VP / AVP, Specialist, Technology Risk (Cybersecurity), Risk Management Group

6 days ago


Singapur, Singapore DBS Bank Full time

Overview Risk Management Group works closely with our business partners to manage the bank’s risk exposure by balancing its objective to maximise returns against an acceptable risk profile. We partner with origination teams to provide financing, investments and hedging opportunities to our customers. To manage risk effectively and run a successful business, we invest significantly in our people and infrastructure. Technology is key to enabling the DBS vision of being the leading bank in Asia. We are constantly challenged by ever changing technology landscape, increasing customer sophistication / demands and introduction of new / updated regulatory requirements. We need passionate Technology Risk Managers who play a high impact role as second line function in enhancing the bank’s technology risk and cybersecurity posture. This includes identifying potential technology and cybersecurity risks associated with existing, evolving and new technology systems and business processes, assessing potential impacts and engaging with other technology leaders on the risk treatment options based on enterprise risk appetite. Risks and mitigation plans are reported to senior leadership for review and attention. The Role Experience in Cybersecurity principles, solutions and processes are essential for this position. The incumbent is a driven, self-starter, who plays an active role working in a dynamic environment with the Technology risk teams to conduct independent assurance of risk management and drive IT risk management initiatives. The role is expected to have a proven record of positively influencing stakeholders at all levels of the organisation and is responsible to promote risk culture. Additionally, the incumbent needs to have analytical skills to assess information and identify potential risks, possess problem-solving skills to be able to determine how to reduce those risks, and introduce more forward-looking measures of risk. The Incumbent should be inquisitive on risks and controls issues and rationalize their mitigation. Communication skills are important to inform management about potential risk issues, provide actionable reports, including articulating impact on policy changes. There will be frequent opportunities to represent Technology Risk’s view in risk forums and different levels of risk committees. The demands and high-visibility nature of this position require an expert with a proven ability to work independently in a fast-paced environment and who can begin contributing immediately. Responsibilities Work with stakeholders across Group Technology to manage Technology Risks relating to cybersecurity. Partner with first line peers to succinctly assess, frame and report on cybersecurity risks relative to risk appetite. Ability to review and challenge cybersecurity design, define and initiate stress testing against various risk scenarios. Ability to use analytical thinking to identify security gaps, risks, control issues and propose / review mitigation strategies. Conduct independent assurance to evaluate effectiveness of IT controls. Perform thematic second line assurance reviews, including short and targeted focused reviews for areas of topical and key concern. Oversight of remediation of issues arising from first line identification of control deficiencies, internal and external incidents, including deep dive reviews to identify root cause. Demonstrate strong judgment to balance being both a trusted advisor to the business and driving effective challenge. Champion risk awareness and best practices with various stakeholders to uplift risk culture in the organisation. Enhance the business’ understanding of regulatory/compliance requirements and the implications to individual initiatives and the broader firm. Provide robust risk management oversight in supporting various internal, external audits and regulatory inspections / examinations. Monitor outstanding risk items and audit issues to ensure proper ownership and follow-up. Ability to work independently, prepare and write comprehensive reports for senior management on technology risk management activities and risk events for presentation to risk committees. Ability to communicate complex technology risk concepts in a clear and concise manner. Mentor more junior members of the team. Stay current on emerging cyber threats and potential implications to the organisation. Requirements Degree holder in Information Technology, Computer Science or related discipline. Minimum 8-12 years of working experience in relevant field. Professional memberships and security or risk management certifications would be considered favourably (e.g., CISA, CRISC, CISSP, CISM, CCSP, etc.): (1) Technical ExperienceIT professional with good understanding of technology platform with specialisation in security domains Familiar with assessing or designing controls for AWS, GCP, Azure or other cloud services. Experienced with technical security solutions surrounding various technologies such as but not limited to: IDS, IPS, firewall management, anti-virus, content filtering, secure email solutions, network sniffing, log management & analysis, forensics, VPN, load balancing, routing, switching and network management. Prior experience in either banking, IT risk management, or security-related. Sound knowledge in regulatory requirements (e.g. MAS Notice 644, 655, and TRM guidelines) and industry standards/ frameworks such as ITIL, SANS, COBIT, NIST, ISO 27001/2, Cyber Security Act, Banking Act, Personal Data Protection Act. (2) Non-Technical ExperienceSuperb interpersonal and communication skills that include active listening, writing and executive presentation skills. Excellent influencing and persuasion skills Proven critical analytical, including and the ability to express a point of view supported by data (with both technical and non-technical audiences) Comfort raising concerns early and knows when to escalate, including the ability to raise issues and facilitate constructive problem-solving at all levels of the organization. Experience in a first-line role at a financial institution or regulatory agency (preferred) Good planning and other project management skills, including strong organisation skills. Must be solutions oriented; ability to work with all levels of management and staff. Self-driven, passionate about hands-on learning on emerging technologies and its risks. Self-starter, performance-oriented individuals Passionate about driving change through innovation. General understanding of overall banking business (3) Work RelationshipSupport the Head of Unit in discharging the responsibilities of the team. Strong ability in knowledge sharing with peers. Contribute as a member of Team and collaborate with fellow team members and technology managers. Develop relationships with peer in the technology organisation. #J-18808-Ljbffr



  • Singapur, Singapore DBS Bank Limited Full time

    Overview Business Function Risk Management Group works closely with our business partners to manage the bank’s risk exposure by balancing its objective to maximise returns against an acceptable risk profile. We partner with origination teams to provide financing, investments and hedging opportunities to our customers. To manage risk effectively and run a...


  • Singapur, Singapore DBS Bank Full time

    SVP/VP - Infrastructure, Technology Risk Manager, Tech COO, Group Technology Join to apply for the SVP/VP - Infrastructure, Technology Risk Manager, Tech COO, Group Technology role at DBS Bank SVP/VP - Infrastructure, Technology Risk Manager, Tech COO, Group Technology Join to apply for the SVP/VP - Infrastructure, Technology Risk Manager, Tech COO, Group...


  • Singapur, Singapore GIC Full time

    Join to apply for the VP/SVP, Operational Risk Management (contract) role at GIC Join to apply for the VP/SVP, Operational Risk Management (contract) role at GIC Get AI-powered advice on this job and more exclusive features. GIC is one of the world’s largest sovereign wealth funds. With over 2,000 employees across 11 locations around the world, we invest...


  • Singapur, Singapore OCBC Full time

    AVP, Group Information Security & Digital Risk Management Get AI-powered advice on this job and more exclusive features. Who We Are As Singapore’s longest established bank, we have been dedicated to enabling individuals and businesses to achieve their aspirations since 1932. We understand people and provide support, services, solutions, and career paths...


  • Singapur, Singapore GIC Full time

    Join to apply for the Assoc/AVP, Investment Risk role at GIC 1 day ago Be among the first 25 applicants Join to apply for the Assoc/AVP, Investment Risk role at GIC Get AI-powered advice on this job and more exclusive features. GIC is one of the world’s largest sovereign wealth funds. With over 2,000 employees across 11 locations around the world, we...


  • Singapur, Singapore OCBC Bank Berhad OCBC Al Amin Bank Berhad Full time

    You are about to enter websites controlled or offered by third parties. OCBC hereby disclaims liability for any information, materials, products or services posted or offered at any of these third party web-sites. By creating a link to these third party web-sites, OCBC does not endorse or recommend any products or services offered or information contained on...

  • VP, Information

    1 week ago


    Singapur, Singapore GIC Private Limited Full time

    VP, Information & Technology Risk Manager Location: Singapore, SG Job Function: Risk & Performance Management Department Job Type: Permanent GIC is one of the world’s largest sovereign wealth funds. With over 2,000 employees across 11 locations, we invest in more than 40 countries globally across asset classes and businesses. Working at GIC gives you...


  • Singapur, Singapore DBS Bank Full time

    VP/ AVP, KYC Specialist - Periodic Reviews, Private Banking, Consumer Banking Group The VP/ AVP, KYC Specialist - Periodic Reviews will oversee screening, risk assessment, and compliance related to KYC/AML for Private Banking clients, supporting the Private Banking business in Singapore. Business Function DBS Private Banking offers a full-service...


  • Singapur, Singapore Bank of Singapore, Asia's Global Private Bank Full time

    Join to apply for the Risk Manager, Collateral Risk Management (AVP/VP) role at Bank of Singapore, Asia's Global Private Bank Bank of Singapore opens doors to new opportunities. At Bank of Singapore, we are constantly on the lookout for exceptional individuals to join our team. We promote a culture of openness, teamwork and fairness. Most importantly, we...


  • Singapur, Singapore Singlife Full time

    Join to apply for the AVP, Technology Infrastructure role at Singlife 2 days ago Be among the first 25 applicants Join to apply for the AVP, Technology Infrastructure role at Singlife Get AI-powered advice on this job and more exclusive features. Singlife is a leading homegrown financial services company, offering consumers a better way to financial freedom....