Avp, Group Information Security

1 week ago


Singapore OCBC Bank Full time

**AVP, Group Information Security & Digital Risk Management** **-** **(**25000009**)**

**Why Join**

The Group Information Security & Digital Risk Management team undertakes a wide range of responsibilities, including risk governance and oversight, risk reporting to senior management and Board, policy formulation, risk assessments, vulnerability management, incident response, security awareness training, and compliance-drive initiatives. This variety of responsibilities offers a diverse and engaging work experience.

You will be responsible for the 2nd line governance and oversight of information security and digital (i.e., technology, cyber and information risks) within the OCBC Group. The primary role would be to drive key project/ initiatives leveraging big data platforms to analyse large datasets to derive risk insights.

**How you succeed**

Regularly update your knowledge on the latest cybersecurity threats, trends, and emerging technologies. This includes understanding emerging technologies like artificial intelligence (AI), machine learning, and blockchain and associated risks.

Familiarize yourself with relevant regulations and standards that impact the organization’s overall control environment and risk profile.

Develop a strong understanding of risk assessment methodologies and frameworks to evaluate and mitigate risks effectively.

**What you do**_ _
- **Data-Driven Risk Management**: Drive projects or initiatives that leverage big data platforms, including data analytics tools and visualization techniques, to analyse large datasets and derive risk insights. This includes partnering with key stakeholders, tracking project status, and providing recommendations to senior management.
- **Risk Governance and Oversight**: Drive or support risk governance activities; provide independent and effective challenge (e.g., on risk mitigation programs) to strengthen the effectiveness of technology, information or cyber risk management across Group.
- **Risk Monitoring and Reporting**: Perform regular risk monitoring and management reporting on risk posture to senior management and the Board.
- **Control Review and Enhancement**: Support the review and enhancement of controls to better mitigate against emerging technology, information and cyber risks.
- **Regulatory Compliance**: Lead or support bank-wide initiatives to work towards compliance with applicable legal & regulatory requirements (e.g., Cybersecurity Act, MAS Technology Risk Management Guidelines).

**Who you work with**

Group Risk Management works independently to protect, build, and drive our businesses. The team support good decision-making. With strong risk analysis. And a crucial, comprehensive role in sharpening our competitive edge. Optimising risk-adjusted returns. It’s about seeking and adopting best-in-class practices. Protecting the group from unforeseen losses. Keeping risk within appetite. Embracing change and managing growth in one of the world’s strongest banks.

**Qualifications**

**Who you are**
- Degree in Computer Science or equivalent technical degree.
- Relevant professional certifications (e.g., CISA, CISM, CRISC or PMP) would be advantageous.
- Proficient in data analytics tools and visualisation techniques (e.g., SQL, Python, PowerBI), experience with big data platforms (e.g., Hadoop) would be advantageous.
- Proficient knowledge of technology risk management guidelines from MAS or any regional regulators.
- Good written and communication skills, as well as solution oriented.
- Ability to contribute through others, collaborate well across seniority, cultures, and locations.
- Proactive and able to work well under pressure or tight deadlines.

**Who we are**

Singapore’s longest established bank, we’ve been helping people and businesses get what they want from life since 1932. How? By taking the time to truly understand people. From there, we provide support, services, solutions, and career paths that meet their individual needs and desires.

Today, we’re on a journey of transformation. Embracing technology and creativity to become a future-ready learning organisation. But for all that change, the entire focus of our organisation remains to be Simply Spot On. In everything we do.

And so whether you want innovate needs-based financial services. Work in friendly, supportive teams. Build lasting value in your community. Help people grow their assets, business, and investments. Take your learning as far as you can. Or simply enjoy a vibrant, future-ready career. Your Opportunity Starts Here.

**What we offer**

Competitive base salary. A suite of holistic, flexible benefits to suit every lifestyle. Community initiatives. Industry-leading learning and professional development opportunities. Your wellbeing, growth and aspirations are every bit as cared for as the needs of our customers.

**Primary Location**: Singapore

**Job**: Information Risk Management and Security

**Organization**: Group Information Security & Digital Ri



  • Singapore DBS Bank Full time

    AVP, Cyber Security Engineer, Information Security Services, Group Technology Join to apply for the AVP, Cyber Security Engineer, Information Security Services, Group Technology role at DBS


  • Singapore DBS Full time

    Job Description - AVP/Sr. Assoc, Application Security Engineer, Information Security Services, Group Technology D6)Job Description Business Function Group Technology enables and empowers the


  • Singapore DBS Full time

    Job Description AVP/Sr. Assoc, Non-Human Identity Security Engineer, Information Security Services, Group Technology CW)Business Function Group Technology empowers the


  • Singapore OCBC Bank Full time

    **WHO WE ARE**: As Singapore’s longest established bank, we have been dedicated to enabling individuals and businesses to achieve their aspirations since 1932. How? By taking the time to truly understand people. From there, we provide support, services, solutions, and career paths that meet their individual needs and desires. Today, we’re on a journey...


  • Singapore FWD Group Full time

    About FWD Group FWD Group (1828.HK) is a pan-Asian life and health insurance business that serves approximately 34 million customers across 10 markets, including BRI Life in Indonesia. FWD's customer-led and tech-enabled approach aims to deliver innovative propositions, easy-to-understand products and a simpler insurance experience. Established in 2013, the...


  • Singapore National Healthcare Group Full time $120,000 - $240,000 per year

    Family Group: AdministrationJob SummaryThe Group Chief Information Security Officer (GCISO) is responsible for establishing and maintaining the enterprise vision, strategy and security program to ensure information assets and technologies are adequately protected. This role involves leading the information security team developing security policies and...


  • Singapore FWD Group Management Holdings Limited Full time

    Senior Manager, Group Information Security page is loaded## Senior Manager, Group Information Securitylocations: Singapore - Suntec Tower 4time type: Full timeposted on: Posted Todayjob requisition id: JR- **About FWD Group**FWD Group (1828.HK) is a pan-Asian life and health insurance business that serves approximately 34 million customers across 10 markets,...


  • Singapore National Healthcare Group Full time

    Group Chief Information Security Officer (GCISO)Family Group: Administration Job Summary The Group Chief Information Security Officer (GCISO) is responsible for establishing and maintaining the enterprise vision, strategy and security program to ensure information assets and technologies are adequately protected. This role involves leading the information...


  • Singapore 300005 Chief Executive's Office_00002555 Full time

    AVP, Team Lead, Secured Loan Operations, Consumer Banking, Group Operations (WD71655)Group Technology and Operations (T&O) enables and empowers the


  • Singapore INTEGRATED HEALTH INFORMATION SYSTEMS PTE. LTD. Full time

    **Role and Responsibilities** 1. Provide guidance to Business Services Group in ensuring that projects/systems comply with security policies and the relevant legal and regulatory frameworks (such as PDPA or Cybersecurity Act) throughout the product lifecycle 2. Perform adequate risk management, including identification, assessment and provide treatment of...