Internal Audit Manager (Enterprise Risk Management)

PayNet (Payments Network Malaysia)

Kuala Lumpur

On-site

MYR 150,000 - 230,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

PayNet in Malaysia seeks a seasoned professional to lead risk-based operational audits across business processes, ERM and the Risk Management function. You will assess governance, operating models, escalation and accountability to strengthen resilience.

Independent assurance will support management and the Board, focusing on horizon scanning, scenarios, KRIs and risk reporting, driving proactive remediation and robust risk controls across the organisation.

Qualifications

  • Experience in internal audit across business or operational processes.
  • Hands-on ERM experience or assurance over enterprise risk.
  • Solid knowledge of risk governance, ERM, thresholds and reporting.
  • Strong critical thinking, analytics and judgement.
  • Ability to engage stakeholders with independent challenge.

Responsibilities

  • Lead or independently execute risk-based operational audits.
  • Assess governance and operating models for accountability, effective oversight and escalation.
  • Evaluate horizon scanning, scenario analysis and RCSA across emerging risks.
  • Test KRIs, thresholds and risk treatment decisions.
  • Shape concise audit reports and working papers supported by evidence and root-cause analysis.
  • Drive closure by validating remediation addresses the underlying risk.

Skills

Internal audit
Enterprise risk management
Risk governance
Stakeholder engagement

Job description

  • Build trust in the platforms Malaysians use every day, including DuitNow, FPX, MyDebit and JomPAY.
  • Shape assurance that strengthens governance, controls and organisational resilience across a national payments institution.
  • Challenge how enterprise risks are identified, treated, monitored and reported before they become material exposures.
  • Influence risk-informed decisions by turning audit insight into clear priorities for Management and the Board.
  • Join a values-led environment built on Aspiration, Curiosity, Grit and Integrity.
Why PayNet / Why Now
  • Build trust in the platforms Malaysians use every day, including DuitNow, FPX, MyDebit and JomPAY.
  • Shape assurance that strengthens governance, controls and organisational resilience across a national payments institution.
  • Challenge how enterprise risks are identified, treated, monitored and reported before they become material exposures.
  • Influence risk-informed decisions by turning audit insight into clear priorities for Management and the Board.
  • Join a values-led environment built on Aspiration, Curiosity, Grit and Integrity.
TL;DR
  • Own risk-based operational audits, with a strong focus on Enterprise Risk Management and risk governance.
  • Decide where assurance effort matters most by applying professional judgement to complex and emerging risks.
  • Lead reviews independently or through audit teams, from scoping and fieldwork to reporting and remediation validation.
  • Deliver practical, evidence-based recommendations that strengthen accountability, oversight and resilience.
Why This Role Matters
  • Provide independent assurance that risk governance supports effective decisions and sustainable organisational resilience.
  • Test whether accountabilities, oversight, escalation and independent challenge work as intended.
  • Surface gaps in how strategic, emerging, systemic, ecosystem and third-party risks are understood and managed.
  • Give Management and the Board clearer insight into material risks, trends and escalating exposures.
  • Raise the quality of remediation by identifying root causes and validating that actions are sustainable.
What You Will Actually Do
  • Lead or independently execute risk-based operational audits across business processes, ERM and the Risk Management function.
  • Assess governance and operating models for clear accountability, effective oversight, structured escalation and robust challenge.
  • Evaluate horizon scanning, scenario analysis and RCSA across emerging, concentration, dependency and interdependency risks.
  • Test KRIs, thresholds and risk treatment decisions, including acceptance, exemptions, mitigation, contingency and exit strategies.
  • Shape concise audit reports and working papers supported by evidence, root-cause analysis, benchmarks and leading practices.
  • Drive closure by validating whether agreed remediation addresses the underlying risk sustainably.
Examples of This Role in Practice
  • A business accepts a material risk: decide whether the rationale, authority, mitigation and escalation are sufficiently robust.
  • A KRI remains within threshold while exposure is rising: challenge whether the indicator still gives timely and meaningful warning.
  • A critical service depends on a concentrated third party: test whether dependency, contingency, workaround and exit risks are understood.
  • A scenario analysis identifies a severe event: assess whether the response translates into clear ownership and management action.
  • A recurring audit issue is marked complete: validate the root cause, evidence and sustainability before supporting closure.
What Will Help You Succeed
  • Bring internal audit experience across business or operational processes, combined with hands‑on ERM experience or assurance over an enterprise risk function.
  • Apply strong knowledge of risk governance, ERM frameworks, RCSA, emerging risk assessment, KRIs, thresholds and risk reporting.
  • Use critical thinking, analytical rigour and sound professional judgement to reach clear, defensible conclusions.
  • Engage stakeholders confidently, provide constructive independent challenge and explain complex risk matters clearly.
  • Add value through experience in financial institutions, regulated payments, operational resilience or comparative ERM benchmarking.
  • Extend audit insight through IT general controls, artificial intelligence or data analytics capabilities.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Internal Audit Manager (Enterprise Risk Management)
Internal Audit Manager (Enterprise Risk Management)

Payment Network Malaysia • Malaysia

On-site
MYR 120,000 - 180,000
Enterprise Risk & Internal Audit Leader
Enterprise Risk & Internal Audit Leader

Payment Network Malaysia • Malaysia

On-site
MYR 120,000 - 180,000
ERM Audit Lead for Payments Risk & Governance
ERM Audit Lead for Payments Risk & Governance

PayNet (Payments Network Malaysia) • Kuala Lumpur

On-site
MYR 150,000 - 230,000
Principal Specialist, Cyber & Technology Risk (Cyber Risk)
Principal Specialist, Cyber & Technology Risk (Cyber Risk)

PayNet (Payments Network Malaysia) • Kuala Lumpur

On-site
MYR 260,000 - 420,000
Assistant Manager, Enterprise Risk Management
Assistant Manager, Enterprise Risk Management

UEM Sunrise Berhad • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Non-Financial Risk Specialist
Non-Financial Risk Specialist

YTL Sea Digital Bank Project • Kuala Lumpur

On-site
MYR 90,000 - 140,000
Internal Audit Executive
Internal Audit Executive

SmartHire by SEEK • Kuala Lumpur

On-site
MYR 60,000 - 90,000
Senior Specialist - Risk Management
Senior Specialist - Risk Management

Deriv.com • Cyberjaya

On-site
MYR 140,000 - 230,000
Senior Associate Internal Audit
Senior Associate Internal Audit

FINEXUS SDN BHD • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Manager, Technology Risk Management
Manager, Technology Risk Management

CTOS Data Systems • Malaysia

On-site
MYR 180,000 - 300,000