Vice President, Cyber Risk Management

Affin Pheim

Malaysia

On-site

MYR 120,000 - 180,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

AFFIN is seeking an experienced IT risk professional to establish and oversee technology risk governance for the group. You will lead third-party risk assessments, monitor vendor security, and align risk appetite with the bank's standards.

The role requires a degree in IT/Computing, 5+ years in IT risk management, and certifications such as CRISC/CISSP; familiarity with Bank Negara Malaysia regulations is a plus.

Qualifications

  • Degree in IT, IS or Computing required.
  • Minimum of 5 years in IT risk management, cyber risk management, project risk management, third-party risk management.
  • Certifications such as PMP, PMI-ACP, CEH, CRISC, and CISSP are advantageous.

Responsibilities

  • Prepare and execute third-party cyber risk assessments, cloud risk assessments, project risk assessments and due diligence.
  • Maintain and update risk inventories and ensure accurate documentation.
  • Review vendor security documentation including SOC reports, ISO certifications, penetration test reports, and security questionnaires.
  • Monitor vendor risk through reviews, assessments, and threat intelligence.
  • Track risk remediation plans for third-party gaps and exceptions.
  • Provide advisory on technology risks and ensure compliance with internal policies and regulatory guidelines.
  • Support senior management in overseeing technology risk management implementation.

Skills

IT risk management
Cyber risk management
Project risk management
Third-party risk management
Regulatory knowledge

Education

Degree in IT/Computing

Job description

# **Create your future with Affin! You too can make a difference.***Join us at AFFIN, where the open minds meet and be inspired by a shared commitment to great work. Here, you don't just stay at the forefront of the industry - you can make a difference too.***JOB PURPOSE**Establish and maintain governance and oversight on the effectiveness of technology risk management for Affin Group. This function will be responsible for maintaining a strong technology risk management culture, formulating/reviewing the technology risk appetite, tolerances and threshold that aligns to the banking group's risk appetite, and for establishing/maintaining a program to identify, assess, measure, monitor, control and report on significant technology risks.**RESPONSIBILITIES*** Prepare and execute third-party cyber risk assessments, cloud risk assessment, project risk assessment and due diligence activities.* Maintain and update the third-party risk inventory, project risk inventory and ensure accurate documentation.* Review and assess vendor security documentation, including SOC reports, ISO certifications, penetration test reports, and security questionnaires.* Monitor ongoing vendor risk through periodic reviews, assessments, and threat intelligence.* Track and report risk remediation plans for third-party gaps and exceptions.* Identify, prepare and review technology and cyber risk metrics pertaining to third-party and project risk.* Perform risk analytics on data from internal and external sources to form leading and lagging risk indicators that identify emerging third-party risks before they surface.* Support the development and maintenance of third-party risk management (TPRM), Project Risk frameworks, policies, and procedures.* Assist in the design and delivery of training and awareness programs related to third-party cyber, project risk and technology risk.* Stay current with emerging risks, threats, and regulatory changes impacting third-party cyber risk and project risk.* Provide advisory, guidance, and recommendation on aspects related to technology risks, particularly in information security and controls, and ensure compliance with the internal IT policies & procedures, as well as regulatory guidelines.* Conduct an independent assessment review to identify, assess, and evaluate project management issues and best practices, as well as strategies to reduce, mitigate, or transfer IT and cyber risks for identified project risks.* Support senior management, including the CISO and GCRO, in overseeing the effective implementation of technology risk management at the entity level.+**JOB REQUIREMENTS*** Degree in IT, IS or Computing and/or other relevant domains.* Minimum of 5 years in IT risk management, cyber risk management, project risk management, third-party risk management.* Professional certifications such as PMP, PMI-ACP, CEH, CRISC, and CISSP are added advantages.* Possess good knowledge and experience of information security and information technology risk management, solid experience in undertaking technical security assessments of technology-related solutions.* Familiar with Bank Negara Malaysia regulatory requirements related to Technology Risk.* Strong analytical, influencing and problem resolution skills. Ability to work independently with minimum supervision.* Ability to work and collaborate with people across seniority and cultures.### Get In TouchJoin AFFIN as we evolve to become a financial institution of the future, embracing innovation and technology to deliver unrivaled customer service. We're looking for colleagues who share our values and are ready to live them every day.Explore the exciting opportunities and make a real impact on the future of finance. Come be a part of our journey today!\"Always About You\"At AFFIN, we strive to always connect and engage with our customers, to understand their changing needs and aspirations better. It represents our passion and commitment to the community we operate in, enabling us to quickly respond to changes and provide a personalised experience.At AFFIN, our people are aligned to our values of customer centricity, creativity and value creation. Our tagline \"Always about you\", was crafted to drive loyalty and build our reputation as a creative and innovative financial organisation.Our people are at the heart of what we do and remain the focus of our customer centric culture. It's about the initiatives we take in understanding and prioritising our stakeholders; our customers, employees and shareholders. As we venture through this metamorphosis journey, we are aware of their ever-changing needs and are embracing the new ways of this digital dimension. We put our hearts and minds into everything we do, to ensure that everyone we touch, receives unrivalled customer service.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Vice President, Cyber Risk Management
Vice President, Cyber Risk Management

Affin Bank Berhad • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Executive, AML- MIS
Executive, AML- MIS

Affin Pheim • Malaysia

On-site
MYR 60,000 - 90,000
Associate, Client Service Officer, Sabah Corporate Office, Group Corporate Banking
Associate, Client Service Officer, Sabah Corporate Office, Group Corporate Banking

Affin Pheim • West Coast Division

On-site
MYR 67,000 - 89,000
Unit Head, Fraud Management
Unit Head, Fraud Management

Affin Pheim • Kuala Lumpur

On-site
MYR 180,000 - 280,000
Executive, Transaction Monitoring
Executive, Transaction Monitoring

Affin Pheim • Kuala Lumpur

On-site
MYR 60,000 - 120,000
Assistant Manager, Corporate Strategy
Assistant Manager, Corporate Strategy

Affin Bank Berhad • Kuala Lumpur

On-site
MYR 120,000 - 180,000
BRCM Officer, Securities
BRCM Officer, Securities

Affin Hwang Investment Bank • Kuala Lumpur

On-site
MYR 90,000 - 170,000
Senior Vice President, IRB Project
Senior Vice President, IRB Project

Affin Bank Berhad • Kuala Lumpur

On-site
MYR 300,000 - 600,000
Assistant Branch Manager
Assistant Branch Manager

Affin Pheim • Kuantan

On-site
MYR 120,000 - 180,000
Executive, AML- MIS
Executive, AML- MIS

Affin Bank Berhad • Kuala Lumpur

On-site
MYR 67,000 - 112,000