Company Overview
My client is a leading Japanese trust bank with a strong global presence, providing comprehensive financial services including trust banking, asset management, custody, and corporate banking. The bank is committed to maintaining robust governance, risk management, and information security practices to support its operations and meet regulatory expectations across the regions in which it operates.
Role & Responsibilities
Technology Risk, Security & Governance
Provide independent second-line oversight of technology risk and information security matters across the organisation.
Support the design, implementation, and ongoing enhancement of the Technology Risk and Information Security governance framework.
Contribute to the development, review, and periodic refresh of technology risk and information security policies, standards, and guidelines to ensure alignment with regulatory and internal requirements.
Perform policy, procedure, and control reviews to identify gaps against applicable technology risk management and cybersecurity standards.
Regulatory Compliance & Audit Support
Maintain a solid understanding of MAS regulations and other applicable technology and cybersecurity regulatory requirements, as well as relevant industry guidance and internal policies.
Assist in monitoring regulatory developments, supervisory expectations, and industry advisories (e.g. ABS), and assess potential implications to the organisation.
Support the tracking, remediation, and closure of audit findings and regulatory examination issues related to technology risk and cybersecurity.
Risk Assessment, Monitoring & Reporting
Assist with technology risk assessments, including risk identification, control evaluation, and remediation planning.
Maintain and update the Technology Risk Register, ensuring risks, issues, and remediation actions are accurately tracked and reported.
Support the collection, validation, and analysis of Technology Key Risk Indicators (KRIs), and contribute to periodic risk and management reporting.
Review security-related assessments and reports (e.g. vulnerability assessments, audits, control reviews) and provide documented risk observations and recommendations.
Advisory & Stakeholder Engagement
Work collaboratively with IT and business stakeholders to support technology initiatives, system changes, and risk assessments.
Provide security and technology risk advisory input to stakeholders under the guidance of senior team members.
Stay informed on emerging cybersecurity threats, technologies, and mitigation practices, and share relevant insights with the team.
Contribute to continuous improvements in technology risk management processes, tools, and reporting.
Perform other technology risk and cybersecurity-related duties as assigned.
Requirements / Qualifications
Education & Certifications
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field.
Holding or pursuing at least one recognised professional certification such as CISM, CISA, CISSP, CRISC, or equivalent.
Experience & Knowledge
3-5 years of relevant experience in Technology Risk Management, Information Security, IT Risk, or related control, assurance, or governance functions.
Good understanding of the cybersecurity threat landscape, security technologies, and control frameworks, including cloud security principles and practices.
Hands-on experience conducting or supporting technology risk or security assessments, control reviews, and remediation activities.
Practical knowledge of major cloud platforms (e.g. AWS, Azure) and associated security, risk, and governance controls.
Skills & Competencies
Strong analytical and problem-solving skills, with the ability to interpret regulatory and security requirements within business and technology contexts.
Ability to draft, review, and contribute to technology and information security documentation aligned with regulatory and industry standards.
Clear and effective written and verbal communication skills, with the ability to engage both technical and non-technical stakeholders.
Detail-oriented, resilient, and able to exercise sound judgment when identifying, assessing, and escalating technology and cybersecurity risks.
Additional Advantage
Exposure to data governance concepts, including data classification, information asset classification, and system criticality frameworks, will be an added advantage.
Jaspreet Kaur Sran (R22109724)
JAC Recruitment Pte. Ltd. (90C3026)
#LI-JACSG





