Hiring.Camp

AVP / Manager, Third-Party Due Diligence Specialist

Ocbc

·

Today

Location
MAL-Menara GE2, Malaysia
Workplace
Onsite
Type
Full-time
Seniority
Manager
Experience
5+ years
Source
Workday

Description

WHO WE ARE:

As Singapore’s longest established bank, we have been dedicated to enabling individuals and businesses to achieve their aspirations since 1932. How? By taking the time to truly understand people. From there, we provide support, services, solutions, and career paths that meet their individual needs and desires.

 Today, we’re on a journey of transformation. Leveraging technology and creativity to become a future-ready learning organisation. But for all that change, our strategic ambition is consistently clear and bold, which is to be Asia’s leading financial services partner for a sustainable future.

 We invite you to build the bank of the future. Innovate the way we deliver financial services. Work in friendly, supportive teams. Build lasting value in your community. Help people grow their assets, business, and investments. Take your learning as far as you can. Or simply enjoy a vibrant, future-ready career.

Your Opportunity Starts Here.

Job Summary

Lead and execute risk-based due diligence for third-party service arrangements, with a focus on technology (including digital and information security risks), cybersecurity, and operational resilience risks. This role involves conducting independent risk assessments, issue management, and providing advisory support to ensure compliance with regulatory requirements, internal policies and international standards. This position requires close collaboration with key internal teams and external service providers.

Key Responsibilities

  • Customise and adapt risk- and context-based questionnaires to ensure assessments align with applicable regulatory requirements and expectations and remain responsive to evolving risk considerations.

  • Conduct comprehensive, risk- and context-based due diligence, including site visits, with a focus on information security, technology architecture, cybersecurity maturity, regulatory compliance, business continuity and physical security risks.

  • Evaluate vendor controls across key domains, including but not limited:

    • Information security and cybersecurity controls (including continuous monitoring of cybersecurity posture).

    • Cloud, infrastructure, and data protection risks

    • IT resilience, BCP/DR, and incident response

  • Identify control gaps and risk exposures, and assess inherent and residual risk, including recommendations for mitigation.

  • Provide subject matter advisory support in managing identified issues by reviewing remediation action tracking and evaluating the timelines and adequacy of controls.

  • Prepare and present risk reports, dashboards, and insights to stakeholders and management.

  • Collaborate with policy owners to ensure alignment with governance and regulatory requirements. Partner with service owners, business units, risk type owners, Procurement, Compliance, Legal, and other assurance functions in the second and third line of defence to identify and appropriately escalate third-party risks.

  • Support Head of ORM in addressing the Central Bank, Internal Audit, and Compliance observations.

Qualifications & Experience

  • Degree in Information Security, Cybersecurity, Information Technology, Risk Management, or related field

  • 5-8 years of experience in TPRM, Technology Risk, Cybersecurity, IT audit, or due diligence.

  • Comprehensive knowledge of BNM RMiT guidelines with practical experience executing mandatory Third-Party Risk Management (TPRM) assessments and vendor due diligence.

  • Strong knowledge of:

    • Cybersecurity frameworks (e.g., ISO 27001 (Information Security Management Systems), NIST CSF (National Institute of Standards and Technology Cybersecurity Framework), BNM RMiT (Bank Negara Malaysia Risk Management in Technology), MAS TRM (Monetary Authority of Singapore Technology Risk Management)

    • Third-party risk management (TPRM), outsourcing regulations, and data privacy laws (PDPA)

    • IT control design, gap analysis, and operating effectiveness assessment

  • Hands-on experience reviewing:

    • Vendor security questionnaires, Outsourced Service Provider Audit Report (OSPAR), System and Organization Controls (SOC) reports, and ISO certifications

    • Vulnerability assessments and penetration testing (VAPT) outputs to determine residual risk

Key Competencies

  • Strong analytical and risk judgement capability

  • Strong capability to analyse complex documentation and interpret audit reports.

  • Ability to independently assess and challenge risk decisions

  • Effective stakeholder management and communication skills

  • Ability to manage multiple assessments in a dynamic environment

  • High attention to detail with strong documentation discipline

Preferred

  • Certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Certified Third Party Risk Professional (CTPRP).

  • Proficient in Microsoft 365 and the Power Platform, with experience building interactive Power BI reports, configuring custom Power Apps, and managing data workflows.

  • Experience with TPRM platforms.

  • Familiarity with outsourcing risk management, cloud governance, data privacy regulations and third-party cybersecurity oversight.

  • Knowledge of Operational Resilience management is a plus.

What we offer:


Competitive base salary. A suite of holistic, flexible benefits to suit every lifestyle. Community initiatives. Industry-leading learning and professional development opportunities. Your wellbeing, growth and aspirations are every bit as cared for as the needs of our customers.

Skills

Power BICybersecurityPenetration TestingSOCRisk ManagementComplianceProcurementISO 27001CISSP

Similar Jobs

30

AVP - Manager

Mufgub · BCIT Bengaluru Office (MGS), India

1 month ago

Onboarding Project Manager, AVP

Morgan Stanley · Sandy, UT,US, US +2

Yesterday

Client Success Manager, AVP

Morgan Stanley · Sandy, UT,US, US

Yesterday

Onboarding Project Manager, AVP

Ms · South Towne Corp Center II, United States of America +2

Yesterday

Client Success Manager, AVP

Ms · South Towne Corp Center II, United States of America

Yesterday

Business Manager (AVP/VP)

Ocbc · BOS-SGP, Singapore · Onsite

Yesterday

Marketing Field Engagement Manager, AVP

Barclays · Working From Home, TEXAS, United States of America

2 days ago

Financial Crime Advisory Manager- AVP

Barclays · Gurugram, DLF Downtown, India

2 days ago

Portfolio Manager - AVP

Associated Bank · Green Bay 200 Adams, United States of America · Remote

5 days ago

Client Manager (AVP), Global Network Banking - Frankfurt

citibank · Frankfurt am Main, HE,DE, DE

1 week ago

Controls Testing Manager, AVP

Rbs · Gurugram, India

1 week ago

Client Manager (AVP), Global Network Banking - Frankfurt

Citi Bank · TAURUS, Germany · Hybrid

1 week ago

Ireland Location Control Manager (AVP)

JPMorgan Chase · Dublin, Ireland, IE

1 week ago

Ireland Location Control Manager (AVP)

JP Morgan Chase · Dublin, Ireland, IE

1 week ago

International Audit - Audit Manager, AVP

Statestreet · London, England, United Kingdom · Remote, Hybrid

1 week ago

Cybersecurity Control Testing & CRI Maturity Assessor - Manager AVP

Mufgub · BCIT Bengaluru Office (MGS), India

1 week ago

Client Success Manager, AVP

Ms · NY - 2000 Westchester Ave, United States of America

1 week ago

Technology Project Manager, AVP

Mufgub · New Jersey Office - 210 Hudson Street, United States of America

1 week ago

Technology Support Team Manager, AVP

nbkc bank · Kansas City, MO

1 week ago

Level 2 Incident Manager, AVP

Db · Pune - Business Bay, India

2 weeks ago

Citi Commercial Bank - CSG Relationship Manager - AVP

Citi Bank · 388 GREENWICH STREET - TOWER, United States of America +3 · Hybrid

2 weeks ago

Alpha Product - Interoperability Manager, AVP

Statestreet · Stamford, United States of America +2

2 weeks ago

AVP/Manager - GPP Payments Business Analyst

Mufgub · BCIT Bengaluru Office (MGS), India

2 weeks ago

Sales & Service Manager, AVP (Woburn Ctr.)

Northern Bank · Woburn, MA

2 weeks ago

Sales & Service Manager, AVP

Northern Bank · Reading, MA

2 weeks ago

Client Service Enablement Project Manager, AVP

Statestreet · Quincy, Massachusetts, United States of America

2 weeks ago

Treasury Markets and Investment - Australia Pool Manager - AVP

Db · Sydney, 126 Phillip Street, Australia

2 weeks ago

Trade Payables Finance Product Manager - AVP

citibank · Jakarta, Jakarta,ID, ID

2 weeks ago

Client Manager (AVP), Global Network Banking - Stockholm

citibank · Stockholm, Stockholm County,SE, SE

2 weeks ago

Senior AI Product Manager, AVP - State Street Investment Management

Statestreet · BOSTON, United States of America

2 weeks ago