VP, Risk & Controls Officer (Risk Governance & Assurance), Technology Group

GIC

Singapore

On-site

SGD 180,000 - 260,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Flexible working arrangement
In-office four days a week
Equal opportunity employer

Job summary

GIC is seeking a VP/SVP Risk & Controls Officer to embed within the Technology function, supporting investment and corporate units. You will lead incident management, audits, and controls design, driving RCA/CAPA and ensuring governance across platforms.

Join a dynamic team in Singapore that values pragmatism and collaboration, with a flexible working pattern and a four‑day in-office week to foster in-person collaboration while enabling remote work where appropriate.

Qualifications

  • Experience in technology risk, IT controls, or IT audit within financial services.
  • Strong ability to lead RCA/CAPA remediation across teams and to author standards and SOPs.

Responsibilities

  • Lead incident and problem management across the technology function with strong risk discipline.
  • Coordinate internal and external audit engagements and manage audit responses.
  • Establish and maintain policies, standards, and SOPs for control domains.
  • Design and embed controls across the technology lifecycle and delivery workflows.
  • Support resilience with disaster recovery and service continuity frameworks.
  • Develop KRIs/KCIs and risk dashboards for senior stakeholders.
  • Assist third-party governance for outsourced technology services.
  • Engage stakeholders across technology, risk, and audit to foster a risk-aware culture.

Skills

Risk management
Incident management
Audit collaboration
Policy and SOPs
Controls design
Operational resilience
Monitoring and reporting
Stakeholder engagement

Education

Degree in Information Systems/Computer Science/Finance

Tools

COSO
COBIT

Job description

GIC is one of the world’s largest sovereign wealth funds. With over 2,000 employees across 11 locations around the world, we invest in more than 40 countries globally across asset classes and businesses. Working at GIC gives you exposure to an extraordinary network of the world’s industry leaders. As a leading global long-term investor, we Work at the Point of Impact for Singapore’s financial future, and the communities we invest in worldwide.

Technology Group

We experiment, design, and lead a 24×7 global business where we support core capabilities in asset management, trading, investment operations, and risk management. We deliver secure, reliable, and integrated solutions, and provide insights on new, and emerging technologies.

Infrastructure & Cybersecurity Resilience (ICR)

We design, build, and secure the technology foundations that power GIC’s global investment operations. We aim to deliver resilient, scalable, and secure infrastructure that empowers our people and businesses to perform securely, efficiently, and effectively.

What impact can you make in this role?

We are seeking a Risk & Controls (R&C) professional to be embedded within the Technology function supporting investment and corporate business units. This role will be part of the R&C function which comprises team members driving R&C Strategy and Standards settings.

Operating within the First Line of Defence, this role partners with engineering, architecture, and platform teams to ensure technology risks are effectively managed and controls are embedded across systems and delivery processes. The role focuses on enabling secure, resilient, and well-governed platforms that support investment decision-making and operations.

What will you do as a VP/SVP Risk & Controls Officer (Risk Governance & Assurance)?
Incident & Problem Management
  • Lead and coordinate the incident and problem management process across the technology function, partnering with teams in all divisions to ensure incidents and problems are managed with strong risk discipline
  • Provide risk input into major incident reviews and problem records
  • Drive Root Cause Analysis (RCA) and manage the Corrective and Preventive Actions (CAPA) process to permanent closure
  • Track remediation of control failures and gaps identified in technology incidents through to sustainable closure, feeding learnings back into controls development
  • Translate operational failures into clear control improvements and business impact
Audit Engagement
  • Partner with technology teams to prepare for audits, strengthening controls and pre-empting findings ahead of engagements
  • Lead internal and external audit engagements on behalf of the first line, collating and reviewing control artefacts
  • Act as the single point of contact to manage audit responses; review responses and coordinate management review before submission
  • Coordinate with the second-line IT risk management function, which governs external audit engagements
  • Translate audit observations into clear, actionable remediation plans
  • Track audit findings and remediation commitments through to closure
Standards & Procedures
  • Establish and maintain fit-for-purpose policies, standards, and Standard Operating Procedures (SOPs) across control domains, partnering with embedded risk and controls specialists and technology teams to define them
  • Centralise the source of these documents for the technology function and manage version control and accessibility
  • Ensure standards and SOPs are complete and high-quality to enable evidence-based Operational Risk Self-Assessment (ORSA) and continuous controls monitoring (CCM)
  • Drive internal compliance and incorporate feedback from embedded risk and controls teams on standards and SOPs
  • Translate control requirements into clear, usable documentation and guide teams on how standards apply to day-to-day controls and compliance checks
Controls Design, Implementation & Monitoring
  • Design and embed controls across the technology lifecycle (SDLC, change management, access controls, data governance) within the domain
  • Ensure controls are integrated into delivery workflows (e.g., DevOps, CI/CD) and validate adherence to governance processes, evidenced by Key Control Indicators (KCIs)
  • Maintain and enhance Operational Risk Self-Assessments (ORSA), progressing toward evidence-based, continuous controls monitoring (CCM)
Operational Resilience
  • Support system resilience, disaster recovery, and service continuity frameworks
Monitoring & Reporting
  • Develop and track Key Risk Indicators (KRIs) and Key Control Indicators (KCIs) for the domain
  • Produce risk dashboards and insights for senior stakeholders
  • Highlight emerging risks across systems, platforms, and dependencies
Third-Party Governance
  • Support risk assessments and controls for vendors and service providers, ensuring appropriate oversight of outsourced technology services
Stakeholder Engagement
  • Act as a liaison between technology teams (first line), IT risk management (second line), and internal audit (third line)
  • Build strong relationships with engineering and platform teams
  • Promote a risk-aware culture while supporting delivery and innovation
What qualifications or skills should you possess in this role?
  • Minimally 6 years in technology risk, IT controls, operational risk, governance, IT operations, or IT audit within financial services
  • Strong understanding of technology risk and IT service management (incident, problem, change); audit processes, evidence standards, and control testing; and policy, standard, and SOP frameworks with their documentation governance, with hands‑on experience in one or more of these domains a strong plus, whether managing audit engagements, running RCA/CAPA remediation across teams, or authoring standards and SOPs to enable ORSA or continuous controls monitoring
  • Rigour in root‑cause analysis and driving corrective and preventive actions to sustainable closure; excellent writing, structuring, and review skills
  • Knowledge of control frameworks (e.g., COSO, COBIT) and operational risk methodologies (ORSA)
  • Ability to balance risk management with delivery priorities; strong stakeholder management and communication skills
  • Degree in Information Systems, Computer Science, Finance, or a related field; relevant certifications (e.g., CISA, CRISC, CISSP) are advantageous
Work at the Point of Impact

We need to be forward-looking to attract the right people to help us become the Leading Global Long-term Investor. Join our ambitious, agile, and diverse teams - be empowered to push boundaries and pursue innovative ideas, share your views, and be heard. Be anchored on our PRIME Values: Prudence, Respect, Integrity, Merit and Excellence, which guides us in how we make our day-to-day decisions. We strive to inspire. To make an impact.

GIC is a Great Place to Work

At GIC, our offices are vibrant hubs for ideation, professional growth, and interpersonal connection. At the same time, we believe that flexibility allows us in to do our best work and be our best selves. Thus, our teams come into the office four days per week to harness the benefits of in‑person collaboration, but have the flexibility to choose which days they work from home and adjust this arrangement as situational needs arise.

GIC is an equal opportunity employer

As an employer, we passionately believe every individual brings with them unique diversity of thought and perspectives to meaningfully enrich perspectives of GIC teams to drive competitive performance. An inclusive environment yields exceptional contribution.

Learn more about our Technology Group here:

https://gic.careers/group/technology-group/

Our PRIME Values

GIC is a values driven organization. GIC’s PRIME Values act as our compass, enabling us to fulfil our fundamental purpose and objectives. It is the foundational bedrock which governs our behaviors, our decision making, and our focus. It informs both our long‑term strategy as a firm, and the way we relate to our Client, business partners and employees. PRIME stands for Prudence, Respect, Integrity, Merit and Excellence.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

VP/SVP, Risk & Controls Officer (Architecture & Engineering), Technology Group
VP/SVP, Risk & Controls Officer (Architecture & Engineering), Technology Group

GIC • Singapore

Hybrid
SGD 240,000 - 320,000
VP/SVP, Risk & Controls Officer (Applications & Data), Technology Group
VP/SVP, Risk & Controls Officer (Applications & Data), Technology Group

GIC • Singapore

Hybrid
SGD 180,000 - 250,000
VP, Risk & Controls Officer (Risk Governance & Assurance), Technology Group
VP, Risk & Controls Officer (Risk Governance & Assurance), Technology Group

GIC Private Limited • Singapore

On-site
SGD 260,000 - 480,000
Flexible work arrangements
Office four days a week
VP/SVP, Risk & Controls Officer (Architecture & Engineering), Technology Group
VP/SVP, Risk & Controls Officer (Architecture & Engineering), Technology Group

GIC Private Limited • Singapore

On-site
SGD 200,000 - 320,000
VP/SVP, Risk & Controls Officer (Infrastructure), Technology Group
VP/SVP, Risk & Controls Officer (Infrastructure), Technology Group

GIC Private Limited • Singapore

On-site
SGD 180,000 - 260,000
SVP, Information & Technology Risk (Infrastructure, Security & Resilience Risk Oversight)
SVP, Information & Technology Risk (Infrastructure, Security & Resilience Risk Oversight)

GIC • Singapore

Hybrid
SGD 260,000 - 380,000
Senior Vice President, Threat Operations, Technology Group
Senior Vice President, Threat Operations, Technology Group

Gic • Singapore

Hybrid
SGD 300,000 - 460,000
VP, Information & Technology Risk Manager (Data & Applications Risk Oversight)
VP, Information & Technology Risk Manager (Data & Applications Risk Oversight)

GIC Private Limited • Singapore

On-site
SGD 120,000 - 180,000
Flexible work arrangements
Professional growth opportunities
Inclusive working environment
VP, Enterprise Cybersecurity Engineering, (Data Security and Protection Engineer), Technology Group
VP, Enterprise Cybersecurity Engineering, (Data Security and Protection Engineer), Technology Group

GIC • Singapore

On-site
SGD 120,000 - 160,000
Flexible work arrangements
Professional development opportunities
VP/SVP, Identity & Access Management (IAM), Technology Group
VP/SVP, Identity & Access Management (IAM), Technology Group

GIC • Singapore

Hybrid
SGD 300,000 - 420,000