Manager, Risk Analysis | Risk Management Department
Position: Manager, Risk Analysis | Risk Management Department
ROLE PURPOSE
Responsible for conducting risk assessment, mainly focusing on Technology and Cybersecurity at Bank’s enterprise level while refining robust and effective risk management framework incorporating policies, methodologies, processes and tools and providing appropriate strategic recommendations where required to strengthen risk management and business continuity culture in the Bank.
PRINCIPAL ACCOUNTABILITIES
GENERAL
a) Risk reporting: Report and provide risk assurance to senior management and Board.
- Conduct continuous environmental scanning to detect, escalate and propose solutions on emerging and current risks for escalation to management.
b) Risk governance, framework and policies: Develop, maintain and ensure effective implementation of risk frameworks and policies.
- Develop and refine the Bank’s risk appetite and tolerance statement (as and when required) and ensure continuous monitoring to detect any breach and escalate to management.
- Liaise and maintain networking with other organizations, and conduct continuous benchmarking or research to keep abreast with the latest risk management practices/standards and regulatory policies.
c) Risk culture and outreach: Promote the development of risk knowledge among staff to build a strong risk management culture.
- Raise awareness on the importance of risk management among Bank staff and develop financial risk management capabilities amongst departmental risk officers (DRO).
d) Risk tools and processes: Develop, maintain, and ensure effective implementation of tools and processes.
e) Risk analysis and advisory: Provide an independent technical and advisory view of related risks, from an enterprise perspective with the objective of adding value to, strengthening, and improving the Bank’s operations through risk mitigation proposals to various risk committees in a timely and effective manner.
f) Provide tactical and strategic leadership to team members through mentoring staff to meet their corporate and personal goals.
CYBERSECURITY AND TECHNOLOGY RISK
a) Research, gather and analyse information about emerging and existing cyber threats to gain insight for developing defensive strategies on potential cyber-attacks.
b) Provide subject matter expertise on cybersecurity and technology risks and incidents.
c) Act as point of reference and provide technical / advisory services to departments to ensure technology and cybersecurity risk management process in the Bank is effective.
d) Independently perform technology and cybersecurity risk assessment and develop risk mitigation proposals to various risk committees in a timely and effective manner.
e) Work with relevant departments to research, develop, implement, and manage cybersecurity policies and frameworks to ensure robustness, effectiveness and compliance with industry standards and regulations.
f) Monitor and coordinate collaborative efforts between departments in transitioning and adapting to new risk tools and protocols.
QUALIFICATIONS
Academic Qualifications:
- Basic Degree in Information Technology, Mathematics, Statistics, Engineering, Business Studies
- Post graduate degree or professional certification in Risk Management (RM) is an added advantage.
- Candidates with CISSP, CISA, CRISC, ISO27001 certifications would possess additional advantage
Experience:
- Preferably minimum four years in the Bank or industry experience i.e. Cyber Security, Risks and Technical Project Management.
GENERIC SKILLS/ATTRIBUTE
- Risk Management
- Project Management
- Communication & Presentation Skill
- Central Bank Core Business Knowledge
- Information & Communication Technology
- Negotiation and problem-solving skills
- Stakeholder management
TECHNICAL SKILLS/ KNOWLEDGE
- Consultancy and Advisory
- Organizational Risk
- Cybersecurity (added advantage)
- Enterprise Risk Management/Business Continuity Management/Information Security Management
Position: Manager, Risk Analysis | Risk Management Department
ROLE PURPOSE
Responsible for conducting risk assessment, mainly focusing on Technology and Cybersecurity at Bank’s enterprise level while refining robust and effective risk management framework incorporating policies, methodologies, processes and tools and providing appropriate strategic recommendations where required to strengthen risk management and business continuity culture in the Bank.
PRINCIPAL ACCOUNTABILITIES
GENERAL
a) Risk reporting: Report and provide risk assurance to senior management and Board.
- Conduct continuous environmental scanning to detect, escalate and propose solutions on emerging and current risks for escalation to management.
b) Risk governance, framework and policies: Develop, maintain and ensure effective implementation of risk frameworks and policies.
- Develop and refine the Bank’s risk appetite and tolerance statement (as and when required) and ensure continuous monitoring to detect any breach and escalate to management.
- Liaise and maintain networking with other organizations, and conduct continuous benchmarking or research to keep abreast with the latest risk management practices/standards and regulatory policies.
c) Risk culture and outreach: Promote the development of risk knowledge among staff to build a strong risk management culture.
- Raise awareness on the importance of risk management among Bank staff and develop financial risk management capabilities amongst departmental risk officers (DRO).
d) Risk tools and processes: Develop, maintain, and ensure effective implementation of tools and processes.
e) Risk analysis and advisory: Provide an independent technical and advisory view of related risks, from an enterprise perspective with the objective of adding value to, strengthening, and improving the Bank’s operations through risk mitigation proposals to various risk committees in a timely and effective manner.
f) Provide tactical and strategic leadership to team members through mentoring staff to meet their corporate and personal goals.
CYBERSECURITY AND TECHNOLOGY RISK
a) Research, gather and analyse information about emerging and existing cyber threats to gain insight for developing defensive strategies on potential cyber-attacks.
b) Provide subject matter expertise on cybersecurity and technology risks and incidents.
c) Act as point of reference and provide technical / advisory services to departments to ensure technology and cybersecurity risk management process in the Bank is effective.
d) Independently perform technology and cybersecurity risk assessment and develop risk mitigation proposals to various risk committees in a timely and effective manner.
e) Work with relevant departments to research, develop, implement, and manage cybersecurity policies and frameworks to ensure robustness, effectiveness and compliance with industry standards and regulations.
f) Monitor and coordinate collaborative efforts between departments in transitioning and adapting to new risk tools and protocols.
QUALIFICATIONS
Academic Qualifications:
- Basic Degree in Information Technology, Mathematics, Statistics, Engineering, Business Studies
- Post graduate degree or professional certification in Risk Management (RM) is an added advantage.
- Candidates with CISSP, CISA, CRISC, ISO27001 certifications would possess additional advantage
Experience:
- Preferably minimum four years in the Bank or industry experience i.e. Cyber Security, Risks and Technical Project Management.
GENERIC SKILLS/ATTRIBUTE
- Risk Management
- Project Management
- Communication & Presentation Skill
- Central Bank Core Business Knowledge
- Information & Communication Technology
- Negotiation and problem-solving skills
- Stakeholder management
TECHNICAL SKILLS/ KNOWLEDGE
- Consultancy and Advisory
- Organizational Risk
- Cybersecurity (added advantage)
- Enterprise Risk Management/Business Continuity Management/Information Security Management