The role is part of the Second Line of Defense (2LoD) team, supporting the enterprise risk function in managing technology risk across the organisation. The role is responsible for supporting the identification, assessment, monitoring, and mitigation of technology-related risks, while providing independent oversight, challenge, and governance across technology operations. Key areas of focus include technology operational resilience, cloud governance, third-party technology risk, and responsible AI governance. The role ensures CTOS operates within its technology risk appetite and complies with regulatory, security, and business resilience requirements.
While the role primarily focuses on technology risk management, the incumbent is expected to possess an understanding of cybersecurity principles and cyber risk management practices due to the interconnected nature of technooogy and cyber risks.
KEY RESPONSIBILITIES
Technology Risk Governance
- Lead the development, implementation, and maintenance of the Technology Risk Management Framework (TRMF).
- Maintain enterprise technology risk registers and monitor risk treatment plans.
- Establish, monitor, and challenge technology risk appetite metrics, KRIs, thresholds, and escalation triggers to ensure risks remain within approved tolerance levels.
- Support the development and oversight of governance frameworks for AI and emerging technologies, including risk assessment, regulatory compliance, ethical considerations, model governance and operational controls.
Technology Risk Assessment & Oversight
- Provide independent oversight and challenge to First Line of Defense (1LoD) technology operations and implementations.
- Conduct technology risk assessments covering infrastructure, applications, cloud services, and strategic technology projects.
- Lead technology due diligence and risk assessments for third-parties, including cloud providers, managed service providers, solution providers, and other vendors.
- Assess and challenge technology risks arising from major technology transformation programmes, architecture decisions, application development initiatives, technology migrations, platform modernisation efforts and adoption of emerging technologies.
- Evaluate risks related to system availability, scalability, capacity management, technology debt, obsolescence, and operational sustainability.
Technology Resilience
- Provide independent oversight and validation of technology resilience capabilities, including IT disaster recovery, backup management, capacity management, high availability design, technology lifecycle management, incident recovery readiness & testing, and technology obsolescence management.
- Provide independent oversight over cloud adoption initiatives, including governance, resilience, concentration risk, vendor lock-in risk, shared responsibility controls, and compliance requirements.
Regulatory Compliance & Assurance
- Ensure technology risk governance, assessments, monitoring, reporting, and assurance activities are aligned with applicable requirements, such as BNM RMiT and ISO 27001.
- Coordinate responses to audits, regulatory reviews, and customer due diligence.
Governance Reporting & Stakeholder Management
- Prepare risk reports, dashboards, committee papers, and management updates.
- Present key technology risks and resilience matters to management and governance forums.
- Partner with business and technology stakeholders to promote effective technology risk management practices across the organisation.
WHAT DOES IT TAKE TO BE SUCCESSFUL
Qualifications
- Bachelor's Degree in technology, computer science, information security, risk management, or related discipline.
- Professional certifications such as CRISC, CISM, CISA, ISO 27001 Lead Implementer, or equivalent.
Work Experience
- 6-10 years of experience in Technology Risk, Information Security, IT Governance, Operational Resilience, or related discipline.
- Familiarity with industry standards and regulatory frameworks such as BNM RMiT, CSA's Cloud Control Matrix, ISO 27001 or similar standards.
Knowledge, Skills & Competencies
- Strong understanding of technology architecture, cloud computing, SDLC, and IT operations.
- Knowledge of operational resilience, business continuity, disaster recovery and service management practices.
- Ability to assess emerging technology risks, including cloud, AI and automation.
- Ability to apply risk-based thinking and provide independent challenge and practical recommendations.
- Strong analytical and risk assessment capabilities with experience translating complex technical risks into business impacts.
- Strong stakeholder management and cross-functional coordination skills.
- Effective verbal and written communication skills, with the ability to engage both technical and non-technical audiences (e.g. customers, management, and business stakeholders).