Hiring.Camp

Vice President, Information Security and Digital Risk Management

Ocbc

·

Jul 16, 2026

Location
Hong Kong
Workplace
Onsite
Type
Full-time
Department
IT
Seniority
VP
Source
Workday

Description

WHO WE ARE:

As Singapore’s longest established bank, we have been dedicated to enabling individuals and businesses to achieve their aspirations since 1932. How? By taking the time to truly understand people. From there, we provide support, services, solutions, and career paths that meet their individual needs and desires.

 Today, we’re on a journey of transformation. Leveraging technology and creativity to become a future-ready learning organisation. But for all that change, our strategic ambition is consistently clear and bold, which is to be Asia’s leading financial services partner for a sustainable future.

 We invite you to build the bank of the future. Innovate the way we deliver financial services. Work in friendly, supportive teams. Build lasting value in your community. Help people grow their assets, business, and investments. Take your learning as far as you can. Or simply enjoy a vibrant, future-ready career.

Your Opportunity Starts Here.

Job Summary:

This position reports into and supports the Head of Information Security and Digital Risk Management (ISDRM). As part of the second line under the Three Lines Model, ISDRM is responsible for establishing, maintaining and enhancing governance and oversight of the Bank’s technology, information, and cyber risk domains.

What you will be doing:

  • Support the implementation and continuous enhancement of the Bank’s technology, information and cyber risk management framework, in collaboration with relevant stakeholders including Group counterparts, technology teams, business and support units, and other risk management functions.

  • Formulate, review and update risk management framework, policies and guidelines, ensuring alignment with applicable Group standards, supervisory expectations, and industry best practices.

  • Act as secretariat for ISDRM-related risk management committee and working groups, and represent ISDRM at relevant Group and local risk governance meetings and forums as required.

  • Prepare and deliver regular risk reports, analyses and metrics (e.g. KRIs) to the Board and senior management, providing clear insights into the Bank’s overall risk posture.

  • Provide independent advice, support and effective challenge on technology, information and cyber risk domains associated with new products, major technology or Fintech initiatives, strategic digital transformation projects and third-party arrangements (e.g. cloud computing).

  • Lead or participate in thematic reviews and compliance assessments related to emerging risks (e.g. AI-enabled attacks) and regulatory requirements (e.g. facilitation of CRAF Maturity Assessment & iCAST).

  • Monitor and perform independent review of specific aspects of first-line risk management activities, including risk assessment and acceptance, incident response, change management processes, and the implementation of key controls or remediation actions.

  • Collaborate with Group counterparts to plan and deliver risk awareness, training and testing programs to enhance staff awareness and vigilance across the Bank.

  • Drive and oversee the implementation of Bank-wide information risk mitigation initiatives, including enhancements to data loss prevention controls, application remote access controls, and the detection and management of system access misuse.

  • Coordinate and facilitate internal and external audits, regulatory examinations and ongoing regulatory communications relating to technology, information and cyber risk domains.

Who are we looking for:

  • A university degree in Technology, Computer Science, Information Security, Business, Risk Management, or a related discipline.

  • Relevant professional certifications such as CISM, CISSP, CISA under the Enhanced Competency Framework (ECF) on Cybersecurity for a second line of defence role required.

  • A minimum of 7 years of relevant experience in information security, cyber / technology risk management or technology audit, gained within the financial services industry (FSI) or professional services firms serving FSI clients.

  • Strong risk management mindset with a solid understanding of IT environments, evolving threat landscapes, and technology/information/cyber security controls, including relevant industry standards (e.g. ISO/IEC27001) and regulatory guidelines (e.g. HKMA’s SPM TM-G-1, C-RAF).

  • Good communication, presentation and stakeholder management skills, with the ability to engage effectively with both technical and non-technical stakeholders at various levels and articulate complex risk issues clearly and confidently.

  • Proven ability to provide constructive challenge and influence risk-informed decision-making through practical, balanced, and commercially sound recommendations.

  • Demonstrates sound judgement, with the ability to prioritise issues, assess materiality, and escalate risk issues appropriately.

  • Self-motivated, well-organized and able to work independently while contributing effectively in a collaborative team environment.

  • Good command of both spoken and written English and Chinese.

  • Experience in conducting risk assessments, threat modelling or audits will be an advantage.

#LI-SL1

What we offer:


Competitive base salary. A suite of holistic, flexible benefits to suit every lifestyle. Community initiatives. Industry-leading learning and professional development opportunities. Your wellbeing, growth and aspirations are every bit as cared for as the needs of our customers.

Skills

CybersecurityRisk ManagementComplianceLoss PreventionChange ManagementCISSP

Similar Jobs

30

Vice President, Attack Surface Research Analyst, Global Information Security, Sydney, Australia

Ghr · Sydney, Australia · Onsite

Yesterday

VP, Engineering Leader, SPS Information Delivery

Fmr · One Destiny Way, Westlake TX, United States of America

2 days ago

VP Enterprise Data & Information Management

Regeneron · TARRYTOWN, United States of America · Hybrid

2 days ago

VP & Chief Information Security Officer - Global Industrial

Join the team making a genuine difference · USA MOT Alton Rd Campus AL00, United States of America +1 · Hybrid

2 days ago

Vice President, Cyber Threat Intelligence Analyst, Global Information Security, Sydney, Australia

Ghr · Sydney, Australia · Onsite

2 days ago

Vice President, Information Technology

Prime Residential · San Francisco, CA · Onsite

2 days ago

Vice President, Information Technology

Avenzo Therapeutics

3 days ago

VP, Chief Information Security Officer

Bigcommerce · Austin, TX, United States of America · Hybrid

3 days ago

Vice President, Cyber, Technology and Information Security (CTIS) Risk Oversight Lead

Morgan Stanley · New York, NY,US, US

3 days ago

Vice President, Cyber, Technology and Information Security (CTIS) Risk Oversight Lead

Ms · 1633 Broadway- NY, United States of America

3 days ago

VP of Information Technology (Remote)

Davies · Home United States · Remote

4 days ago

Vice President, Information Security

0101022-GIA PROD US LOS ANGELES · Lake Mary, FL, United States, US

4 days ago

Information Security Architect , Vice President

Statestreet · Dublin 2, Ireland +1

5 days ago

Vice President of Information Security & Technology

ECS4KIDS · Jacksonville, FL

1 week ago

Associate Vice President - Information Technology

Ims Group · Toronto, ON

1 week ago

Vice President, Senior Security Detection & Response Manager, Global Information Security, Sydney

Ghr · Sydney, Australia · Onsite

1 week ago

Vice President & Chief Information Security Officer

Planetlabs · Arlington, VA · Remote, Hybrid

1 week ago

Vice President, Information Security and Privacy

Sanmanuel · San Manuel Commons - 674 Brier, United States of America

1 week ago

Vice President, Security Detection & Response, Global Information Security

Ghr · Sydney, Australia · Onsite

1 week ago

Vice President, Security Detection & Response, Global Information Security

Ghr · Sydney, Australia · Onsite

1 week ago

Assistant Vice President, Security Detection & Response, Global Information Security, Sydney

Ghr · Sydney, Australia · Onsite

1 week ago

Vice President of Information Technology & Chief Information Security Officer (VP of IT / CISO)

Multiview Corporation

1 week ago

Vice President, Chief Digital & Information Officer

Otterbein · Lebanon, Ohio +1

2 weeks ago

Vice President, Information Security - Manufacturing Plant Security, Product Security & Application Security

Danaher · USA - Remote, United States of America · Remote

2 weeks ago

Vice President of Information Technology

HiNext · (JRA)MI - Sunnyside Drive, United States of America · Hybrid

2 weeks ago

Senior Data Information management Analyst - Assistant Vice President

citibank · Chennai, TN,IN, IN

2 weeks ago

Senior Data Information management Analyst - Assistant Vice President

Citi Bank · IT BUILDING, RAMANUJAN IT SEZ,, India · Hybrid

2 weeks ago

Vice President, Information Technology

Hogan Assessment Systems Inc · Tulsa, OK

2 weeks ago

Vice President of Information Technology

"Volunteers of America, Inc." · Alexandria, VA

2 weeks ago

Business Information Security Officer-VP

Statestreet · Quincy, Massachusetts, United States of America +3

2 weeks ago
Vice President, Information Security and Digital Risk Management at Ocbc | Hiring.Camp