Manager - IT Risk and Compliance

Great Eastern

Kuala Lumpur

On-site

MYR 180,000 - 240,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Great Eastern seeks an experienced IT Risk and Compliance professional to join our team in Kuala Lumpur. You will evaluate technology risk, implement an IT compliance programme, and monitor regulatory requirements to safeguard our information systems.

The role requires 5+ years in technology risk or IT audit, relevant certifications (CISA/CISM/CRISC/CISSP) and strong analytical, communication, and stakeholder management skills. Insurance/financial services experience is a plus.

Qualifications

  • Bachelor’s degree in IT, risk or related field.
  • Minimum 5 years in technology risk, IT compliance or IT audit.
  • Professional certifications preferred (CISA/CISM/CRISC/CISSP).
  • Strong knowledge of MAS TRM and RMiT requirements.
  • Experience with RCSA methodologies and control testing.
  • Experience in data analytics and risk reporting.
  • Excellent communication and stakeholder management.
  • Insurance/financial services experience is a plus.

Responsibilities

  • Evaluate IT risk across processes, systems and data.
  • Maintain an active risk view and report to Group IT management.
  • Implement and maintain IT compliance programme with key controls.
  • Monitor regulatory compliance and report gaps to management.
  • Track changes in tech regulations and recommend remediation.
  • Coordinate IT audit engagements and monitor progress.
  • Prepare management reports on IT compliance and risk.
  • Support Third-Party Risk Management (TPRM) processes.

Skills

Regulatory IT risk
IT governance
Data analytics
Stakeholder management
Analytical skills
Communication skills
Report writing
IT controls testing

Education

Bachelor's degree in Information Security / IT / Risk Management
Certifications: CISA / CISM / CRISC / CISSP

Job description

Jora Malaysia will close on 9th September 2026. Thank you for being with us, we are cheering you on as you continue your career journey.

Integral role in IT Risk and Compliance team, responsible to evaluate overall information technology risk, maintain an active view, and report the overall risk & compliance posture to Group IT management on regular basis.

Implement and maintain the IT Compliance Programme to provide assurance over Group IT's compliance status. This includes validating key IT controls based on annual prioritization using industry-accepted sampling methodologies. Reviews will cover relevant processes, systems, reports, and metrics.

Monitor and assess IT compliance with regulatory requirements, internal policies, and standards, and report any compliance gaps or breaches to management.

Track and evaluate changes in technology-related regulations and legislation that may impact Group IT's technology risk and compliance posture, and recommend appropriate remediation measures.

Conduct compliance reviews of key IT processes and systems in accordance with the annual review plan, identifying gaps against regulatory, policy, and control requirements.

Prepare timely compliance review reports, communicate findings to management, and monitor remediation actions through to closure.

Support the consolidation and submission of Compliance Event Reporting from Group IT to Group Risk Management (GRM) and local Risk Management & Compliance (RM&C) teams.

Support the review and assessment of Control Risk Self-Assessment (CRSA) activities in accordance with GRM and local RM&C requirements.

Participate in technology risk assessments for emerging technology domains, including Artificial Intelligence (AI), Cloud Computing, and other new technologies.

Support the management and oversight of Third-Party Risk Management (TPRM) processes for the GELM IT department.

Prepare and maintain regular management reporting on IT compliance and technology risk matters.

Coordinate IT audit engagements, including monitoring audit progress, tracking information requests, and escalating overdue items where necessary.

Participate in root cause analysis activities for technology incidents and assist in identifying corrective and preventive actions.

Conduct awareness sessions and promote staff understanding of IT risk, compliance requirements, and control responsibilities.

Support the Department Risk Officer and Department Compliance Officer in executing risk and compliance governance responsibilities.

Maintain the department's Risk Control Self-Assessment (RCSA) framework and perform control testing in accordance with GRM and local RM&C requirements.

Review and assess various risk assessments, including Project Risk Assessments, General Purpose Risk Assessments, IT Risk Acceptance requests, and related technology risk documentation.

  • Bachelor's Degree in Information Technology, Business Administration, Risk Management, Information Security, or a related discipline.
  • Minimum 5 of relevant experience in Technology Risk, IT Compliance, IT Audit, Information Security, IT Governance, or Risk Management.
  • Professional certifications such as CISA, CISM, CRISC, CISSP, or equivalent are preferred.
  • Good understanding of MAS Technology Risk Management (TRM) Guidelines and BNM Risk Management in Technology (RMiT) requirements.
  • Knowledge and hands-on experience in Risk and Control Self-Assessment (RCSA) methodologies, including control design and control effectiveness testing.
  • Experience in data analytics and reporting, including the use of analytics tools to support risk and compliance monitoring.
  • Strong analytical, problem-solving, and stakeholder management skills.
  • Excellent communication, presentation, and report-writing skills.
  • Experience in the insurance, banking, or financial services industry would be an advantage.
  • Champion and embody our Core Values in everyday tasks and interactions.
  • Demonstrate high level of integrity and accountability.
  • Take initiative to drive improvements and embrace change.
  • Take accountability of business and regulatory compliance risks, implementing measures to mitigate them effectively.
  • Keep abreast with industry trends, regulatory compliance, and emerging threats and technologies to understand and highlight potential concerns/ risks to safeguard our company proactively.

Founded in 1908, Great Eastern is a well-established market leader and trusted brand in Singapore and Malaysia. With over S$100 billion in assets and more than 16 million policyholders, including 12.5 million from government schemes, it provides insurance solutions to customers through three successful distribution channels – a tied agency force, bancassurance, and financial advisory firm Great Eastern Financial Advisers. The Group also operates in Indonesia and Brunei. The Great Eastern Life Assurance Company Limited and Great Eastern General Insurance Limited have been assigned the financial strength and counterparty credit ratings of "AA-" by S&P Global Ratings since 2010, one of the highest among Asian life insurance companies. Great Eastern's asset management subsidiary, Lion Global Investors Limited, is one of the leading asset management companies in Southeast Asia. Great Eastern is a subsidiary of OCBC, the longest established Singapore bank, formed in 1932. It is the second largest financial services group in Southeast Asia by assets and one of the world’s most highly-rated banks, with an Aa1 rating from Moody’s and AA- by both Fitch and S&P. Recognised for its financial strength and stability, OCBC is consistently ranked among the World’s Top 50 Safest Banks by Global Finance and has been named Best Managed Bank in Singapore by The Asian Banker.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, Technology Risk Management
Manager, Technology Risk Management

Great Eastern • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Senior Audit Associate
Senior Audit Associate

Great Eastern • Kuala Lumpur

On-site
MYR 78,000 - 106,000
Manager - IFRS Financial Reporting
Manager - IFRS Financial Reporting

Great Eastern • Kuala Lumpur

On-site
MYR 70,000 - 100,000
Senior IT Business Partner
Senior IT Business Partner

Great Eastern • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Senior Data Scientist
Senior Data Scientist

Great Eastern • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Audit Associate (Opportunity to gain experience with one of the Big 4 Accounting Firm!)
Audit Associate (Opportunity to gain experience with one of the Big 4 Accounting Firm!)

Great Eastern • Kuala Lumpur

On-site
MYR 60,000 - 90,000
Assistant Manager, Data & Insights Analyst (GETB)
Assistant Manager, Data & Insights Analyst (GETB)

Great Eastern • Kuala Lumpur

On-site
MYR 90,000 - 130,000
Intern (GELM Operations-Policy Servicing Administration)
Intern (GELM Operations-Policy Servicing Administration)

Great Eastern • Kuala Lumpur

On-site
MYR 60,000 - 90,000
Manager, Financial Risk
Manager, Financial Risk

Great Eastern • Kuala Lumpur

On-site
MYR 180,000 - 260,000
Associate - Premium Management
Associate - Premium Management

Great Eastern • Kuala Lumpur

On-site
MYR 60,000 - 90,000