Job Purpose
The Manager, Technology Governance, Risk & Compliance (Technology GRC) is responsible for supporting and maintaining the Bank's Technology Governance, Risk Management, and Compliance framework. The role ensures that technology-related policies, controls, risks, and compliance obligations are effectively managed in alignment with business objectives, Group requirements, and regulatory expectations.
This position will work closely with all funtion in Digital and Technology, Risk Management, Compliance, Internal Audit, and business stakeholders to strengthen the overall technology control environment and support the Bank's risk and governance activities.
Key Responsibilities
1. Technology Governance
Governance Framework, Policy & Standards Management
- Establish and maintain the local Technology Governance framework in alignment with business strategy, Group requirements, and regulatory expectations.
- Develop, review, maintain, and communicate technology policies, standards, procedures, and governance requirements.
- Conduct periodic reviews and updates of technology policies and standards to ensure compliance with internal and external requirements.
- Monitor and assess adherence to governance requirements across Technology functions.
- Provide governance advisory and guidance to stakeholders regarding policy interpretation and implementation.
Technology Performance Management
- Monitor Technology functions goals, initiatives, and action plans, ensuring alignment with business objectives and strategic priorities.
- Facilitate Technology and Digital Transformation governance committees, including agenda preparation, meeting coordination, and minutes documentation.
- Prepare governance dashboards, management reporting, committee papers, and other governance-related materials.
- Track and report governance actions, decisions, and commitments to ensure timely completion.
2. Technology Risk Management
Risk Identification & Assessment
- Conduct annual Technology Risk and Control Self-Assessments (RCSA) for key technology risks and controls in accordance with Group methodologies.
- Perform ad-hoc risk assessments arising from significant technology changes, projects, incidents, outsourcing arrangements, or emerging threats.
- Support identification, assessment, and evaluation of technology risks across infrastructure, applications, cybersecurity, data, and third-party environments.
Risk Response & Monitoring
- Maintain and update Technology Risk Registers and Technology Risk Landscape documentation.
- Monitor Key Risk Indicators (KRIs), risk appetite metrics, and threshold breaches.
- Prepare periodic risk reports for management, risk forums, and governance committees.
- Analyze and report emerging technology risk trends and recommend appropriate risk treatment actions.
Critical Control Monitoring
- Develop, coordinate, and execute critical technology control monitoring programs.
- Monitor control performance and effectiveness to identify potential control deficiencies.
- Escalate significant control exceptions and support remediation activities.
Control Effectiveness Assessment
- Perform assessments of design and operating effectiveness of technology controls following significant process, system, or operating model changes.
- Identify control gaps and recommend risk mitigation measures.
- Support stakeholders in developing remediation plans and tracking implementation progress.
Third-Party Risk Management
- Conduct technology due diligence and risk assessments for vendors, service providers, outsourcing arrangements, and cloud service providers.
- Review technology control environments and supporting evidence provided by third parties.
- Monitor compliance with the Bank's outsourcing and third-party risk management framework.
- Support risk assessments throughout the vendor lifecycle.
3. Technology Compliance
Regulatory, External & Internal Compliance
- Conduct gap assessments against new or revised regulatory requirements, Group policies, standards, and industry guidelines.
- Evaluate the impact of regulatory changes on Technology functions and support implementation of required actions.
- Maintain compliance tracking and monitoring activities to ensure ongoing adherence to applicable requirements.
Audit & Regulatory Examination Management
- Coordinate internal audits, external audits, independent reviews, and regulatory examinations involving Technology functions.
- Act as a primary liaison between auditors, regulators, and technology stakeholders.
- Facilitate information requests, evidence collection, and audit walkthroughs.
Internal Compliance Monitoring
- Conduct periodic assurance reviews to assess compliance with Technology policies, standards, and control requirements.
- Perform gap analysis and identify areas requiring remediation or improvement.
- Support the continuous enhancement of the Technology compliance monitoring program.
Issue & Action Management
- Manage and track audit findings, independent review findings, regulatory observations, and self-identified issues.
- Conduct ad-hoc look-back reviews, impact assessments, and investigations related to high-risk observations and incidents.
- Monitor remediation plans and ensure timely closure of action items.
- Prepare issue status reports and esscalation materials for senior management and governance committees.
Job Specification
Bachelor's Degree in Information System, Information Technology, Computer Science, Information Security, Risk Management or related discipline
Certification as following is the plus.
- CGEIT (Certified in the Governance of Enterprise IT)
- ISO 38500 Lead Implementer or Lead Auditor
- COBIT Foundation
- ITIL Foundation
- CRISC (Certified in Risk and Information Systems Control)
- CISA (Certified Information Systems Auditor)
- CISSP (Certified Information Systems Security Professional)
- ISO 27001 Lead Implementer or Lead Auditor
- Minimum 7 years of relevant experience in: Technology Governance, IT Risk Management, Technology Compliance, IT Audit, Information Security Governance
- IT Risk Advisory /IT Audit in big 4 professional service firms (PwC, Deloitte, KPMG or E&Y) is a plus
- Experience in similar position in banks/ Financial service company is a plus.
- Experience working with regulators, auditors, and control functions is preferred.
Technical/Functional skills
- Knowledge of common infrastructure, security principles and application development
- Familiar with ISO, ITIL, COBIT, MS Office, and Data Presentation.
- Familiar with regulatory guidelines such as SBV's Circular 09, Cir 35, Cir 20.
- Seasoned understanding of risk management principles and practices
- Extensive experience in IT and banking, with focus on assurance and IT process, risk management.
- Knowledge of information security controls, guidelines and standards, such as ISO 27001.
Personal skills
- Delivers Result
- Builds Relationships
- Exercises Sound Judgment
- Inquisitive approach and Inquisitive approach and attention to detail attention to detail
- Problem-solving skill
- Good command of English.