- Location
- EIB | Kuala Lumpur - Menara Prudential 22/F (TRX), Malaysia
- Type
- Full-time
- Seniority
- Manager
- Closing date
- Today
- Source
- Workday
Description
Eastspring is a global asset manager with Asia at its core. We create a culture in which diversity is celebrated and inclusion assured, for our colleagues, customers, and partners. We provide a platform for our people to do their best work and make an impact to the business, and in exchange, we support our people's career ambitions. We pledge to make Eastspring a place where you can Connect, Grow and Succeed.
.
.
KEY RESPONSIBILITIES
- Drive 1st line IT risk management activities in Eastspring regionally through annual RCSA review, user security awareness campaigns, key risk indicator (KRI) metric reporting, IT issue management, IT dispensation and support management in different steering committee or Enterprise risk reporting forums.
- Support Eastspring compliances to APAC regulatory requirement on Technology Risk Management and Cyber Security through various governance activities.
- Management and support for Identity Access Management related projects, operations, risk, and compliance activities.
- Work with Group Information Security team to ensure alignment of local country security controls with Eastspring regional and group policy/standard/guideline.
- Manage all internal/external audits and regulatory inspections for Eastspring Singapore and provide advisory on IT RFIs for Country LBUs.
- Provide support to third party security risk assessment associated with third party vendors and clients.
- Work closely with stakeholders from Eastspring business, IT, 2nd line enterprise/operation risk, and group/external 3rd line auditor to ensure effective security controls in place.
EXPERIENCE / QUALIFICATIONS
- 5-10 years working experiences in information security and/or IT Risk areas, preferably within financial institution, or from consulting firm.
- Proficiency and in-depth knowledge and experience in identity and access management.
- Knowledge and experience in IT risk management and an understanding of regulatory requirements particularly in the following domains: security risk management, change management, data leakage prevention, application security, cloud security, vulnerability management, security monitoring, security incident response and 3rd Party Security Risk.
- A plus to have knowledge on Privacy (PDPA) Ordinance/requirement of APAC countries.
- Can work independently with ownership and able to work with multiple IT stakeholders/leaders, 2nd line (OPS risk) and 3rd line (IT Audit) stakeholders.
- Either one or more of below IT security certificates CISSP, CISA, CISM, CCSP
Eastspring is an equal opportunity employer. We provide equality of opportunity of benefits for all who apply and who perform work for our organisation irrespective of sex, race, age, ethnic origin, educational, social and cultural background, marital status, pregnancy and maternity, religion or belief, disability or part-time / fixed-term work, or any other status protected by applicable law. We encourage the same standards from our recruitment and third-party suppliers taking into account the context of grade, job and location. We also allow for reasonable adjustments to support people with individual physical or mental health requirements.