Technology Risk Manager, Boost Digital Bank
Apply on
It’s 2023, technology has undergone an accelerated phase as we lived through unprecedented times. The ‘tech-tonic’ shift has reshaped our day-to-day aspects and we, at Boost, aspire to shake things up further in the financial services scene. In the last 5 years, some of our highlights include: made paying for your roti canai directly from your phone screen, made obtaining your loans completely digital in just 3 minutes, made insurance bite-sized and customizable (think – insurance for phone screens?!)
The Boost-RHB consortium is building towards a Digital Bank, where we strive to make innovative financial services such as these convenient, transparent, and most importantly accessible to anyone and everyone. We want to enable better living for our customers through our inclusive financial services that can universally serve and be embedded in their daily lives.
Join us in creating a roaring future for Malaysia, don’t let this incredible opportunity slip like 2020…too
The Technology Risk Manager in the Boost Bank is responsible to monitor and review technology risk management together with its related control mechanisms. The role is placed as second line role in accordance to 3 line of defense model in risk management which it requires to facilitate risk management, monitor, independently review and challenge risk identification & risk management performed by the first line.
Role
- Review the risk assessments and facilitate the management of technology risk in accordance to Technology Risk Management Framework (TRMF) and Cyber Resilience Framework (CRF) which are aligned to Enterprise Risk Management Framework
- Responsible to independently review and challenge first line in the management of technology risk in accordance to organisation defined technology risk policies, framework, standards and guidelines for Boost Bank in commensurate with the latest law & regulatory requirements, technology threat landscape, enterprise risk exposure and appetite
- Perform independent review the various technology risk assessment performed by first line of defense. The types of risk assessment include, but not limited to, application risk assessment, cloud risk assessment, 3rd-party technology risk assessment, material technology project risk assessment, ad-hoc risk assessment and etc.
- Facilitate the risk identification, assessment (including RCSA), management, and reporting of technology risks in alignment with ERM reporting and processes
- Provide supplementary technology risk assessments tools/template in facilitation of risk management
- Work closely with ERM in performing risk workshop and risk culture awareness
- Advise suitable Key Risk Indicators (KRIs) to effectively monitor key technology & cyber risks
- Provide complementary risk expertise, support, monitoring, and challenge related to the management of risks
- Provide advisory on technology risk assessment, risk mitigation controls and risk treatments
- Provide independent technology risk management opinion, comment and feedback as part of risk assessment outcome together with risk assessment review sign-off as second line independent risk review
- Ensuring risk owner performed risk registration into the enterprise-wide technology risk register for the identified risk
- Monitor the risk status and obtains updates from the risk owner with regards to the registered risks
Requirements
- Bachelor's Degree in Information Technology (IT), Computer Science or other related discipline with relevant experience in managing technology/cyber risk in financial institution
- 5-7 years of full-time work experience in information security management and/or related functions (such as IT audit and IT Risk Management)
- Professional certification such as CISM, CISA, CRISC, CISSP, or equivalent is highly desirable
- Good understanding in regulatory frameworks and compliance requirements associated with financial services and thorough understanding of end-to-end IT operations and how IT interfaces with business, risk management and compliance processes and IT Security
- Excellent interpersonal skills and able to communicate and manage relationship at all levels including senior management, business users, participants, vendors, and team members
- Ability to communicate technology and security risks in business terms to all levels of the organization
- Knowledge of digital banking technologies, cloud and security solutions
- Knowledge of security metrics and technology related key risk indicators