharging the responsibilities of the team.* Strong ability in knowledge sharing with peers.* Contribute as a member of Team and collaborate with fellow team members and technology managers.* Develop relationships with peer in the technology organisation.-en