IT Governance, Risk & Compliance (Asst Manager)

  •  Job Reference: 161209
  •  Industry: Real Estate and Property
  •  Consultant Registration Number: R1219552
  •  EA License Number: 02C3423

This role supports the day-to-day management of IT Governance, Cyber Governance, Risk & Compliance, Audit, ISO certification, AI Governance and IT Budget activities across the Group. Working closely with the Senior Manager of IT Governance, the CTO, D&T teams and corporate functions, the role coordinates governance requirements, audits, risk management, financial activities and management reporting, while also supporting AI governance and adoption, IT training programmes, and departmental operations.

Key Responsibilities

Governance, Risk, Audit & Compliance

  • Support the implementation and maintenance of the Group's IT Governance framework, policies and procedures, including maintaining trackers, the governance calendar, and following up on outstanding actions.
  • Coordinate cybersecurity governance activities, reviews and assessments, and support the consideration of security requirements in technology projects.
  • Coordinate internal/external IT audits and annual ISO/IEC 27001 and Cyber Trust Mark certification activities, including evidence collection, ISMS documentation and follow-up on findings.
  • Support the Group's Enterprise Risk Management process for D&T, including maintaining the risk register and following up with risk owners on treatment plans.
  • Assist in reviewing IT proposals and governance papers to ensure required information, risks and approvals are complete.

AI Governance

  • Support implementation and administration of the Group's AI Governance framework, including maintaining the AI Policy and reviewing AI use cases against governance requirements.
  • Coordinate AI risk, security, privacy and compliance assessments, and track related risks, actions and approvals.
  • Support AI awareness and adoption activities, including coordinating training, workshops and Lunch & Learn sessions with the AI Centre of Excellence.

Budget, Procurement & Management Reporting

  • Support annual D&T CAPEX/OPEX budget planning, consolidate inputs, and track expenditure, commitments and cost allocations, liaising with Finance as needed.
  • Support IT procurement and governance documentation, ensuring submissions include appropriate business justification, financials and risk information.
  • Draft and review management papers, memoranda and approval submissions, consolidating multi-stakeholder inputs into clear, accurate updates for the CTO and senior management.

Department Operations & Engagement

  • Coordinate D&T departmental meetings, training programmes and Lunch & Learn sessions, including scheduling, logistics and attendance tracking.
  • Support planning and execution of department events and employee engagement activities, including budget tracking.

Requirements

Education

  • Degree in Information Technology, Computer Science, Information Systems, Business, Risk Management or a related discipline.
  • Professional qualifications in IT Governance, Cybersecurity, Risk or Audit are good to have

Experience

  • Approximately 5–8 years in IT Governance, IT Risk, IT Audit, Cybersecurity Governance, IT Management or a related technology function.
  • Experience coordinating audits, ISO/IEC 27001, Cyber Trust Mark or IT compliance activities.
  • Experience in budget tracking, management reporting and preparing business/approval papers.
  • Experience working across multiple stakeholders and cross-functional teams; supporting senior management or a technology leadership team is advantageous.
  • Experience in AI Governance or Generative AI initiatives is good to have

Skills & Competencies

  • Good IT governance, risk, compliance and coordination skills, with familiarity in ISO/IEC 27001 and audit processes.
  • Good business writing, presentation and stakeholder communication skills.
  • Good financial and budget management skills.
  • Good Microsoft Office skills (Excel, PowerPoint) and familiarity with Teams, Forms and SharePoint.
  • Good organisational and time-management skills; able to manage multiple deadlines and work independently.
  • Able to handle confidential and sensitive information appropriately.