The Opportunity
- This is an exciting opportunity to work for one of the leading global banks
- It is an opportunity for a Senior Control Manager, Technology Risk & Governance to join the team
The Job
Technology Risk Management
- Conduct technology risk assessments (e.g., application, infrastructure, third-party, cloud) to identify potential vulnerabilities, threats, and control gaps.
- Evaluate the effectiveness of technology controls and recommend enhancements to mitigate identified risks.
- Maintain and update the bank's technology risk register, tracking key risks, control effectiveness, and mitigation actions
- Monitor technology risk metrics and Key Risk Indicators (KRIs) to provide early warnings of potential issues.
- Participate in technology project lifecycle reviews (SDLC) to ensure security and risk-by-design principles are incorporated from inception.
- Collaborate with internal Technology and business units to develop and implement risk treatment plans
Regulatory Compliance
- Interpret, implement, and monitor compliance with various Singapore regulations and industry standards, including but not limited to requirements for cybersecurity, data governance, business continuity, outsourcing and incident management.
- Participate in regulatory inspections and audits, providing necessary documentation and explanations.
- Track and report on regulatory findings and ensure timely remediation.
Policy & Standards Development
- Assist in the development, review, and update of technology risk management policies, standards, guidelines, and procedures.
- Ensure policies are aligned with regulatory requirements, industry best practices, and the bank's risk appetite.
- Drive awareness and adoption of technology risk and compliance policies across the organization.
Incident Management & Business Continuity
- Support the technology incident management process, focusing on identifying root causes, assessing impact, and ensuring effective remediation from a risk perspective.
- Participate in the review and testing of technology-related business continuity plans and disaster recovery plans.
- Act key reporting contact for regulatory related notifications including incident reporting
Third-Party Risk Management
- Conduct technology risk assessments for third-party vendors and service providers, especially those handling sensitive data or critical services.
- Ensure third-party contracts include appropriate security and compliance clauses.
- Monitor ongoing third-party compliance with agreed-upon security controls.
Reporting
- Prepare regular risk reports, dashboards, and presentations for management, risk committees, and the Board (as required).
The Talent