Senior Technology Risk Manager | 6-month Contract | Bank
Job Reference: 160565
Industry: Banking and Finance
brand-id: R1434374
Brand Name: 02C3423
Role Summary
We are seeking an experienced Senior Control Manager, Technology Risk & Governance to strengthen the organization's technology risk management framework and ensure compliance with regulatory requirements, internal controls, and industry best practices. This role is responsible for identifying, assessing, monitoring, and reporting technology risks across the technology landscape while driving governance initiatives that support a robust control environment.
The successful candidate will partner with Technology, Information Security, Risk, Compliance, Audit, and Business stakeholders to enhance technology risk management, regulatory compliance, operational resilience, and third-party risk oversight within a highly regulated financial services environment.
Key Responsibilities
- Lead and conduct technology risk assessments across applications, infrastructure, cloud platforms, third-party services, and technology projects to identify vulnerabilities, control gaps, and emerging risks.
- Evaluate the design and effectiveness of technology controls and recommend risk mitigation strategies to strengthen the overall control environment.
- Maintain and regularly update the Technology Risk Register, ensuring key risks, mitigation plans, control effectiveness, and remediation activities are accurately tracked.
- Monitor and report Technology Risk Metrics and Key Risk Indicators (KRIs) to proactively identify potential issues and support risk-based decision-making.
- Participate in the Software Development Life Cycle (SDLC) and technology project governance processes to ensure security, risk, and compliance requirements are embedded throughout project delivery.
- Partner with Technology, Information Security, Risk, Compliance, and Business teams to develop and implement effective risk treatment and remediation plans.
- Interpret, implement, and monitor compliance with regulatory requirements, including the Monetary Authority of Singapore (MAS) Technology Risk Management (TRM) Guidelines, as well as other applicable regulations and industry standards relating to cybersecurity, data governance, outsourcing, business continuity, and incident management.
- Support regulatory reviews, inspections, and internal or external audits by coordinating documentation, responding to audit queries, and ensuring timely closure of findings.
- Track regulatory observations, audit issues, and remediation activities to ensure compliance obligations are met within agreed timelines.
- Develop, review, and maintain technology risk management policies, standards, procedures, and governance documentation, ensuring alignment with regulatory requirements and organizational risk appetite.
- Promote awareness and adoption of technology risk, cybersecurity, and governance policies through stakeholder engagement, communications, and training initiatives.
- Support technology incident management by performing risk assessments, root cause analysis, impact assessments, and ensuring appropriate corrective and preventive actions are implemented.
- Coordinate regulatory notifications and reporting relating to technology incidents where required.
- Review and support testing of Business Continuity Plans (BCP) and Disaster Recovery (DR) plans to strengthen operational resilience.
- Conduct technology risk assessments of third-party vendors, outsourced service providers, and cloud service providers to ensure compliance with security, regulatory, and contractual requirements.
- Review vendor security controls and contractual obligations to ensure appropriate technology risk management measures are in place throughout the vendor lifecycle.
- Prepare risk dashboards, management reports, committee papers, and executive presentations to communicate technology risk posture, compliance status, emerging risks, and remediation progress to senior management and governance committees.
- Provide subject matter expertise and advisory support to business and technology teams on technology risk, governance, cybersecurity controls, and regulatory compliance matters.
Requirements
- Bachelor's Degree in Information Technology, Computer Science, Information Systems, Cyber Security, Business, or a related discipline. A Master's Degree is advantageous.
- Minimum 10 years of experience in Technology Risk Management, IT Governance, IT Audit, Information Security, Technology Controls, or IT Compliance, preferably within the banking or financial services industry.
- Solid understanding of banking technology environments, enterprise IT infrastructure, cloud technologies, and application architectures.
- Demonstrated experience implementing and managing technology risk frameworks, governance processes, and regulatory compliance programmes.
- Hands-on experience conducting technology risk assessments, control reviews, risk reporting, and remediation management.
- Excellent knowledge of Monetary Authority of Singapore (MAS) Technology Risk Management (TRM) Guidelines.
- Good understanding of regulatory frameworks and industry standards, including Personal Data Protection Act (PDPA), Anti-Money Laundering and Countering the Financing of Terrorism (AML/CFT) requirements, ISO/IEC 27001, NIST Cybersecurity Framework, COBIT, and Information Technology Infrastructure Library (ITIL).
- Good understanding of IT General Controls (ITGCs), application controls, infrastructure security, cloud security, identity and access management, and operational resilience.
- Experience supporting regulatory inspections, internal and external audits, and governance committees.
- Excellent stakeholder management and influencing skills, with experience working across Technology, Risk, Compliance, Audit, and Business functions.
- Professional certifications such as Certified in Risk and Information Systems Control (CRISC), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), or Certified Information Systems Security Professional (CISSP) are good to have.
