- Location
- Kuala Lumpur (City Area), Malaysia
- Workplace
- Hybrid
- Type
- Full-time
- Department
- IT
- Seniority
- Lead
- Experience
- 10+ years
- Education
- Bachelor
- Source
- Workday
Description
About UOB
United Overseas Bank Limited (UOB) is a leading bank in Asia with a global network of more than 500 branches and offices in 19 countries and territories in Asia Pacific, Europe and North America. In Asia, we operate through our head office in Singapore and banking subsidiaries in China, Indonesia, Malaysia and Thailand, as well as branches and offices. Our history spans more than 80 years. Over this time, we have been guided by our values – Honorable, Enterprising, United and Committed. This means we always strive to do what is right, build for the future, work as one team and pursue long-term success. It is how we work, consistently, be it towards the company, our colleagues or our customers.
Job Description
Technology Governance Assurance (TGA) Team Lead
Role Purpose
Lead and oversee Technology Governance Assurance activities to provide independent assurance on the effectiveness of technology risk management, cybersecurity, technology operations, regulatory compliance and governance practices across the Bank. The role is responsible for driving assurance reviews, managing stakeholder engagement, strengthening governance oversight, and supporting senior management and Board reporting on technology-related risks.
Key Responsibilities
Technology Governance & Assurance Review
- Lead the development and execution of the annual Technology Assurance Review Plan, aligned with the Bank's risk profile, regulatory priorities and Group requirements.
- Oversee end-to-end assurance reviews covering technology governance, cybersecurity, infrastructure, resilience, outsourcing, data management, cloud computing, SDLC, project management and emerging technology risks.
- Review and challenge the adequacy and effectiveness of controls to ensure compliance with internal policies, standards and regulatory requirements.
- Provide independent assessment and constructive challenge to identify control gaps, emerging risks, root causes and opportunities for improvement.
- Ensure assurance reviews are completed in accordance with approved methodology, quality standards and timelines.
- Leverage data analytics, automation and continuous monitoring techniques to enhance review coverage and effectiveness.
Regulatory & Technology Risk Governance
- Monitor and assess developments in technology-related regulations, guidelines and industry practices.
- Evaluate the Bank's compliance with regulatory requirements including:
- BNM RMiT
- MAS Guidelines
- PayNet Guidelines
- Cyber Security Act
- Other applicable regulatory and industry standards
- Provide advisory guidance to stakeholders on technology governance and risk management requirements.
- Support regulatory inspections, thematic reviews and supervisory engagements relating to technology risk and cybersecurity matters.
Technology Risk Reporting & Management Oversight
- Oversee the preparation and quality review of technology governance and assurance reports for Senior Management, Risk Committees and Group stakeholders.
- Review technology risk metrics, KRIs, incidents, audit findings and regulatory matters to identify risk themes and emerging concerns.
- Ensure reporting is accurate, insightful and supports effective management decision-making.
- Escalate significant issues and emerging risks to management in a timely manner.
Audit & Regulatory Examination Management
- Act as the primary liaison for technology-related audits, regulatory reviews and assurance engagements.
- Review Requests for Information (RFIs), audit responses and management action plans for completeness and accuracy.
- Provide challenge and oversight during audit observation and reporting stages.
- Track remediation progress and ensure timely closure of audit and regulatory findings.
- Facilitate effective engagement between auditors, regulators and technology stakeholders.
Stakeholder Management & Advisory
- Build strong working relationships with Technology, Information Security, Operational Risk, Technology Risk, Compliance, Internal Audit and Business Units.
- Provide independent advice and guidance on governance, control and regulatory matters.
- Facilitate discussions with senior stakeholders and drive accountability for risk management and remediation activities.
- Support strategic initiatives relating to technology governance, cybersecurity, digital transformation and operational resilience.
People Leadership
- Lead, coach and develop TGA team members.
- Review work performed by team members to ensure consistency, quality and adherence to methodology.
- Provide guidance on assurance techniques, technology risks, regulatory requirements and stakeholder management.
- Drive a culture of professionalism, collaboration, continuous learning and innovation within the team.
- Support resource planning, succession planning and capability development initiatives.
Requirements
Qualifications
Bachelor's Degree in Computer Science, Information Technology, Information Security, Engineering or related disciplines.
Professional certifications preferred:
- CISA
- CISSP
- CISM
- CRISC
- CCSP
- ISO 27001 Lead Auditor
- Other relevant technology risk certifications
Experience
- Minimum 10 to 15 years of experience in:
- Technology Governance
- Technology Assurance
- IT Audit
- Cybersecurity
- Technology Risk Management
- Regulatory Compliance
- At least 5 years in a supervisory or team leadership role.
- Experience in the banking or financial services industry preferred.
- Demonstrated experience engaging regulators, auditors and senior management.
Knowledge & Skills
Strong understanding of:
- Technology Risk Management
- Cybersecurity
- Cloud Computing
- Operational Resilience
- IT Infrastructure
- Systems Development Life Cycle (SDLC)
- Technology Project Governance
- Data Governance and Analytics
- AI and Emerging Technology Risks
- Outsourcing Risk Management
- Familiarity with:
- BNM RMiT
- PayNet Cyber Resilience Guidelines
- ISO 27001
- NIST Cybersecurity Framework
- PCI-DSS
Competencies
- Strong leadership and stakeholder management skills.
- Independent mindset with the ability to provide effective challenge.
- High level of analytical, critical thinking and problem-solving capability.
- Excellent report writing and presentation skills.
- Strong communication skills with the ability to engage stakeholders across all levels, including Senior Management and regulators.
- Ability to manage multiple priorities and deliver results in a fast-paced environment.
Additional Requirements
Be a Part of the UOB Family
UOB is an equal opportunity employer. UOB does not discriminate on the basis of a candidate's age, race, gender, color, religion, sexual orientation, physical or mental disability, or other non-merit factors. All employment decisions at UOB are based on business needs, job requirements and qualifications. If you require any assistance or accommodations to be made for the recruitment process, please inform us when you submit your online application.
Apply now and make a Difference