Search by job, company or skills

Executive | Technology Risk Management

  • Posted 6 hours ago
  • Be among the first 10 applicants

Job Description

JOB SUMMARY

Leads the implementation and execution of enterprise-wide technology risk management and third-party due diligence, driving governance, delivering strategic advisory, and operationalizing risk frameworks to ensure proactive risk mitigation, regulatory compliance, and the protection of critical systems and data.

JOB RESPONSIBILITIES

  • Lead the development, review, and advisory of the Technology Risk Management Framework (TRMF) and Third-Party Risk Management Framework (TPRMF) to ensure robust governance and alignment with regulatory and EPF requirements.
  • Strategise and align technology and cybersecurity risk management by ensuring risk exposures, control gaps, and remediation actions are consistently aligned with ERM and TRMF risk appetite to support informed decision-making and organisational resilience.
  • Manage and guide end-to-end technology and cybersecurity risk advisory across projects, encompassing risk assessment, validation, challenge, and reporting, while providing independent assurance, actionable insights, and regular updates on key risk exposures and emerging threats to ensure effective risk governance and informed stakeholder decision-making.
  • Conduct and review third-party due diligence (TPDD) activities and end-to-end risk assessments across the vendor lifecycle by ensuring that technology, cybersecurity, and third-party risks are rigorously identified and evaluated, including effective control assessments and gap identification, while providing risk-based recommendations and tracking remediation efforts to maintain alignment with the Third-Party Risk Management Framework (TPRMF) and enterprise risk governance standards.
  • Execute and align Business Continuity Management (BCM) implementation with governance frameworks and regulatory expectations, while overseeing validation of BIA and Business Continuity Plans (BCP) to strengthen operational resilience and continuity.
  • Facilitate Technology Risk Exemptions (TRE) by providing risk advisory, ensuring proper governance, and escalating material risks to management committees for timely resolution.
  • Conduct a comprehensive review of Operating Manuals and Work Instructions for technology division from a risk perspective to strengthen control governance and support the continuous enhancement of risk management practices
  • Analyse and consolidate emerging risk insights across the Digital Technology Division to support integration into enterprise risk management and enable risk-informed decision-making.

JOB REQUIREMENTS

  • Malaysian citizen.
  • Obtain a pass in Bahasa Melayu, including an oral test in Sijil Pelajaran Malaysia (SPM) level or equivalent qualification recognised by the Government.
  • Possess a bachelor's degree in information technology, Computer Science, Cybersecurity, Risk Management, or a related field.
  • At least 4 – 6 years of relevant experience in technology and cybersecurity risk management, IT audit, or IT governance, with hands-on exposure to risk assessment, validation, and regulatory compliance.
  • Preferably an experienced officer with expertise in information security, as well as technology and cybersecurity audit.
  • Have experience in Corporate Banking/Financial Services or equivalent.
  • Experience in risk assessment, validation, and reporting, including risk scorecards and governance forums.
  • Good stakeholder management and communication skills, with ability to provide advisory and present to management committees.
  • Experience with CRISC, ISO 27002, ITIL, and NIST is preferred.
  • Strong knowledge of regulatory frameworks and standards, e.g. TRMF, RMiT, ISO/IEC 27001.

JOB STATUS

Permanent

PLACEMENT

Cybersecurity Risk Unit, Risk Management Advisory I Section, Risk Management Department

All applications are strictly CONFIDENTIAL, and only shortlisted candidates will be called in for interview. Applications are deemed UNSUCCESSFUL if there is no feedback from the EPF 2 MONTHS after the closing date of advertisement.

More Info

Job Type:
Industry:
Employment Type:

About Company

Job ID: 152479967

Similar Jobs

Malaysia, Selangor

Skills:

ItilInformation SecurityRMiTIt GovernanceIt AuditRegulatory ComplianceRisk AssessmentISO 27002nistISO IEC 27001CRISCTRMF

Beware of Scammers

We don’t charge money for job offers