AVP / Manager, Third-Party Due Diligence Specialist

OCBC Malaysia

Malaysia

On-site

MYR 120,000 - 180,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Competitive base salary
Flexible benefits
Learning & development opportunities
Community initiatives

Job summary

OCBC Malaysia seeks aRisk Management professional to lead risk-based due diligence for third-party service arrangements, focusing on technology, cybersecurity, and operational resilience. You will collaborate with internal teams and external providers to ensure regulatory compliance and effective risk controls.

The role requires hands-on review of vendor security documents, familiarity with international standards, and strong communication skills to present insights to management.

Qualifications

  • Experience in Third-Party Risk Management (TPRM) and vendor due diligence.
  • Strong ability to review vendor security questionnaires and ISO/SOC reports.
  • Knowledge of information security, cloud governance, and data privacy laws.

Responsibilities

  • Lead risk-based due diligence for third-party services with focus on technology and cybersecurity.
  • Prepare risk reports, dashboards, and insights for stakeholders.
  • Collaborate with policy owners and other assurance functions in the risk framework.
  • Assess control gaps and advise on remediation timelines and effectiveness.

Skills

Analytical thinking
Risk judgement
Stakeholder management
Documentation discipline
Auditing interpretation

Education

Degree in Information Security or related field
CISSP/CISM/CISA/CRISC/CTPRP (preferred)

Tools

Microsoft365
Power Platform
PowerBI
Data workflows
TPRM platforms

Job description

WHO WE ARE:

As Singapore’s longest established bank, we have been dedicated to enabling individuals and businesses to achieve their aspirations since 1932. How? By taking the time to truly understand people. From there, we provide support, services, solutions, and career paths that meet their individual needs and desires. Today, we’re on a journey of transformation. Leveraging technology and creativity to become a future‑ready learning organisation. But for all that change, our strategic ambition is consistently clear and bold, which is to be Asia’s leading financial services partner for a sustainable future. We invite you to build the bank of the future. Innovate the way we deliver financial services. Work in friendly, supportive teams. Build lasting value in your community. Help people grow their assets, business, and investments. Take your learning as far as you can. Or simply enjoy a vibrant, future‑ready career. Your Opportunity Starts Here.

Job Summary

Lead and execute risk‑based due diligence for third‑party service arrangements, with a focus on technology (including digital and information security risks), cybersecurity, and operational resilience risks. This role involves conducting independent risk assessments, issue management, and providing advisory support to ensure compliance with regulatory requirements, internal policies and international standards. This position requires close collaboration with key internal teams and external service providers.

Key Responsibilities
  • Customise and adapt risk‑ and context‑based questionnaires to ensure assessments align with applicable regulatory requirements and expectations and remain responsive to evolving risk considerations.
  • Conduct comprehensive, risk‑ and context‑based due diligence, including site visits, with a focus on information security, technology architecture, cybersecurity maturity, regulatory compliance, business continuity and physical security risks.
  • Evaluate vendor controls across key domains, including but not limited: Information security and cybersecurity controls (including continuous monitoring of cybersecurity posture).
  • Cloud, infrastructure, and data protection risks IT resilience, BCP/DR, and incident response.
  • Identify control gaps and risk exposures, and assess inherent and residual risk, including recommendations for mitigation.
  • Provide subject matter advisory support in managing identified issues by reviewing remediation action tracking and evaluating the timelines and adequacy of controls.
  • Prepare and present risk reports, dashboards, and insights to stakeholders and management.
  • Collaborate with policy owners to ensure alignment with governance and regulatory requirements.
  • Partner with service owners, business units, risk type owners, Procurement, Compliance, Legal, and other assurance functions in the second and third line of defence to identify and appropriately escalating third‑party risks.
  • Support Head of ORM in addressing the Central Bank, Internal Audit, and Compliance observations.
Qualifications & Experience
  • Degree in Information Security, Cybersecurity, Information Technology, Risk Management, or related field 5-8 years of experience in TPRM, Technology Risk, Cybersecurity, IT audit, or due diligence.
  • Comprehensive knowledge of BNM RMiT guidelines with practical experience executing mandatory Third‑Party Risk Management (TPRM) assessments and vendor due diligence.
  • Strong knowledge of: Cybersecurity frameworks (e.g., ISO27001 (Information Security Management Systems), NISTCSF (National Institute of Standards and Technology Cybersecurity Framework), BNMRMiT (Bank Negara Malaysia Risk Management in Technology), MASTRM (Monetary Authority of Singapore Technology Risk Management) Third‑party risk management (TPRM), outsourcing regulations, and data privacy laws (PDPA) IT control design, gap analysis, and operating effectiveness assessment.
  • Hands‑on experience reviewing: Vendor security questionnaires, Outsourced Service Provider Audit Report (OSPAR), System and Organization Controls (SOC) reports, and ISO certifications Vulnerability assessments and penetration testing (VAPT) outputs to determine residual risk.
  • Key Competencies: Strong analytical and risk judgement capability.
  • Strong capability to analyse complex documentation and interpret audit reports.
  • Ability to independently assess and challenge risk decisions.
  • Effective stakeholder management and communication skills.
  • Ability to manage multiple assessments in a dynamic environment.
  • High attention to detail with strong documentation discipline.
  • Preferred Certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Certified Third Party Risk Professional (CTPRP).
  • Proficient in Microsoft365 and the Power Platform, with experience building interactive PowerBI reports, configuring custom PowerApps, and managing data workflows.
  • Experience with TPRM platforms.
  • Familiarity with outsourcing risk management, cloud governance, data privacy regulations and third‑party cybersecurity oversight.
  • Knowledge of Operational Resilience management is a plus.
What we offer:
  • Competitive base salary.
  • A suite of holistic, flexible benefits to suit every lifestyle.
  • Community initiatives.
  • Industry‑leading learning and professional development opportunities.

Your wellbeing, growth and aspirations are every bit as cared for as the needs of our customers. Let’s build the bank we need for the future we want. Find the best version of yourself in a friendly, supportive team. Build lasting value in your community. Help people grow their assets, business, and investments. Take your learning as far as you can. Or simply enjoy a vibrant, future‑ready career. Your Opportunity Starts Here.

As the longest established Singapore bank, formed in 1932 from the merger of three local banks, we have grown from strength to strength to become a regional financial services group. With a deep history in Asia, we offer the most comprehensive coverage across ASEAN and Greater China, complemented with a presence in the leading economies of New York, London and Sydney. We are the second largest financial services group in Southeast Asia by assets with one of the world’s highest credit rating (Aa1 by Moody’s and AA- by both Fitch and S&P). We offer private banking services through our wholly‑owned subsidiary, Bank of Singapore, which operates on a unique open‑architecture product platform to source for the best‑in‑class products to meet its clients’ goals. Our insurance subsidiary, Great Eastern Holdings, is the oldest and most established life insurance group in Singapore and Malaysia.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

AVP / Manager, Third-Party Due Diligence Specialist
AVP / Manager, Third-Party Due Diligence Specialist

OCBC Bank (Malaysia) Berhad • Malaysia

On-site
MYR 180,000 - 300,000
Flexible benefits
Learning opportunities
Wellbeing programs
AVP / Manager, Third-Party Due Diligence Specialist
AVP / Manager, Third-Party Due Diligence Specialist

ocbc • Kampung Teluk Menara

On-site
MYR 180,000 - 240,000
AVP / Manager, Third-Party Due Diligence Specialist
AVP / Manager, Third-Party Due Diligence Specialist

OCBC company • Kuala Lumpur

On-site
MYR 150,000 - 260,000
Competitive base salary
Learning and development
VP - Risk Analyst, Business & Operational Audit
VP - Risk Analyst, Business & Operational Audit

OCBC Malaysia • Malaysia

On-site
MYR 80,000 - 120,000
Markets Operations – Risk and Control
Markets Operations – Risk and Control

OCBC e2 Power Sdn Bhd • Malaysia

On-site
MYR 56,000 - 100,000
Competitive base salary
Professional development opportunities
Community initiatives
Corporate Banking Credit Risk Management - VP
Corporate Banking Credit Risk Management - VP

OCBC Group • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Competitive base salary
Flexible benefits
Professional development
Corporate Banking Credit Risk Management - VP
Corporate Banking Credit Risk Management - VP

OCBC company • Kuala Lumpur

Hybrid
MYR 90,000 - 130,000
Competitive salary
Flexible benefits
Community initiatives
+2
VP/ED - CARM Team Lead (CFS R&P)
VP/ED - CARM Team Lead (CFS R&P)

OCBC Malaysia • Malaysia

On-site
MYR 210,000 - 320,000
Competitive base salary
Holistic benefits
Community initiatives
+2
Assistant Manager / Manager, Management Reporting
Assistant Manager / Manager, Management Reporting

OCBC company • Kuala Lumpur

On-site
MYR 60,000 - 85,000
Assistant Manager / Manager, Management Reporting
Assistant Manager / Manager, Management Reporting

OCBC Group • Kuala Lumpur

On-site
MYR 60,000 - 90,000
Competitive base salary
Holistic benefits
Learning and development opportunities