Manager, Technology Risk Management

CTOS

Kuala Lumpur

On-site

MYR 180,000 - 240,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

CTOS is seeking a senior Technology Risk professional to join the 2LoD team to govern technology risk across the enterprise. You will oversee risk assessment, governance, and regulatory compliance, ensuring resilience and secure operations.

Key responsibilities include risk appetite, third-party risk, cloud governance, and model governance, with a focus on ethics, resilience, and regulatory alignment. Strong collaboration with 1LoD and stakeholders is essential.

Qualifications

  • Bachelor’s Degree in technology, computer science, information security, risk management, or related discipline.
  • Professional certifications such as CRISC, CISM, CISA, ISO 27001 Lead Implementer, or equivalent.

Responsibilities

  • Lead the development, implementation, and maintenance of the Technology Risk Management Framework (TRMF).
  • Maintain enterprise technology risk registers and monitor risk treatment plans.
  • Establish, monitor, and challenge technology risk appetite metrics, KRIs, thresholds, and escalation triggers.
  • Support governance frameworks for AI and emerging technologies, including risk assessment, compliance, and model governance.
  • Provide independent oversight and challenge to 1LoD technology operations and implementations.
  • Conduct technology risk assessments for infrastructure, applications, cloud services, and projects.
  • Lead third-party risk assessments for cloud providers, MSPs, and vendors.
  • Ensure risk governance aligns with BNMRiT, ISO 27001, and regulatory requirements.

Skills

Risk management
Cybersecurity
Regulatory compliance
Stakeholder management
Independent oversight

Education

Bachelor’s degree in technology or related field
CRISC/CISM/CISA/ISO 27001 Lead Implementer

Job description

Jora Malaysia will close on 9th September 2026. Thank you for being with us, we are cheering you on as you continue your career journey.

We are Malaysia’s leading Credit Reporting Agency (CRA) and we are aggressively expanding our business, and looking for dynamic, driven and motivated individuals to join our team. Our Direct-To-Consumer segment (D2C), is one of our fastest growing product areas in the market, with an abundance of expansion plans and innovative ideas on hand.

ROLE OVERVIEW

The role is part of theSecond Line of Defense (2LoD) team, supporting the enterprise risk function inmanaging technology risk across the organisation. The role is responsible for supportingthe identification, assessment, monitoring, and mitigation oftechnology-related risks, while providing independent oversight, challenge, andgovernance across technology operations. Key areas of focus include technologyoperational resilience, cloud governance, third-party technology risk, andresponsible AI governance. The role ensures CTOS operates within its technologyrisk appetite and complies with regulatory, security, and business resiliencerequirements.

While the role primarilyfocuses on technology risk management, the incumbent is expected to possess anunderstanding of cybersecurity principles and cyber risk management practicesdue to the interconnected nature of technooogy and cyber risks.

KEY RESPONSIBILITIES
Technology Risk Governance
  • Lead the development, implementation, and maintenance of the TechnologyRisk Management Framework (TRMF).
  • Maintain enterprise technology risk registers and monitor risk treatmentplans.
  • Establish, monitor, and challenge technology risk appetite metrics, KRIs,thresholds, and escalation triggers to ensure risks remain within approvedtolerance levels.
  • Support the development andoversight of governance frameworks for AI and emerging technologies, includingrisk assessment, regulatory compliance, ethical considerations, modelgovernance and operational controls.
Technology Risk Assessment & Oversight
  • Provide independent oversight and challenge to First Line of Defense(1LoD) technology operations and implementations.
  • Conduct technology risk assessments covering infrastructure,applications, cloud services, and strategic technology projects.
  • Lead technology due diligence and risk assessments for third-parties,including cloud providers, managed service providers, solution providers, andother vendors.
  • Assess and challenge technology risks arising from major technologytransformation programmes, architecture decisions, application developmentinitiatives, technology migrations, platform modernisation efforts and adoptionof emerging technologies.
  • Evaluate risks related tosystem availability, scalability, capacity management, technology debt, obsolescence,and operational sustainability.
  • Provide independent oversight and validation of technology resilience capabilities,including IT disaster recovery, backup management, capacity management, highavailability design, technology lifecycle management, incident recoveryreadiness & testing, and technology obsolescence management.
  • Provide independent oversightover cloud adoption initiatives, including governance, resilience,concentration risk, vendor lock-in risk, shared responsibility controls, andcompliance requirements.
Regulatory Compliance & Assurance
  • Ensure technology risk governance, assessments, monitoring, reporting,and assurance activities are aligned with applicable requirements, such as BNMRMiT and ISO 27001.
  • Coordinate responses toaudits, regulatory reviews, and customer due diligence.
Governance Reporting & Stakeholder Management
  • Prepare risk reports, dashboards, committee papers, and managementupdates.
  • Present key technology risks and resilience matters to management andgovernance forums.
  • Partner with business andtechnology stakeholders to promote effective technology risk managementpractices across the organisation.
WHAT DOES IT TAKE TO BE SUCCESSFUL
Qualifications
  • Bachelor’s Degree in technology, computer science, information security,risk management, or related discipline.
  • Professional certifications such as CRISC, CISM, CISA, ISO 27001 LeadImplementer, or equivalent.
Work Experience
  • 6-10 years of experience in Technology Risk, Information Security, ITGovernance, Operational Resilience, or related discipline.
  • Familiarity with industry standards and regulatory frameworks such as BNMRMiT, CSA’s Cloud Control Matrix, ISO 27001 or similar standards.
  • Strong understanding of technology architecture, cloud computing, SDLC,and IT operations.
  • Knowledge of operational resilience, business continuity, disasterrecovery and service management practices.
  • Ability to assess emerging technology risks, including cloud, AI andautomation.
  • Ability to apply risk-based thinking and provide independent challengeand practical recommendations.
  • Strong analytical and risk assessment capabilities with experiencetranslating complex technical risks into business impacts.
  • Strong stakeholder management and cross-functional coordination skills.
  • Effective verbal and written communication skills, with the ability toengage both technical and non-technical audiences (e.g. customers, management,and business stakeholders).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, Technology Risk Management
Manager, Technology Risk Management

CTOS Data Systems • Malaysia

On-site
MYR 180,000 - 300,000
IT Risk & Compliance Manager (Technology Risk)
IT Risk & Compliance Manager (Technology Risk)

Powtech Solution • Kuala Lumpur

On-site
MYR 90,000 - 150,000
EPF
SOCSO
EIS
+1
IT Risk Manager
IT Risk Manager

Powtech Solution • Kuala Lumpur

On-site
MYR 120,000 - 180,000
EPF
SOCSO
EIS
+1
Senior Manager - Technology Risk Management & Advisory
Senior Manager - Technology Risk Management & Advisory

AmBank • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Senior IT Risk & Compliance Specialist
Senior IT Risk & Compliance Specialist

MOL AccessPortal • Kuala Lumpur

On-site
MYR 120,000 - 180,000
IT Governance, Risk & Compliance Manager
IT Governance, Risk & Compliance Manager

CapBay • Kuala Lumpur

Hybrid
MYR 90,000 - 150,000
Manager - Risk Management (Technology Risk Management)
Manager - Risk Management (Technology Risk Management)

Hong Leong Bank • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Chief Technology Officer
Chief Technology Officer

Jobstreet Malaysia • Kuala Lumpur

On-site
MYR 280,000 - 480,000
Head, Cyber Risk Management
Head, Cyber Risk Management

Affin Bank Berhad • Kuala Lumpur

On-site
MYR 120,000 - 160,000
SENIOR MANAGER - GOVERNANCE, RISK AND COMPLIANCE (RISK & COMPLIANCE) (EG12)
SENIOR MANAGER - GOVERNANCE, RISK AND COMPLIANCE (RISK & COMPLIANCE) (EG12)

Hartalega • Selangor

On-site
MYR 180,000 - 280,000