Jora Malaysia will close on 9th September 2026. Thank you for being with us, we are cheering you on as you continue your career journey.
We are Malaysia’s leading Credit Reporting Agency (CRA) and we are aggressively expanding our business, and looking for dynamic, driven and motivated individuals to join our team. Our Direct-To-Consumer segment (D2C), is one of our fastest growing product areas in the market, with an abundance of expansion plans and innovative ideas on hand.
ROLE OVERVIEW
The role is part of theSecond Line of Defense (2LoD) team, supporting the enterprise risk function inmanaging technology risk across the organisation. The role is responsible for supportingthe identification, assessment, monitoring, and mitigation oftechnology-related risks, while providing independent oversight, challenge, andgovernance across technology operations. Key areas of focus include technologyoperational resilience, cloud governance, third-party technology risk, andresponsible AI governance. The role ensures CTOS operates within its technologyrisk appetite and complies with regulatory, security, and business resiliencerequirements.
While the role primarilyfocuses on technology risk management, the incumbent is expected to possess anunderstanding of cybersecurity principles and cyber risk management practicesdue to the interconnected nature of technooogy and cyber risks.
KEY RESPONSIBILITIES
Technology Risk Governance
- Lead the development, implementation, and maintenance of the TechnologyRisk Management Framework (TRMF).
- Maintain enterprise technology risk registers and monitor risk treatmentplans.
- Establish, monitor, and challenge technology risk appetite metrics, KRIs,thresholds, and escalation triggers to ensure risks remain within approvedtolerance levels.
- Support the development andoversight of governance frameworks for AI and emerging technologies, includingrisk assessment, regulatory compliance, ethical considerations, modelgovernance and operational controls.
Technology Risk Assessment & Oversight
- Provide independent oversight and challenge to First Line of Defense(1LoD) technology operations and implementations.
- Conduct technology risk assessments covering infrastructure,applications, cloud services, and strategic technology projects.
- Lead technology due diligence and risk assessments for third-parties,including cloud providers, managed service providers, solution providers, andother vendors.
- Assess and challenge technology risks arising from major technologytransformation programmes, architecture decisions, application developmentinitiatives, technology migrations, platform modernisation efforts and adoptionof emerging technologies.
- Evaluate risks related tosystem availability, scalability, capacity management, technology debt, obsolescence,and operational sustainability.
- Provide independent oversight and validation of technology resilience capabilities,including IT disaster recovery, backup management, capacity management, highavailability design, technology lifecycle management, incident recoveryreadiness & testing, and technology obsolescence management.
- Provide independent oversightover cloud adoption initiatives, including governance, resilience,concentration risk, vendor lock-in risk, shared responsibility controls, andcompliance requirements.
Regulatory Compliance & Assurance
- Ensure technology risk governance, assessments, monitoring, reporting,and assurance activities are aligned with applicable requirements, such as BNMRMiT and ISO 27001.
- Coordinate responses toaudits, regulatory reviews, and customer due diligence.
Governance Reporting & Stakeholder Management
- Prepare risk reports, dashboards, committee papers, and managementupdates.
- Present key technology risks and resilience matters to management andgovernance forums.
- Partner with business andtechnology stakeholders to promote effective technology risk managementpractices across the organisation.
WHAT DOES IT TAKE TO BE SUCCESSFUL
Qualifications
- Bachelor’s Degree in technology, computer science, information security,risk management, or related discipline.
- Professional certifications such as CRISC, CISM, CISA, ISO 27001 LeadImplementer, or equivalent.
Work Experience
- 6-10 years of experience in Technology Risk, Information Security, ITGovernance, Operational Resilience, or related discipline.
- Familiarity with industry standards and regulatory frameworks such as BNMRMiT, CSA’s Cloud Control Matrix, ISO 27001 or similar standards.
- Strong understanding of technology architecture, cloud computing, SDLC,and IT operations.
- Knowledge of operational resilience, business continuity, disasterrecovery and service management practices.
- Ability to assess emerging technology risks, including cloud, AI andautomation.
- Ability to apply risk-based thinking and provide independent challengeand practical recommendations.
- Strong analytical and risk assessment capabilities with experiencetranslating complex technical risks into business impacts.
- Strong stakeholder management and cross-functional coordination skills.
- Effective verbal and written communication skills, with the ability toengage both technical and non-technical audiences (e.g. customers, management,and business stakeholders).