Checking job availability...
Original
Simplified
Req ID: 7105
Job Description:
Summary
The Risk Operation Advisor is responsible in conducting independent reviews of technology-related operation risk such as technology-related risk events to ensure comprehensive root cause analysis (RCA), identification of all potential risks and the implementation of effective action plans to mitigate future occurrences. This role requires engagement with various stakeholders to challenge and holistically assess risks. Additionally, the advisor is also required to conduct trend analysis of RLE reported and highlight critical risk areas identified within the group.
Duties and Responsibilities:
- Conduct comprehensive review of the risk event report, challenge the adequacy of RCA performed by BU/SU and effectiveness of action plans to mitigate future occurrence.
- Validate that all potential risks are identified and assessed holistically
- Engage with various stakeholders involved which includes IT, Ops Risk Team, risk owners, system owners and process owners as well as communicating outcomes of the RLE report to senior management and key stakeholders.
- Monitor and keep track of the implementation of action plans to ensure timely execution and escalate delay or ineffective risk mitigation action to senior management.
- Conduct comprehensive trend analysis of reported technology-related risk events to identify patterns, emerging risks and systemic control weaknesses.
- Provide insights and recommendation based on analysis findings.
- Participate in enterprise-wide scenario analysis exercise, independently review and challenge technology-related scenarios prepared by the first line of defence.
- Review and challenge the adequacy of current control in addressing the risk identified from the scenario, identify control / process gaps and review action plans to address the identified weaknesses.
- Ensure mitigation strategies enhance resilience against various risk scenarios.
- Assist in developing, implementing, and managing enterprise-wide awareness programs on Technology Risk.
- Develop and distribute infographics covering key topics on Technology Risk and emerging risks.
- Assist in planning, coordinating and execution of division’s awareness event.
- Facilitate training sessions for employees to enhance awareness, reinforce compliance, and promote a risk-conscious culture.
- Periodically update and revamp awareness materials relevant to technology and emerging risk to ensure relevance and effectiveness.
- Support in the facilitation of periodic Technology Risk Control Self-Assessment (RCSA)
- Support preparation, development and enhancement of periodic technology risk report & dashboard for various audiences and committees (including Board and Senior Management)
- Challenge the adequacy and effectiveness of technology and security controls to ensure alignment with best practices and risk mitigation goals.
Qualification
1.Familiar with Technology and Cybersecurity policies and standards and regulatory requirement in Malaysia (e.g., BNM, PCI-DSS, PayNet and Security Commission guideline.
2.Working experience in Technology Risk Management / IT Governance, IT Compliance / IT Audit would be an added advantage.
3.Analytical and critical thinking skills with the ability to interpret risk trends and patterns.
4.Strong communication and stakeholder management skills to engage with different levels of the stakeholders, including senior management.
5.Ability to independently challenge and validate risk mitigation strategies.
6.Highly sceptical and inquisitive mindset to probe deeper into stakeholder-provided information and uncover hidden risks.
7.Ability to develop training materials and facilitate awareness sessions.
8.Capable of working independently and efficiently with minimal supervision.
- Bachelor’s degree in information technology, Computing, Information Systems, or any related domains.
- 4 or more years of experience in any of these disciplines: Information security, risk management, audit and compliance in technology areas.
- Prior experience in one of the top 4 consulting firms or regulatory environment is preferred.
1.Familiar with Technology and Cybersecurity policies and standards and regulatory requirement in Malaysia (e.g., BNM, PCI-DSS, PayNet and Security Commission guideline.
2.Working experience in Technology Risk Management / IT Governance, IT Compliance / IT Audit would be an added advantage.
3.Analytical and critical thinking skills with the ability to interpret risk trends and patterns.
4.Strong communication and stakeholder management skills to engage with different levels of the stakeholders, including senior management.
5.Ability to independently challenge and validate risk mitigation strategies.
6.Highly sceptical and inquisitive mindset to probe deeper into stakeholder-provided information and uncover hidden risks.
7.Ability to develop training materials and facilitate awareness sessions.
8.Capable of working independently and efficiently with minimal supervision.