Job Descriptions:Ā·
Participate in IT outsourcing risk management, lead IT outsourcing risk assessment, participate in due diligence and annual inspections of IT outsourcing vendors, participate in verification of the implementation of IT risk management and control measures of outsourcing vendors, and other IT outsourcing management work.Ā·
Regularly organize and carry out inspections of the first line of defense, make inspection plans, scope and approaches for the first line of defense, and follow up with relevant departments or teams to complete the rectification of inspection problems.Ā·
Take the lead in response of gap analysis and other regulatory requirements, verify the implementation of regulatory compliance requirements, and ensure compliance of the branch's IT risk work.Ā· Participate in the assessment and mitigation of IT risks and vulnerabilities, and monitor the completion of the mitigating of risk vulnerabilities timely.
Participate in the assessment of local regulatory and head office IT risk alerts, and follow up with relevant teams to complete risk mitigation work according to requirements.Ā· Improve the IT risk identification and assessment working mechanisms and methods, and organize relevant teams to carry out IT risk identification and assessment work.Ā·
Participate in the construction and organization promotion of IT risk quantification indicator system and other management tools , improve the use of IT risk monitoring platforms, cooperate with the second and third line of defense departments to carry out risk and internal control management work ; organize risk assessment matrix, RACA , KRI , LDC and other assessment work.Ā·
Organize and complete the data collection, review and submission of the IT risk quantitative indicator system of the head office.Ā· Develop branch-level IT risk safety training plans and organize their implementation.Ā· Participate in completing other tasks assigned by superiors and the head office.
Job Requirements:
Able to communication effectively both written and spoken in English & Chinese with internal/external stakeholders and HQ.
Open to candidates with interests in IT risk, IT governance, IT audit, IT regulatory compliance who are keen to explore a career in IT risk management.
Knowledge of regulatory requirements and industry practices (e.g. MAS TRM Guidelines, MAS Cyber Hygiene, ISO27001 etc.)
Attention to details, with the ability to thoroughly and accurately review IT policies, process, reporting and audit responses.
Bachelor's degree or above in IT relevant majors.
Relevant professional qualifications and certificates will be a plus.
Company information
Please submit resumes to [email protected] with the following details in MS Word format:
- Position applying for
- Current remuneration
- Expected remuneration
- Notice period
John Goh Meng Chye
EA License No : 06C4642
EA Reg No : R1102621
We regret that only shortlisted candidates will be notified.