AVP / Manager, Third-Party Due Diligence Specialist

ocbc

Kampung Teluk Menara

On-site

MYR 180,000 - 240,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

OCBC Bank seeks an experienced risk professional to lead and execute risk-based due diligence for third-party tech service arrangements, focusing on information security, cybersecurity, and operational resilience. You will conduct independent risk assessments, manage issues, and advise to ensure compliance with regulatory requirements and internal policies.

The role requires collaboration with internal teams and external providers, preparing risk reports and dashboards for stakeholders.

Qualifications

  • Degree in Information Security, Cybersecurity, Information Technology, Risk Management, or related field.
  • 5-8 years in TPRM, Technology Risk, Cybersecurity, IT audit, or due diligence.
  • Knowledge of BNM RMiT, PDPA, and outsourcing regulations.
  • Experience reviewing vendor security questionnaires and SOC/ISO reports.

Responsibilities

  • Customise risk-based questionnaires for regulatory alignment and evolving risk needs.
  • Perform thorough due diligence including site visits and technology/cyber risk focus.
  • Evaluate vendor controls across information security, cloud, data protection, and IT resilience.
  • Identify gaps and provide remediation recommendations with timelines.
  • Prepare risk reports and dashboards for stakeholders and management.
  • Collaborate with policy owners and assurance functions across the Second/Third lines.
  • Support Head of ORM with Central Bank, Internal Audit, and Compliance observations.

Skills

Analytical thinking
Risk judgement
Stakeholder management
Regulatory interpretation
Documentation discipline
Communication skills

Education

Degree in Information Security or related field

Tools

Microsoft 365
Power Platform
Power BI

Job description

WHO WE ARE:

As Singapore's longest established bank, we have been dedicated to enabling individuals and businesses to achieve their aspirations since 1932. How? By taking the time to truly understand people. From there, we provide support, services, solutions, and career paths that meet their individual needs and desires.

Today, we're on a journey of transformation. Leveraging technology and creativity to become a future-ready learning organisation. But for all that change, our strategic ambition is consistently clear and bold, which is to be Asia's leading financial services partner for a sustainable future.

We invite you to build the bank of the future. Innovate the way we deliver financial services. Work in friendly, supportive teams. Build lasting value in your community. Help people grow their assets, business, and investments. Take your learning as far as you can. Or simply enjoy a vibrant, future-ready career.

Your Opportunity Starts Here.
Job Summary

Lead and execute risk-based due diligence for third-party service arrangements, with a focus on technology (including digital and information security risks), cybersecurity, and operational resilience risks. This role involves conducting independent risk assessments, issue management, and providing advisory support to ensure compliance with regulatory requirements, internal policies and international standards. This position requires close collaboration with key internal teams and external service providers.

Key Responsibilities
  • Customise and adapt risk- and context-based questionnaires to ensure assessments align with applicable regulatory requirements and expectations and remain responsive to evolving risk considerations.
  • Conduct comprehensive, risk- and context-based due diligence, including site visits, with a focus on information security, technology architecture, cybersecurity maturity, regulatory compliance, business continuity and physical security risks.
  • Evaluate vendor controls across key domains, including but not limited:
    • Information security and cybersecurity controls (including continuous monitoring of cybersecurity posture).
    • Cloud, infrastructure, and data protection risks
    • IT resilience, BCP/DR, and incident response
  • Identify control gaps and risk exposures, and assess inherent and residual risk, including recommendations for mitigation.
  • Provide subject matter advisory support in managing identified issues by reviewing remediation action tracking and evaluating the timelines and adequacy of controls.
  • Prepare and present risk reports, dashboards, and insights to stakeholders and management.
  • Collaborate with policy owners to ensure alignment with governance and regulatory requirements. Partner with service owners, business units, risk type owners, Procurement, Compliance, Legal, and other assurance functions in the second and third line of defence to identify and appropriately escalated third-party risks.
  • Support Head of ORM in addressing the Central Bank, Internal Audit, and Compliance observations.
Qualifications & Experience
  • Degree in Information Security, Cybersecurity, Information Technology, Risk Management, or related field
  • 5-8 years of experience in TPRM, Technology Risk, Cybersecurity, IT audit, or due diligence.
  • Comprehensive knowledge of BNM RMiT guidelines with practical experience executing mandatory Third-Party Risk Management (TPRM) assessments and vendor due diligence.
  • Strong knowledge of:
    • Cybersecurity frameworks (e.g., ISO 27001 (Information Security Management Systems), NIST CSF (National Institute of Standards and Technology Cybersecurity Framework), BNM RMiT (Bank Negara Malaysia Risk Management in Technology), MAS TRM (Monetary Authority of Singapore Technology Risk Management))
    • Third-party risk management (TPRM), outsourcing regulations, and data privacy laws (PDPA)
  • IT control design, gap analysis, and operating effectiveness assessment
  • Hands-on experience reviewing:
    • Vendor security questionnaires, Outsourced Service Provider Audit Report (OSPAR), System and Organization Controls (SOC) reports, and ISO certifications
  • Vulnerability assessments and penetration testing (VAPT) outputs to determine residual risk
Key Competencies
  • Strong analytical and risk judgement capability
  • Strong capability to analyse complex documentation and interpret audit reports.
  • Ability to independently assess and challenge risk decisions
  • Effective stakeholder management and communication skills
  • Ability to manage multiple assessments in a dynamic environment
  • High attention to detail with strong documentation discipline
Preferred
  • Certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Certified Third Party Risk Professional (CTPRP).
  • Proficient in Microsoft 365 and the Power Platform, with experience building interactive Power BI reports, confi
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

AVP / Manager, Third-Party Due Diligence Specialist
AVP / Manager, Third-Party Due Diligence Specialist

OCBC Bank (Malaysia) Berhad • Malaysia

On-site
MYR 180,000 - 300,000
Flexible benefits
Learning opportunities
Wellbeing programs
AVP / Manager, Third-Party Due Diligence Specialist
AVP / Manager, Third-Party Due Diligence Specialist

OCBC company • Kuala Lumpur

On-site
MYR 150,000 - 260,000
Competitive base salary
Learning and development
AVP / Manager, Third-Party Due Diligence Specialist
AVP / Manager, Third-Party Due Diligence Specialist

OCBC Malaysia • Malaysia

On-site
MYR 120,000 - 180,000
Competitive base salary
Flexible benefits
Learning & development opportunities
+1
AVP: Third-Party Risk & Cybersecurity Due Diligence Lead
AVP: Third-Party Risk & Cybersecurity Due Diligence Lead

OCBC company • Kuala Lumpur

On-site
MYR 150,000 - 260,000
Competitive base salary
Learning and development
Head - Cybersecurity Services
Head - Cybersecurity Services

alrajhi bank Malaysia • Kuala Lumpur

On-site
MYR 300,000 - 700,000
Head, Cyber Risk Management
Head, Cyber Risk Management

Affin Bank Berhad • Kuala Lumpur

On-site
MYR 120,000 - 160,000
Manager, Risk - Third Party Risk Oversight MY
Manager, Risk - Third Party Risk Oversight MY

CIMB Bank Berhad • Kuala Lumpur

On-site
MYR 150,000 - 230,000
Security Governance Assistant Manager
Security Governance Assistant Manager

Boost Holdings Sdn Bhd • Kuala Lumpur

On-site
MYR 150,000 - 210,000
Senior TPRM & Cybersecurity Due Diligence Lead
Senior TPRM & Cybersecurity Due Diligence Lead

OCBC Bank (Malaysia) Berhad • Malaysia

On-site
MYR 180,000 - 300,000
Flexible benefits
Learning opportunities
Wellbeing programs
IT Security Governance
IT Security Governance

GoKardz Technologies • Kuala Lumpur

On-site
MYR 90,000 - 120,000