AVP, Third-Party Due Diligence Specialist

OCBC

Kuala Lumpur

On-site

MYR 120,000 - 180,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Learning opportunities
Flexible benefits

Job summary

OCBC is seeking a risk management professional to lead Third-Party Risk Management assessments in a regulatory‑heavy environment in Kuala Lumpur. You will conduct due diligence, assess information security and cloud risks, and coordinate with stakeholders to strengthen controls.

The role requires 5–8 years in risk/IT domains, with certifications preferred and strong communication skills for cross‑functional collaboration.

Qualifications

  • Bachelor’s degree in information security, IT, or risk management.
  • 5–8 years in TPRM, technology risk, cybersecurity, IT audit, or due diligence.
  • Strong knowledge of ISO 27001, NIST CSF, BNM RMiT, MAS TRM.
  • Experience reviewing vendor security questionnaires and SOC reports.
  • Familiar with PDPA and data privacy regulations.

Responsibilities

  • Customize risk questionnaires to align with regulatory requirements.
  • Conduct risk-based due diligence including site visits focusing on security, technology, compliance, and continuity.
  • Evaluate vendor controls across information security, cloud, data protection, IT resilience, and incident response.
  • Identify control gaps and risk exposures; provide remediation recommendations.
  • Prepare and present risk reports, dashboards, and insights to stakeholders and management.
  • Collaborate with policy owners and assurance functions in second and third lines of defence to identify and elevate third‑party risks.
  • Support addressing regulatory observations from Central Bank, Internal Audit, and Compliance.

Skills

Risk management
Cybersecurity
IT audit
Third‑party risk
Regulatory compliance
Data privacy

Education

Degree in Information Security, Cybersecurity, Information Technology, Risk Management, or related field

Tools

Microsoft 365
Power Platform
Power BI
Power Apps
Data workflows

Job description

Who We Are

As Singapore’s longest established bank, we have been dedicated to enabling individuals and businesses to achieve their aspirations since 1932. How? By taking the time to truly understand people. From there, we provide support, services, solutions, and career paths that meet their individual needs and desires. Today, we’re on a journey of transformation. Leveraging technology and creativity to become a future‑ready learning organisation. But for all that change, our strategic ambition is consistently clear and bold, which is to be Asia’s leading financial services partner for a sustainable future. We invite you to build the bank of the future. Innovate the way we deliver financial services. Work in friendly, supportive teams. Build lasting value in your community. Help people grow their assets, business, and investments. Take your learning as far as you can. Or simply enjoy a vibrant, future‑ready career. Your Opportunity Starts Here.


Key Responsibilities


  • Customize and adapt risk‑and‑context‑based questionnaires to ensure assessments align with applicable regulatory requirements and expectations and remain responsive to evolving risk considerations.

  • Conduct comprehensive, risk‑and‑context‑based due diligence, including site visits, with a focus on information security, technology architecture, cybersecurity maturity, regulatory compliance, business continuity and physical security risks.

  • Evaluate vendor controls across key domains, including but not limited:


    • Information security and cybersecurity controls (including continuous monitoring of cybersecurity posture).

    • Cloud, infrastructure, and data protection risks

    • IT resilience, BCP/DR, and incident response

    • Identify control gaps and risk exposures, and assess inherent and residual risk, including recommendations for mitigation.

    • Provide subject matter advisory support in managing identified issues by reviewing remediation action tracking and evaluating the timelines and adequacy of controls.

    • Prepare and present risk reports, dashboards, and insights to stakeholders and management.

    • Collaborate with policy owners to ensure alignment with governance and regulatory requirements. Partner with service owners, business units, risk type owners, Procurement, Compliance, Legal, and other assurance functions in the second and third line of defence to identify and appropriately elevate third‑party risks.

    • Support Head of ORM in addressing the Central Bank, Internal Audit, and Compliance observations.



Qualifications & Experience


  • Degree in Information Security, Cybersecurity, Information Technology, Risk Management, or related field

  • 5‑8 years of experience in TPRM, Technology Risk, Cybersecurity, IT audit, or due diligence.

  • Comprehensive knowledge of BNM RMiT guidelines with practical experience executing mandatory Third‑Party Risk Management (TPRM) assessments and vendor due diligence.

  • Strong knowledge of:


    • Cybersecurity frameworks (e.g., ISO 27001 (Information Security Management Systems), NIST CSF (National Institute of Standards and Technology Cybersecurity Framework), BNM RMiT (Bank Negara Malaysia Risk Management in Technology), MAS TRM (Monetary Authority of Singapore Technology Risk Management)

    • Third‑party risk management (TPRM), outsourcing regulations, and data privacy laws (PDPA)

    • IT control design, gap analysis, and operating effectiveness assessment




  • Hands‑on experience reviewing:


    • Vendor security questionnaires, Outsourced Service Provider Audit Report (OSPAR), System and Organization Controls (SOC) reports, and ISO certifications

    • Vulnerability assessments and penetration testing (VAPT) outputs to determine residual risk



Key Competencies


  • Strong analytical and risk judgement capability

  • Strong capability to analyze complex documentation and interpret audit reports.

  • Ability to independently assess and challenge risk decisions

  • Effective stakeholder management and communication skills

  • Ability to manage multiple assessments in a dynamic environment

  • High attention to detail with strong documentation discipline


Preferred


  • Certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Certified Third Party Risk Professional (CTPRP).

  • Proficient in Microsoft 365 and the Power Platform, with experience building interactive Power BI reports, configuring custom Power Apps, and managing data workflows.

  • Experience with TPRM platforms.

  • Familiarity with outsourcing risk management, cloud governance, data privacy regulations and third‑party cybersecurity oversight.

  • Knowledge of Operational Resilience management is a plus.


What We Offer

Competitive base salary. A suite of holistic, flexible benefits to suit every lifestyle. Community initiatives. Industry‑leading learning and professional development opportunities. Your wellbeing, growth and aspirations are every bit as cared for as the needs of our customers.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, Risk - Third Party Risk Oversight MY
Manager, Risk - Third Party Risk Oversight MY

CIMB Bank Berhad • Kuala Lumpur

On-site
MYR 150,000 - 230,000
Head - Cybersecurity Services
Head - Cybersecurity Services

alrajhi bank Malaysia • Kuala Lumpur

On-site
MYR 300,000 - 700,000
Third Party Risk Management, Specialist
Third Party Risk Management, Specialist

AIA Malaysia • Kuala Lumpur

On-site
MYR 60,000 - 95,000
Non-Financial Risk Specialist
Non-Financial Risk Specialist

Ryt Bank • Kuala Lumpur

On-site
MYR 90,000 - 130,000
Head of Information Technology
Head of Information Technology

NTT DATA Payment Services • Kuala Lumpur

On-site
MYR 350,000 - 650,000
Non-Financial Risk Specialist
Non-Financial Risk Specialist

YTL Sea Digital Bank Project • Kuala Lumpur

On-site
MYR 90,000 - 140,000
Head, Cyber Risk Management
Head, Cyber Risk Management

Affin Bank Berhad • Kuala Lumpur

On-site
MYR 120,000 - 160,000
Remittance - Head, Compliance
Remittance - Head, Compliance

TNG Digital • Kuala Lumpur

On-site
MYR 400,000 - 800,000
Medical coverage
Lifestyle allowance
Mobile and broadband reimbursement
Outsourcing Services Management
Outsourcing Services Management

OCBC company • Kuala Lumpur

On-site
MYR 100,000 - 120,000
Competitive salary
Holistic benefits
Professional development opportunities
Remittance - Head, Compliance
Remittance - Head, Compliance

Fintech News • Kuala Lumpur

On-site
MYR 300,000 - 520,000
Medical coverage
Family leave
Lifestyle allowance
+2