Vice President, Cyber Risk Management

Affin Bank Berhad

Kuala Lumpur

On-site

MYR 120,000 - 180,000

Full time

11 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Affin Bank Berhad is seeking a seasoned IT risk management professional to establish and oversee governance of technology risk. The role focuses on aligning risk appetite and thresholds with the banking group, and building a program to identify, assess, monitor, and report significant technology risks.

The candidate will assess third-party cyber risk, review vendor security documentation, and support TPRM frameworks while staying abreast of regulatory changes affecting technology risk.

Qualifications

  • Degree in IT, IS or Computing or related field.
  • Minimum 5 years in IT risk management, cyber risk or third-party risk management.
  • Professional certifications such as PMP, PMI-ACP, CEH, CRISC and CISSP are an advantage.

Responsibilities

  • Prepare and execute third-party cyber risk assessments and due diligence.
  • Maintain and update third-party risk inventories and project risk inventories.
  • Review vendor security docs, SOC reports, ISO certs and pen test reports.
  • Monitor vendor risk through reviews, assessments and threat intel.
  • Track risk remediation plans for third-party gaps and exceptions.
  • Provide advisory on technology risks, information security and controls.
  • Support development of TPRM, project risk frameworks, and policies.

Skills

IT risk management
Information security
Regulatory compliance

Education

Degree in IT/IS/Computing

Job description

JOB PURPOSE

Establish and maintain governance and oversight on the effectiveness of technology risk management for Affin Group. This function will be responsible for maintaining a strong technology risk management culture, formulating/reviewing the technology risk appetite, tolerances and threshold that aligns to the banking group’s risk appetite, and for establishing/maintaining a program to identify, assess, measure, monitor, control and report on significant technology risks.

RESPONSIBILITIES
  • Prepare and execute third-party cyber risk assessments, cloud risk assessment, project risk assessment and due diligence activities.
  • Maintain and update the third-party risk inventory, project risk inventory and ensure accurate documentation.
  • Review and assess vendor security documentation, including SOC reports, ISO certifications, penetration test reports, and security questionnaires.
  • Monitor ongoing vendor risk through periodic reviews, assessments, and threat intelligence.
  • Track and report risk remediation plans for third-party gaps and exceptions.
  • Identify, prepare and review technology and cyber risk metrics pertaining to third-party and project risk.
  • Perform risk analytics on data from internal and external sources to form leading and lagging risk indicators that identify emerging third-party risks before they surface.
  • Support the development and maintenance of third-party risk management (TPRM), Project Risk frameworks, policies, and procedures.
  • Assist in the design and delivery of training and awareness programs related to third-party cyber, project risk and technology risk.
  • Stay current with emerging risks, threats, and regulatory changes impacting third-party cyber risk and project risk.
  • Provide advisory, guidance, and recommendation on aspects related to technology risks, particularly in information security and controls, and ensure compliance with the internal IT policies & procedures, as well as regulatory guidelines.
  • Conduct an independent assessment review to identify, assess, and evaluate project management issues and best practices, as well as strategies to reduce, mitigate, or transfer IT and cyber risks for identified project risks.
  • Support senior management, including the CISO and GCRO, in overseeing the effective implementation of technology risk management at the entity level.
JOB REQUIREMENTS

Degree in IT, IS or Computing and/or other relevant domains. Minimum of 5 years in IT risk management, cyber risk management, project risk management, third-party risk management. Professional certifications such as PMP, PMI-ACP, CEH, CRISC, and CISSP are added advantages. Possess good knowledge and experience of information security and information technology risk management, solid experience in undertaking technical security assessments of technology-related solutions. Familiar with Bank Negara Malaysia regulatory requirements related to Technology Risk. Strong analytical, influencing and problem resolution skills. Ability to work independently with minimum supervision. Ability to work and collaborate with people across seniority and cultures.

ABOUT AFFIN BANK

People are the heart of AFFIN BANK. We have a positive and supportive environment where we celebrate people’s personal growth and encourage them to be the best versions of themselves, both in the workplace and in their community. Join AFFIN as we evolve to become a financial institution of the future, embracing innovation and technology to deliver unrivaled customer service. We're looking for colleagues who share our values and are ready to live them every day. Explore the exciting opportunities and make a real impact on the future of finance.

ALWAYS ABOUT YOU

At AFFIN, we strive to always connect and engage with our customers, to understand their changing needs and aspirations better. It represents our passion and commitment to the community we operate in, enabling us to quickly respond to changes and provide a personalised experience. At AFFIN, our people are aligned to our values of customer centricity, creativity and value creation. Our tagline “Always about you”, was crafted to drive loyalty and build our reputation as a creative and innovative financial organisation. Our people are at the heart of what we do and remain the focus of our customer centric culture. It’s about the initiatives we take in understanding and prioritising our stakeholders; our customers, employees and shareholders. As we venture through this metamorphosis journey, we are aware of their ever-changing needs and are embracing the new ways of this digital dimension. We put our hearts and minds into everything we do, to ensure that everyone we touch, receives unrivalled customer service.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Executive, AML- MIS
Executive, AML- MIS

Affin Bank Berhad • Kuala Lumpur

On-site
MYR 67,000 - 112,000
Senior Vice President, IRB Project
Senior Vice President, IRB Project

Affin Bank Berhad • Kuala Lumpur

On-site
MYR 300,000 - 600,000
Senior Manager, IRB Project
Senior Manager, IRB Project

Affin Bank Berhad • Kuala Lumpur

On-site
MYR 180,000 - 280,000
Senior Manager, Compliance Review
Senior Manager, Compliance Review

Affin Bank Berhad • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Senior Manager, Post-Approval Credit Review
Senior Manager, Post-Approval Credit Review

Affin Bank Berhad • Kuala Lumpur

On-site
MYR 89,000 - 201,000
Executive, Transaction Monitoring
Executive, Transaction Monitoring

Affin Bank Berhad • Kuala Lumpur

On-site
MYR 50,000 - 80,000
Head of Cyber Risk Management & Regulatory Oversight
Head of Cyber Risk Management & Regulatory Oversight

Affin Bank Berhad • Kuala Lumpur

On-site
MYR 120,000 - 160,000
Associate Risk Analyst/ Risk Analyst, Cyber Risk Specialist Unit (TCS)
Associate Risk Analyst/ Risk Analyst, Cyber Risk Specialist Unit (TCS)

Bank Negara Malaysia • Kuala Lumpur

On-site
MYR 90,000 - 120,000
Head, Cyber Risk Management
Head, Cyber Risk Management

Affin Bank Berhad • Kuala Lumpur

On-site
MYR 120,000 - 160,000
Assistant Manager, Business Planning & Analytics
Assistant Manager, Business Planning & Analytics

Affin Bank Berhad • Kuala Lumpur

On-site
MYR 120,000 - 200,000