Hiring.Camp

Vice President, Information Security and Digital Risk Management

Ocbc

·

4 days ago

Location
Hong Kong
Workplace
Onsite
Type
Full-time
Department
IT
Seniority
VP
Source
Workday

Description

WHO WE ARE:

As Singapore’s longest established bank, we have been dedicated to enabling individuals and businesses to achieve their aspirations since 1932. How? By taking the time to truly understand people. From there, we provide support, services, solutions, and career paths that meet their individual needs and desires.

 Today, we’re on a journey of transformation. Leveraging technology and creativity to become a future-ready learning organisation. But for all that change, our strategic ambition is consistently clear and bold, which is to be Asia’s leading financial services partner for a sustainable future.

 We invite you to build the bank of the future. Innovate the way we deliver financial services. Work in friendly, supportive teams. Build lasting value in your community. Help people grow their assets, business, and investments. Take your learning as far as you can. Or simply enjoy a vibrant, future-ready career.

Your Opportunity Starts Here.

Job Summary:

This position reports into and supports the Head of Information Security and Digital Risk Management (ISDRM). As part of the second line under the Three Lines Model, ISDRM is responsible for establishing, maintaining and enhancing governance and oversight of the Bank’s technology, information, and cyber risk domains.

What you will be doing:

  • Support the implementation and continuous enhancement of the Bank’s technology, information and cyber risk management framework, in collaboration with relevant stakeholders including Group counterparts, technology teams, business and support units, and other risk management functions.

  • Formulate, review and update risk management framework, policies and guidelines, ensuring alignment with applicable Group standards, supervisory expectations, and industry best practices.

  • Act as secretariat for ISDRM-related risk management committee and working groups, and represent ISDRM at relevant Group and local risk governance meetings and forums as required.

  • Prepare and deliver regular risk reports, analyses and metrics (e.g. KRIs) to the Board and senior management, providing clear insights into the Bank’s overall risk posture.

  • Provide independent advice, support and effective challenge on technology, information and cyber risk domains associated with new products, major technology or Fintech initiatives, strategic digital transformation projects and third-party arrangements (e.g. cloud computing).

  • Lead or participate in thematic reviews and compliance assessments related to emerging risks (e.g. AI-enabled attacks) and regulatory requirements (e.g. facilitation of CRAF Maturity Assessment & iCAST).

  • Monitor and perform independent review of specific aspects of first-line risk management activities, including risk assessment and acceptance, incident response, change management processes, and the implementation of key controls or remediation actions.

  • Collaborate with Group counterparts to plan and deliver risk awareness, training and testing programs to enhance staff awareness and vigilance across the Bank.

  • Drive and oversee the implementation of Bank-wide information risk mitigation initiatives, including enhancements to data loss prevention controls, application remote access controls, and the detection and management of system access misuse.

  • Coordinate and facilitate internal and external audits, regulatory examinations and ongoing regulatory communications relating to technology, information and cyber risk domains.

Who are we looking for:

  • A university degree in Technology, Computer Science, Information Security, Business, Risk Management, or a related discipline.

  • Relevant professional certifications such as CISM, CISSP, CISA under the Enhanced Competency Framework (ECF) on Cybersecurity for a second line of defence role required.

  • A minimum of 7 years of relevant experience in information security, cyber / technology risk management or technology audit, gained within the financial services industry (FSI) or professional services firms serving FSI clients.

  • Strong risk management mindset with a solid understanding of IT environments, evolving threat landscapes, and technology/information/cyber security controls, including relevant industry standards (e.g. ISO/IEC27001) and regulatory guidelines (e.g. HKMA’s SPM TM-G-1, C-RAF).

  • Good communication, presentation and stakeholder management skills, with the ability to engage effectively with both technical and non-technical stakeholders at various levels and articulate complex risk issues clearly and confidently.

  • Proven ability to provide constructive challenge and influence risk-informed decision-making through practical, balanced, and commercially sound recommendations.

  • Demonstrates sound judgement, with the ability to prioritise issues, assess materiality, and escalate risk issues appropriately.

  • Self-motivated, well-organized and able to work independently while contributing effectively in a collaborative team environment.

  • Good command of both spoken and written English and Chinese.

  • Experience in conducting risk assessments, threat modelling or audits will be an advantage.

#LI-SL1

What we offer:


Competitive base salary. A suite of holistic, flexible benefits to suit every lifestyle. Community initiatives. Industry-leading learning and professional development opportunities. Your wellbeing, growth and aspirations are every bit as cared for as the needs of our customers.

Skills

CybersecurityRisk ManagementComplianceLoss PreventionChange ManagementCISSP

Similar Jobs

30

Assistant Vice President / Vice President, Information Security Threat Management Specialist (Application Monitoring & Response), Global Information Security, Sydney, Australia

Bank Of America · Sydney, Australia · Onsite

5 days ago

Vice President, Information Technology

Global Lending Services · Greenville, South Carolina · Hybrid

1 week ago

Senior Vice President, Information Security

0101022-GIA PROD US LOS ANGELES · MH, India

1 week ago

Vice President, Information Technology

Compass Surgical Partners · Remote · Remote

1 week ago

Vice President, Information Security

Springhealth66 · Remote · Remote

1 week ago

Vice President, Information Technology

Netatwork · Remote (United States) · Remote

2 weeks ago

Vice President, Information Security

0101022-GIA PROD US LOS ANGELES · Nashville, TN, United States, US

2 weeks ago

Assistant Vice President - Information Security.Information Security Group-ISG

Mashreq · Bengaluru, Karnataka, India · Remote

2 weeks ago

Vice President, Information Technology

The Summit Federal Credit Union · Rochester, NY

1 month ago

Vice President, Information Technology, Asia Pacific

PVH as one of the · Hong Kong, Hong Kong SAR

1 month ago

Senior Vice President, Information Technology & Innovation

Indiana University Foundation · Bloomington, IN, United States · Hybrid

1 month ago

Senior Vice President, Information Security

0101022-GIA PROD US LOS ANGELES · Lake Mary, FL, United States, US

1 month ago

Vice President, Information Security

0101022-GIA PROD US LOS ANGELES · Pittsburgh, PA, United States, US

1 month ago

Associate Vice President, Information Technology Services

State of Colorado · Multiple Locations, CO, CO, US

1 month ago

Vice President, Information Security - Cyber Threat Simulation

0101022-GIA PROD US LOS ANGELES · Manchester, Greater Manchester, United Kingdom, GB

1 month ago

Vice President, Information Technology and Chief Information Officer

Marymount University · Main Campus, United States of America

2 months ago

Vice President, Information Security

0101022-GIA PROD US LOS ANGELES · New York, NY, United States, US

2 months ago

Vice President, Information Security

0101022-GIA PROD US LOS ANGELES · Pittsburgh, PA, United States, US

2 months ago

Vice President, Information Security

0101022-GIA PROD US LOS ANGELES · MH, India

2 months ago

Vice President, Information Technology

Riot Platforms · Denver, CO +1 · Remote

2 months ago

Vice President, Information Security

Procare Solutions · Denver, CO +1

2 months ago

Vice President, Information Security

0101022-GIA PROD US LOS ANGELES · Sao Paulo, SP, Brazil

2 months ago

Vice President, Information Technology

SCIC · Melville, SK, Canada · Hybrid

2 months ago

Vice President Information Systems Services

Kaweah Health · USA, CA, Visalia, United States of America

3 months ago

Vice President, Information Technology

Xairatherapeutics · South San Francisco, California, United States

3 months ago

Vice President, Information Security Threat & Insider Risk Management Specialist Sydney, Australia

Bank Of America · Sydney, Australia · Onsite

3 months ago

Vice President, Information Technology

Power & Tel · Piperton, TN

3 months ago

Vice President, Information Security, Central Tech

Chanzuckerberginitiative · Redwood City, CA (Hybrid) +1 · Hybrid

4 months ago

Senior Vice President, Information Technology - Enterprise Data and AI

Smartrent · Phoenix, Arizona · Remote

4 months ago

Assistant Vice President – Information Systems & Technology

Upturn Co · Guaynabo

4 months ago