Jora Malaysia will close on 9th September 2026. Thank you for being with us, we are cheering you on as you continue your career journey.
To drive and enhance organisation-wide Operational Risk Management (ORM) implementation through effective risk identification, assessment, monitoring, and reporting. The role serves as a trusted advisor to business and project teams, while driving continuous improvement in risk practices and optimisation of the GRC platform to strengthen governance and support informed decision‑making. Key responsibilities include oversight of Risk and Control Self‑Assessment (RCSA), GRC system management, incident management, Key Risk Indicator (KRI) monitoring, and Risk & Compliance Representative (RCR) management and engagement, ensuring consistency and timely execution across divisions.
Key responsibilities
- Drive the preparation and delivery of organisation-wide risk management reports, ensuring timely, accurate, and insightful reporting to management and governing bodies with minimal supervision.
- Drive KRI monitoring to provide early warning signals and track risk movements across the organisation, with timely communication and escalation of key risk insights to stakeholders and management.
- Assess risk exposures and evaluate mitigation effectiveness to ensure risks are effectively managed and controls remain robust, while actively tracking and monitoring mitigation actions.
- Drive the identification and analysis of emerging risks, delivering forward‑looking insights to support proactive risk management and informed decision‑making.
- Manage stakeholder engagement across divisions to ensure alignment, completeness, and quality of risk inputs.
- Drive continuous improvement of ORM methodologies, processes, and reporting to enhance the consistency, completeness, and overall quality of risk outputs across divisions.
- Drive the end‑to‑end execution of the RCSA process, including planning and execution, integration with the GRC system, and alignment with established reporting standards, ensuring consistency, accuracy, and quality of outputs across divisions.
- Manage and administer the GRC system, ensuring system reliability, data integrity, and effective user governance.
- Manage the incident management process, including the preparation of Incident Management Reports and timely reporting to relevant governing bodies.
- Drive proactive engagement of Risk & Compliance Representatives (RCRs) to strengthen risk awareness, ownership, and accountability across divisions, fostering a consistent and embedded risk culture.
Experience / Exposure
- Bachelor's degree in Business, Finance, Accounting, Risk Management, Information Technology or related discipline
- Strong understanding of Enterprise Risk Management (ERM) and Operational Risk Management (ORM) principles, frameworks and practices
- Minimum 8–12 years of relevant experience in risk management, compliance, audit or related functions, preferably within a financial services or regulated environment
- Hands‑on experience in core Operational Risk Management areas, including RCSA, incident management, KRI monitoring and risk reporting
- Proven experience in engaging with business units and stakeholders to support risk identification, assessment and mitigation
- Experience in preparing risk reports for Management or committees
- Strong analytical, communication and stakeholder management skills
- Proficient in MS Office applications, with strong presentation and communication skills
- Good understanding of Malaysian capital market rules and industry practices
- Strong leadership skills with the ability to drive outcomes and influence stakeholders