VP/SVP, Risk & Controls Officer (Architecture & Engineering), Technology Group

GIC Private Limited

Singapore

On-site

SGD 200,000 - 320,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

GIC Private Limited seeks a VP/SVP Risk & Controls Officer (Architecture & Engineering) to embed risk and controls into technology strategy, architecture and transformation roadmaps. You will partner with engineering, architecture, and platform teams to ensure risk-informed decisions across DevOps, CI/CD, and SDLC practices.

Leading the risk management function, you will drive ORSA, CCM, and KCIs, while partnering with auditors and stakeholders to ensure resilient, secure platforms across the

Qualifications

  • 12 years (senior) or 7 years (mid‑level) in technology risk, IT controls, operational risk or IT audit in financial services.
  • Experience partnering with strategy, enterprise architecture, or large‑scale transformation programmes.
  • Hands‑on with DevOps, CI/CD, and developer tooling or secure SDLC practices.
  • Familiarity with AI/ML risk, technology risk domains, and risk management frameworks.
  • Knowledge of TOGAF, risk governance, and control frameworks (COSO/COBIT).
  • Ability to balance risk management with delivery priorities; strong stakeholder management and communication skills.

Responsibilities

  • Embed risk and control considerations into technology strategy, enterprise architecture, and transformation roadmaps.
  • Lead design of major transformation and change programmes with secure, controlled by design principles.
  • Embed controls into architecture standards and KCIs; participate in governance forums.

Skills

Leadership
Stakeholder management
Communication skills

Education

Degree in Information Systems / Computer Science / Finance
Certifications (CISA, CRISC, CISSP) advantageous

Tools

DevOps
CI/CD
COSO
COBIT

Job description

Select how often (in days) to receive an alert: Create Alert

VP/SVP, Risk & Controls Officer (Architecture & Engineering), Technology Group

Location: Singapore, SG

Job Function: Technology Group

Job Type: Permanent

GIC is one of the world’s largest sovereign wealth funds. With over 2,000 employees across 11 locations around the world, we invest in more than 40 countries globally across asset classes and businesses. Working at GIC gives you exposure to an extraordinary network of the world’s industry leaders. As a leading global long-term investor, we Work at the Point of Impact for Singapore’s financial future, and the communities we invest in worldwide.

Technology Group
We experiment, design, and lead a 24×7 global business where we support core capabilities in asset management, trading, investment operations, and risk management. We deliver secure, reliable, and integrated solutions, and provide insights on new, and emerging technologies.

Infrastructure & Cybersecurity Resilience (ICR)
We design, build, and secure the technology foundations that power GIC’s global investment operations. We aim to deliver resilient, scalable, and secure infrastructure that empowers our people and businesses to perform securely, efficiently, and effectively.

What impact can you make in this role?

We are seeking a Risk & Controls (R&C) professional to be embedded within the Technology function supporting investment and corporate business units. This role will be part of the R&C function which comprises team members driving R&C Strategy and Standards settings.

Operating within theFirst Line of Defence, this role partners with engineering, architecture, and platform teams to ensure technology risks are effectively managed and controls are embedded across systems and delivery processes. The role focuses on enabling secure, resilient, and well-governed platforms that support investment decision-making and operations.

What will you do as a VP/SVP Risk & Controls Officer (Architecture & Engineering)?

Architecture, Strategy & Transformation

  • Partner with strategy and architecture leadership to embed risk and control considerations into technology strategy, enterprise architecture, and transformation roadmaps
  • Provide risk input into architecture decision-making, technology standards, and the design of major transformation and change programmes
  • Ensure control requirements and 'secure and controlled by design' principles are embedded into architecture standards, reference patterns, and transformation gating, evidenced through architecture governance forums (e.g., design authorities, change gates) and Key Control Indicators (KCIs)
  • Translate strategic and architectural risks into clear business impact and mitigation actions for senior technology and business stakeholders

Developer Tooling & AI Foundations

  • Partner with engineering teams to identify, assess, and manage risks across developer tooling and AI foundation platforms, coordinating with broader infrastructure risk assessments
  • Embed preventative controls and early issue detection (e.g., vulnerability scanning, SAST/DAST) into developer tooling and CI/CD pipelines

Controls Design, Implementation & Monitoring

  • Design and embed controls across the technology lifecycle (SDLC, change management, access controls, data governance) within the domain
  • Ensure controls are integrated into delivery workflows (e.g., DevOps, CI/CD) and validate adherence to governance processes, evidenced by Key Control Indicators (KCIs)
  • Maintain and enhance Operational Risk Self-Assessments (ORSA), progressing toward evidence-based, continuous controls monitoring (CCM)

Operational Resilience & Incident Management

  • Support system resilience, disaster recovery, and service continuity frameworks
  • Contribute to incident and problem management: drive Root Cause Analysis (RCA) and manage Corrective and Preventive Actions (CAPA) to ensure control gaps are permanently fixed
  • Ensure timely closure of control gaps and sustainable remediation

Monitoring & Reporting

  • Develop and track Key Risk Indicators (KRIs) and Key Control Indicators (KCIs) for the domain
  • Produce risk dashboards and insights for senior stakeholders
  • Highlight emerging risks across systems, platforms, and dependencies

Compliance with Standards & Procedures

  • Adhere to, and provide feedback on, the standards and Standard Operating Procedures (SOPs) defined for the first line of defence
  • Support internal compliance checks against defined standards relevant to the domain

Audit & Third-Party Governance

  • Support internal and external audit engagements: collate and review control artefacts, and provide domain input to management responses
  • Support risk assessments and controls for vendors and service providers, ensuring appropriate oversight of outsourced technology services

Stakeholder Engagement

  • Act as a liaison between technology teams (first line), IT risk management (second line), and internal audit (third line)
  • Build strong relationships with engineering and platform teams
  • Promote a risk-aware culture while supporting delivery and innovation

What qualifications or skills should you possess in this role?

  • Minimally 12 years for senior appointments, or minimally 7 years for mid-level appointments, in technology risk, IT controls, operational risk, or IT audit within financial services; senior appointments also include team or workstream leadership
  • Experience partnering with strategy, enterprise architecture, or large-scale transformation and change programmes
  • Hands-on experience with DevOps, CI/CD, and developer tooling or secure SDLC practices
  • Familiarity with programme or portfolio risk management, or AI/ML and emerging-technology risk, is a strong plus
  • Strong understanding of technology risk domains (access management, SDLC, cloud, data governance), with emphasis on vulnerability management, pipeline controls, and preventative shift-left control design
  • Understanding of enterprise architecture frameworks (e.g., TOGAF), technology strategy, transformation delivery risk, and AI/ML risk considerations
  • Knowledge of control frameworks (e.g., COSO, COBIT) and operational risk methodologies (ORSA)
  • Ability to balance risk management with delivery priorities; strong stakeholder management and communication skills
  • Degree in Information Systems, Computer Science, Finance, or a related field; relevant certifications (e.g., CISA, CRISC, CISSP) are advantageous

Work at the Point of Impact
We need to be forward-looking to attract the right people to help us become the Leading Global Long-term Investor. Join our ambitious, agile, and diverse teams - be empowered to push boundaries and pursue innovative ideas, share your views, and be heard. Be anchored on our PRIME Values: Prudence, Respect, Integrity, Merit and Excellence, which guides us in how we make our day-to-day decisions. We strive to inspire. To make an impact.

GIC is a Great Place to Work

At GIC, our offices are vibrant hubs for ideation, professional growth, and interpersonal connection. At the same time, we believe that flexibility allows us to do our best work and be our best selves. Thus, our teams come into the office four days per week to harness the benefits of in-person collaboration, but have the flexibility to choose which days they work from home and adjust this arrangement as situational needs arise.

GIC is an equal opportunity employer
As an employer, we passionately believe every individual brings with them unique diversity of thought and perspectives to meaningfully enrich perspectives of GIC teams to drive competitive performance. An inclusive environment yields exceptional contribution.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

VP/SVP, Risk & Controls Officer (Infrastructure), Technology Group
VP/SVP, Risk & Controls Officer (Infrastructure), Technology Group

GIC Private Limited • Singapore

On-site
SGD 180,000 - 260,000
VP/SVP, Risk & Controls Officer (Architecture & Engineering), Technology Group
VP/SVP, Risk & Controls Officer (Architecture & Engineering), Technology Group

GIC • Singapore

Hybrid
SGD 240,000 - 320,000
VP, Risk & Controls Officer (Risk Governance & Assurance), Technology Group
VP, Risk & Controls Officer (Risk Governance & Assurance), Technology Group

GIC Private Limited • Singapore

On-site
SGD 260,000 - 480,000
Flexible work arrangements
Office four days a week
VP/SVP, Risk & Controls Officer (Infrastructure), Technology Group
VP/SVP, Risk & Controls Officer (Infrastructure), Technology Group

GIC • Singapore

Hybrid
SGD 150,000 - 260,000
VP/SVP, Risk & Controls Officer (Applications & Data), Technology Group
VP/SVP, Risk & Controls Officer (Applications & Data), Technology Group

GIC • Singapore

Hybrid
SGD 180,000 - 250,000
SVP, Information & Technology Risk (Infrastructure, Security & Resilience Risk Oversight)
SVP, Information & Technology Risk (Infrastructure, Security & Resilience Risk Oversight)

GIC Private Limited • Singapore

Hybrid
SGD 180,000 - 300,000
VP, IT Risk & Data Security Oversight
VP, IT Risk & Data Security Oversight

GIC Private Limited • Singapore

Hybrid
SGD 120,000 - 180,000
Flexible work arrangements
Professional growth opportunities
Inclusive working environment
VP, Information & Technology Risk Manager (Data & Applications Risk Oversight)
VP, Information & Technology Risk Manager (Data & Applications Risk Oversight)

GIC Private Limited • Singapore

On-site
SGD 120,000 - 180,000
Flexible work arrangements
Professional growth opportunities
Inclusive working environment
Senior Vice President, Threat Operations, Technology Group
Senior Vice President, Threat Operations, Technology Group

GIC Private Limited • Singapore

On-site
SGD 250,000 - 420,000
SVP, Information & Technology Risk (Infrastructure, Security & Resilience Risk Oversight)
SVP, Information & Technology Risk (Infrastructure, Security & Resilience Risk Oversight)

GIC • Singapore

Hybrid
SGD 260,000 - 380,000