Epicareer Might not Working Properly
Learn More

Head - Technology Risk & Business Resilience

Salary undisclosed

Apply on


Original
Simplified

Key Responsibilities:

  1. Develop and implement technology risk strategy and plan that aligns with the Company’s overall business objectives and risk appetite
  2. Oversee the implementation of a robust cybersecurity strategy and controls to protect the Company’s digital assets, data and infrastructure from evolving threats.
  3. Establish and maintain a business resilience strategy, including business continuity and crisis management plans to ensure Company can withstand and quickly recover from disruptions.
  4. Provide advice to the Board and influence Management on the effective management of technology risk, cybersecurity and business resilience matters, driving informed decision-making.
  5. Oversee the identification, assessment and mitigation of technology-related risks across the organization, including IT systems and third-party vendors.
  6. Work closely with the IT Department to ensure continuous monitoring, detection and response to security incidents including resilience planning which include Disaster Recovery.
  7. Ensure adherence to relevant regulatory requirements (BNM’s Risk Management in Technology and Business Continuity Management)
  8. Provide assurance to the Board and management over the effectiveness of Technology Risk Management through periodic IT risk assessments and monitoring of security vulnerabilities / parameters.
  9. Promote a strong culture of risk awareness and appreciation to ensure that the Company adopts best practices in cybersecurity, technology risk management and business continuity.
  10. Advice and drive informed risk taking and risk decisions at Management and Board level through Management and Board committees and forums
  11. Drive the effective implementation of the company’s cyber security strategy and framework and its supporting policies, tools and processes for the Company. X People Manager
  12. Collaborate with business to review, advice and support the achievement of objectives stated in the Technology Risk Framework, Business Continuity Management Framework, Outsourcing Risk Management Framework and the Cyber Resilience Framework
  13. Work closely with IT Security team in the alignment of cyber security strategy direction and initiatives

People Management:

  1. Lead, mentor and develop a high-performing risk management team, providing guidance and support to ensure their professional growth and positive contribution to the organization.
  2. Promote a risk-aware culture throughout the organization (leveraging on the Risk and Compliance Representative Model), encouraging employees at all levels to understand, own and manage risks effectively.
  3. Facilitate to ensure training and awareness programs are in place on risk management principles, practices and policies for employees and stakeholders.
  4. Facilitate cross-functional collaboration and communication to ensure a holistic approach to risk management

Qualification & Experience Requirements:

  1. Minimum 10 years of experience in IT Risk Management and Information Security Risk. Solid experience in performing assessments aligned information technology-related standards such as RMIT, NIST, COBIT, ISO2700 and PCI-DSS and having tertiary education in fields of Computer Science, IT, Engineering with Info Sec domain knowledge
  2. Industry certification in IT security and governance (e.g., CISSP, CRISC, CISA, CISM) is preferred.
  3. Professional qualification in Insurance such as CMII, AMII or CII will be an added advantage.
  4. Behavioral competencies: Personal agility, Strategic Orientation, Commercial Orientation, Result Driven, Collaborating & Influencing.
  5. Technical competencies: IT Risk & Control, Risk analysis & Assessment, Business continuity management, Insurance fundamentals, Legal & Compliance