Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.
OwnBank is seeking an IT Governance Manager / Head of IT Governance, Risk & Compliance to establish, implement, and maintain the Bank’s IT governance, technology risk management, compliance, IT controls, business continuity, disaster recovery, and outsourcing risk framework.
The role ensures that IT operations, systems, projects, vendors, policies, and controls are aligned with regulatory requirements, internal policies, business objectives, and the Bank’s risk appetite.
The IT Governance Manager / Head of IT Governance, Risk & Compliance is responsible for establishing, implementing, and maintaining the Bank’s IT governance, technology risk management, compliance, IT controls, business continuity, disaster recovery, and third-party outsourcing risk management framework.
The role ensures that IT operations, systems, projects, vendors, policies, and controls are aligned with regulatory requirements, internal policies, business objectives, and the Bank’s risk appetite. The position also provides oversight on IT resilience, regulatory compliance, audit readiness, and Board and Management reporting.
IT Governance Framework
Develop, implement, and maintain the Bank’s IT Governance Framework.
Ensure IT governance policies, standards, and procedures are aligned with business objectives and regulatory expectations.
Support IT Steering Committee, Risk Committee, and Management reporting requirements.
Monitor IT governance action items, decisions, and commitments.
Promote clear accountability, ownership, and segregation of duties across IT functions.
Ensure governance practices are embedded in IT operations, projects, systems, and vendor management.
Technology Risk & Compliance Management
Establish and maintain the IT Risk Management Framework.
Conduct regular technology risk assessments covering IT systems, infrastructure, applications, cloud services, and critical projects.
Maintain the IT Risk Register, including identified risks, risk owners, mitigation plans, target dates, and residual risk ratings.
Monitor compliance with BSP regulations, internal policies, cybersecurity requirements, and applicable industry standards.
Track and escalation high-risk issues, breaches, exceptions, and overdue remediation items.
Ensure timely closure of audit, compliance, and regulatory findings.
Policy & Standard Management
Own and manage the lifecycle of IT policies, standards, procedures, and governance documents.
Ensure IT policies are reviewed, updated, approved, communicated, and implemented on schedule.
Maintain version control, approval records, and evidence of policy dissemination.
Coordinate with IT, Risk, Compliance, Audit, and business units to ensure policy alignment.
Conduct policy awareness sessions and monitor completion of required training.
IT Controls & Assurance
Monitor and assess the effectiveness of IT general controls and technology risk controls.
Support internal audits, external audits, regulatory examinations, and control reviews.
Coordinate IT control self-assessments and compliance testing.
Track audit observations, management action plans, and remediation status.
Ensure control gaps are properly documented, risk-rated, assigned to owners, and resolved within agreed timelines.
Provide independent challenge on IT control weaknesses and risk acceptance decisions.
Business Continuity & Disaster Recovery
Oversee IT disaster recovery governance and ensure alignment with the Bank’s Business Continuity Management requirements.
Ensure all critical systems have documented Recovery Time Objectives, Recovery Point Objectives, recovery procedures, escalation paths, and dependency mapping.
Coordinate with IT Operations, business units, Risk, and Compliance in developing and maintaining disaster recovery plans.
Ensure annual disaster recovery testing and tabletop exercises are conducted, documented, and reported.
Review disaster recovery test results, identify gaps, and track corrective actions to closure.
Ensure backup, restoration, system failover, and recovery capabilities are periodically validated.
Report IT resilience status, DR readiness, and unresolved recovery risks to Management and relevant governance committees.
Third-Party & Outsourcing Risk Management
Establish and maintain governance over IT third-party and outsourced service providers.
Conduct or coordinate vendor risk assessments, due diligence reviews, and periodic performance evaluations.
Ensure critical IT vendors are covered by appropriate contracts, service level agreements, information security requirements, data privacy provisions, business continuity requirements, and exit arrangements.
Monitor vendor compliance with agreed SLAs, regulatory expectations, and contractual obligations.
Track vendor-related incidents, SLA breaches, control issues, and remediation plans.
Coordinate with Procurement, Legal, Compliance, Risk, and IT teams on vendor onboarding, contract renewal, and outsourcing risk reviews.
Ensure outsourced IT services remain subject to adequate oversight, monitoring, and governance by the Bank.
Regulatory Reporting, Management Reporting & Oversight
Prepare regular IT governance, risk, compliance, audit, resilience, and vendor oversight reports for Management and Board-level committees.
Maintain governance dashboards covering IT risks, audit findings, policy compliance, DR readiness, vendor risks, and key risk indicators.
Ensure reports are accurate, timely, and supported by proper evidence.
Escalate critical technology risks, control gaps, compliance breaches, and unresolved vendor issues.
Support regulatory examinations and ensure timely submission of required evidence and management responses.
Leadership & Stakeholder Management
Lead and develop the IT Governance, Risk & Compliance function.
Coordinate closely with IT Operations, IT Engineering, Product Management, Cybersecurity, Risk, Compliance, Internal Audit, Legal, Procurement, and business units.
Promote a strong culture of governance, accountability, risk awareness, compliance, and continuous improvement.
Provide guidance to IT teams on policy interpretation, control requirements, risk assessments, and regulatory expectations.
Support training and awareness initiatives related to IT governance, cybersecurity, business continuity, disaster recovery, and vendor risk management.
Bachelor’s degree in Information Technology, Computer Science, Information Systems, Engineering, Risk Management, or related field.
Master’s degree or postgraduate qualification is an advantage.
At least 8 to 10 years of experience in IT governance, IT risk management, information security, technology audit, compliance, business continuity, disaster recovery, or third-party risk management.
At least 3 to 5 years in a managerial or leadership role.
Experience in banking, digital banking, fintech, financial services, or regulated industries is highly preferred.
Strong working knowledge of BSP IT risk management expectations, outsourcing governance, cybersecurity, business continuity, and disaster recovery practices.
Certified Information Systems Auditor
Certified Information Security Manager
Certified in Risk and Information Systems Control
Certified Information Systems Security Professional
COBIT Foundation
ISO/IEC 27001 Lead Implementer or Lead Auditor
ISO 22301 Business Continuity Management certification
Project Management Professional or equivalent certification
IT Governance Frameworks
Technology Risk Management
Regulatory Compliance
IT Controls and Assurance
IT Policy and Standards Management
Business Continuity Management
Disaster Recovery Governance
Third-Party and Outsourcing Risk Management
Vendor Risk Assessment and SLA Monitoring
IT Audit and Regulatory Examination Management
Cybersecurity Governance
Risk Reporting and Dashboarding
Control Testing and Remediation Tracking
Strong leadership and accountability
Risk-based decision-making
Analytical and critical thinking
Strong communication and reporting skills
Stakeholder management
Integrity and professional judgment
Attention to detail
Ability to challenge constructively
Collaboration across IT, Risk, Compliance, Audit, and business teams
Continuous improvement mindset