AVP, Information Security & Digital Risk Management Specialist

OCBC Bank

Singapore

On-site

SGD 180,000 - 240,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Competitive base salary
Comprehensive benefits
Community initiatives
Professional development

Job summary

OCBC Bank in Singapore seeks a senior Information Security and Digital Risk Management Specialist to safeguard the Group’s digital ecosystem and manage third-party risk. You will conduct risk assessments, implement controls, and advise on governance across technology, business, and control functions.

You will lead or support data-driven insights, policy development, and training to promote consistent risk management, with emphasis on MAS guidelines and regulatory alignment.

Qualifications

  • Degree in Computer Science, Information Security, or related field.
  • 8+ years in technology, information, or cyber risk management.
  • 5+ years in third-party risk management in financial services.
  • Certs: CISSP, CISA, CISM advantageous.
  • Experience with AI risk, governance and data security.
  • Knowledge of MAS guidelines and local regulatory frameworks.

Responsibilities

  • Conduct digital risk assessments and due diligence of third-party providers.
  • Develop and maintain third-party risk policies and frameworks.
  • Collaborate across technology, business, and control functions for end-to-end risk management.
  • Lead data-driven risk insights and reporting to senior management.
  • Provide training and awareness on technology and third-party risk management.

Skills

Cyber risk management
Third-party risk management
Cloud security (AWS/Azure)
Threat assessment
Stakeholder communication

Education

Degree in Computer Science or Information Security

Tools

SOC 2
OSPAR
NIST SP 800-53
ISO/IEC 27001

Job description

WHO WE ARE:

As Singapore’s longest established bank, we have been dedicated to enabling individuals and businesses to achieve their aspirations since 1932. How? By taking the time to truly understand people. From there, we provide support, services, solutions, and career paths that meet their individual needs and desires. Today, we’re on a journey of transformation. Leveraging technology and creativity to become a future-ready learning organisation. But for all that change, our strategic ambition is consistently clear and bold, which is to be Asia’s leading financial services partner for a sustainable future. We invite you to build the bank of the future. Innovate the way we deliver financial services. Work in friendly, supportive teams. Build lasting value in your community. Help people grow their assets, business, and investments. Take your learning as far as you can. Or simply enjoy a vibrant, future-ready career. Your Opportunity Starts Here.

Why Join

Protecting our customers’ assets and information is at the heart of what we do at OCBC Group. As an Information Security and Digital Risk Management Specialist, you will play a key role in safeguarding the Group's digital ecosystem and strengthening its resilience against evolving technology and cyber risks. In this role, you will conduct independent reviews of digital risks arising from third-party service arrangements. This includes assessing the design and operating effectiveness of controls implemented by third-party service providers and providing assurance on compliance with Group policies and regulatory requirements applicable to the arrangement, as well as relevant industry best practices.

How you succeed

To succeed in this role, you will combine strong domain knowledge, sound professional judgement, and effective stakeholder engagement skills. You are expected to stay abreast of emerging technology, information, and cyber risk trends, and translate these developments into practical risk insights and actionable mitigation strategies. You will work closely with technology, business, and control functions to identify material risks, provide constructive and independent challenge to existing controls where appropriate, and ensure that security policies, standards, and practices remain effective, proportionate, and aligned with business objectives.

What you do

Conduct digital risk assessments, due diligence reviews, and ongoing monitoring of third-party service providers. Support the development, implementation, and maintenance of third-party policies, procedures and frameworks in alignment with regulatory requirements and industry best practices. Collaborate with technology, business, and control functions to ensure effective end-to-end risk management for third-party service arrangements. Drive or support continuous improvement initiatives for the Third-Party Risk Management programme, including process optimisation, automation, and operating model enhancements. Lead or support data-driven initiatives leveraging enterprise data platforms to analyse risk data, identify trends and emerging risks, and provide clear, actionable insights to support risk-informed decision-making. Perform or support ongoing risk monitoring and management reporting on the Group’s technology and cyber risk posture relating to third-party services, highlighting key issues and trends to senior management and relevant committees. Support Group-wide initiatives to facilitate compliance with applicable legal and regulatory requirements, including the MAS Cyber Hygiene Notice, MAS Technology Risk Management Guidelines and MAS Guidelines on Outsourcing. Provide training and awareness to stakeholders on technology risk and third-party risk management to promote consistent understanding and application across the Group.

Who you are

A degree in Computer Science, Information Security, or a related discipline. More than eight years of relevant experience in technology, information, or cyber risk management, or information security, with at least five years of hands-on experience in third-party risk management, preferably within the financial services industry. Relevant professional certifications such as CISSP, CISA, CISM are advantageous. Strong knowledge and practical experience in conducting technical assessments across network and system infrastructure security, cloud-native security platforms and service offerings (such as Amazon Web Services or Microsoft Azure), and third-party assurance artefacts and security assessment frameworks (such as SOC 2 and OSPAR). Strong knowledge and practical experience in assessing risks and controls relating to Artificial Intelligence, including generative AI, AI governance, model risk, data security, privacy, third-party AI services and the responsible use of AI. Strong knowledge and practical experience in assessing risks and controls relating to Digital Assets and associated technologies, including distributed ledger technology, tokenisation, digital asset custody, smart contracts and the assessment of related technology, cyber and third-party risks. Strong working knowledge of Singapore regulatory frameworks, including the MAS Technology Risk Management Guidelines and MAS Guidelines on Outsourcing, and/or other regional regulatory frameworks and industry standards such as NIST SP 800-53, ISO/IEC 27001. Strong written and verbal communication skills, with the ability to articulate risk issues clearly and constructively to stakeholders. Ability to lead and drive initiatives, influence outcomes through others, and collaborate effectively across different seniority levels, functions, cultures, and geographies. Proactive, resilient, and able to perform effectively under pressure and tight timelines in a dynamic risk environment.

What we offer
  • Competitive base salary.
  • A suite of holistic, flexible benefits to suit every lifestyle.
  • Community initiatives.
  • Industry-leading learning and professional development opportunities.

Your wellbeing, growth and aspirations are every bit as cared for as the needs of our customers. Let’s build the bank we need for the future we want. Find the best version of yourself in a friendly, supportive team. Build lasting value in your community. Help people grow their assets, business, and investments. Take your learning as far as you can. Or simply enjoy a vibrant, future-ready career. Your Opportunity Starts Here. As the longest established Singapore bank, formed in 1932 from the merger of three local banks, we have grown from strength to strength to become a regional financial services group. With a deep history in Asia, we offer the most comprehensive coverage across ASEAN and Greater China, complemented with a presence in the leading economies of New York, London and Sydney. We are the second largest financial services group in Southeast Asia by assets with one of the world’s highest credit rating (Aa1 by Moody’s and AA- by both Fitch and S&P). We offer private banking services through our wholly‑owned subsidiary, Bank of Singapore, which operates on a unique open‑architecture product platform to source for the best‑in‑class products to meet its clients’ goals. Our insurance subsidiary, Great Eastern Holdings, is the oldest and most established life insurance group in Singapore and Malaysia.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AVP, Information Security & Digital Risk Management Specialist
AVP, Information Security & Digital Risk Management Specialist

OCBC Group • Singapore

On-site
SGD 180,000 - 300,000
Competitive base salary
Holistic benefits
Community initiatives
+1
VP/ED, Cyber Risk Management
VP/ED, Cyber Risk Management

OCBC Group • Singapore

On-site
SGD 300,000 - 550,000
Competitive base salary
Holistic benefits package
Professional development opportunities
AVP, Information Security & Digital Risk Management Specialist
AVP, Information Security & Digital Risk Management Specialist

OCBC (Singapore) • Singapore

On-site
SGD 150,000 - 200,000
Competitive base salary
Holistic benefits
Industry-leading learning & career dev
AVP, Business Analyst (Legal & Compliance)
AVP, Business Analyst (Legal & Compliance)

OCBC Group • Singapore

On-site
SGD 120,000 - 180,000
VP/ED, Cyber Risk Management
VP/ED, Cyber Risk Management

OCBC • Singapore

On-site
SGD 350,000 - 650,000
Competitive salary
Flexible benefits
Learning & development
+1
VP, Financial Crime Compliance Advisory Officer
VP, Financial Crime Compliance Advisory Officer

OCBC Group • Singapore

On-site
SGD 180,000 - 300,000
Competitive base salary.
A suite of holistic, flexible benefits
Community initiatives.
+1
Cybersecurity Solutioning & Transformation Team Lead (VP/ED) CISO)
Cybersecurity Solutioning & Transformation Team Lead (VP/ED) CISO)

OCBC Group • Singapore

On-site
SGD 180,000 - 260,000
Competitive salary
Flexible benefits
Community initiatives
+2
MGR, Data Loss Monitoring (AI, Automation & Digital Risk Analytics)
MGR, Data Loss Monitoring (AI, Automation & Digital Risk Analytics)

OCBC Group • Singapore

On-site
SGD 90,000 - 150,000
Competitive base salary
Learning & development opportunities
Community initiatives
+1
Threat Hunting Analyst (AVP)
Threat Hunting Analyst (AVP)

OCBC Group • Singapore

On-site
SGD 120,000 - 180,000
Competitive base salary
Holistic benefits
Community initiatives
+2
AVP, Product & Third-Party Risk Management Specialist
AVP, Product & Third-Party Risk Management Specialist

OCBC Bank • Singapore

On-site
SGD 90,000 - 150,000
Competitive base salary
Holistic benefits package
Community initiatives
+2