

Search by job, company or skills

Job Purpose
The job holder will be part of the Risk Management department in the Second Line of Defense in accordance with the Enterprise-Wide Risk Management framework. Under the guidance of Head of Risk, the job holder has 2 responsibilities as follows:
Technology Risk:
The first role of the job holder is to effectively manage Technology risk in the second line of defense. The Manager shall oversee all Technology related rules, regulations, issuances, and standards and ensure that CIMB Bank Vietnam is compliant. The incumbent shall assess and manage threats/risk, IT & Cyber Security Risk, Technology Resilience, 3rd Party Risk and Assurance, Reporting & Analytics.
The incumbent shall work closely with the related business units (especially the IT and Digital Development team), Group Technology Risk and local regulators where applicable as part of the incumbent's accountability to assist the Head of Risk in managing CIMB Bank Vietnam's Technology risk.
Business Continuity Planning:
The second role is to manage Business Continuity Management and Sustainability under the guidance of the Head of Risk.
Key Responsibilities:
The Key Responsibilities of the Technology Risk Role are as follows:
Common roles and responsibility
IT & Cyber Security Risk
Technology Resilience
Third Party Risk
Assurance, Reporting & Analytics
The Key Responsibilities of the Business Continuity Management are as follows:
Job Specification
Job ID: 152261177
Skills:
Soc, Incident Response, Vulnerability Management, Iso 27001, Iam, Siem, PAM, NIST CSF, Cyber security governance and strategy, CIS Controls, Disaster Recovery, Business continuity, ITGC technology risk and compliance, EDR, Cobit, Third-party technology risk
Skills:
remediation , control design , Cybersecurity, cloud, technology risk management, data, Cisa, Regulatory Requirements, third-party risk, Assurance, Cissp, CRISC, operational resilience

Skills:
Data Governance, Risk management, Third party risk, Regulatory remediation, Operational resilience, Management information governance, Reporting governance
Skills:
Iso27001, Information Security Management, Cism, Risk Analysis for Cyber Threats, GIAC, Cisa, ISO27701, Information Risk Assessment, Information Management and Protection Laws, SANS, Compliance and Regulatory Requirements, Cissp, Information Security Frameworks
Skills:
call center operations, ITIL or similar Incident Problem Management frameworks, support metrics, KPI-driven performance improvement, support quality frameworks, Sla Management