Technology Risk Management
- Support technology risk reviews, risk assessments, and control effectiveness assessments across technology platforms.
- Identify and analyse technology risks, emerging risks, control gaps, and areas requiring remediation.
- Maintain and track remediation actions arising from incidents, audits, risk assessments, and regulatory reviews.
- Support Risk and Control Self-Assessment (RCSA) activities and maintenance of technology risk registers.
- Monitor Key Risk Indicators (KRIs), perform trend analysis, and prepare management reporting.
- Conduct thematic reviews and root cause analysis of control deficiencies.
- Prepare risk dashboards, metrics, and management reports.
- Support the review of technology changes and associated risk controls.
- Analyse change failures, unauthorised changes, and change-related incidents.
- Track change governance metrics and identify trends for reporting.
- Support improvement initiatives relating to change and release management processes.
- Support cybersecurity governance activities and track security risk remediation actions.
Requirements
Education
- Bachelor's Degree in Computer Science, Information Technology, Engineering, Information Systems, Cybersecurity, Risk Management, or a related discipline.
- Professional certification in technology risk, IT governance, cybersecurity, audit, or related domains will be an advantage.
Mandatory Requirements
- Minimum 3 years of relevant experience in one or more of the following areas: Technology Risk ManagementIT GovernanceIT ControlsCybersecurity GovernanceTechnology ComplianceIT AuditOperational RiskService ResilienceTechnology Project Governance
Preferred Experience
Experience in any of the following areas will be advantageous:
- Risk assessments and control testing
- Audit management
- RCSA execution
- KRI/KCI monitoring and reporting
- Incident and problem management
- Regulatory compliance reviews
- Cloud governance and security controls
- Third-party risk management
- Technology project risk oversight
Experience in banking, financial services, fintech, regulated industries, or large-scale technology environments will be an advantage.
Technical Competencies
Candidates should have a good understanding of:
- Technology risk management lifecycle
- Governance, Risk & Compliance (GRC) practices
- ITIL processes
- Cybersecurity principles
- Operational resilience
- Technology controls and governance
- Regulatory and industry standards, including: MAS Technology Risk Management (TRM) Guidelines, MAS Notice 644, MAS Notice 655, ISO 27001, NIST, COBIT
Knowledge of data analysis and reporting tools such as Microsoft Excel, Power BI, SQL, Python, or AI-enabled analytics tools will be advantageous.