
Search by job, company or skills
Role Overview
We are seeking an experienced Technology Risk & Regulatory Compliance Lead, to lead and coordinate our organisation's compliance with prevailing global Technology Risk, Cybersecurity and Cyber Hygiene regulations.
This is a global role suited to a professional who can articulate and operate confidently across both global ICT resilience requirements and technology risk supervisory framework in a Financial Services environment, translating regulatory obligations into practical, auditable controls across the organisation's technology, third-party, and operational risk landscape.
The successful candidate will act as the subject-matter authority on ICT/technology risk/cyber hygiene regulations, working closely with Compliance, Legal, Technology and Senior Management to build and maintain a defensible, regulator-ready technology risk and resilience program.
Key Responsibilities
1. Regulatory Compliance & Gap Assessment
. Define and lead on the organisation's compliance programme against DORA (Regulation (EU) 2022/2554), its associated Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS).
. Lead and maintain compliance against the MAS Technology Risk Management Guidelines and the MAS Notice on Cyber Hygiene and related Notices/Guidelines.
. Conduct periodic gap assessments mapping current technology, cybersecurity, and third-party risk controls against DORA's five pillars (ICT risk management, incident reporting, digital operational resilience testing, third-party risk management, information sharing) and MAS TRM domains.
. Track regulatory developments, technical standards updates, and supervisory expectations issued by the ESAs (EBA, ESMA, EIOPA), MAS and translate these into internal policy and control updates.
2. Policy, Framework & Documentation
. Draft, review, and maintain ICT risk management frameworks, technology risk policies, business continuity and disaster recovery (BCP/DR) documentation, and third-party/outsourcing risk policies aligned to DORA and MAS TRM.
. Develop and maintain the ICT Register of Information (RoI) required under DORA, and equivalent third-party/vendor risk registers required under MAS TRM and outsourcing guidelines.
. Prepare quarterly board and monthly management-level reporting MIs, risk registers, and compliance dashboards summarising technology risk posture, control effectiveness, and regulatory readiness.
3. Third-Party & ICT Risk Management
. Own the third-party/ICT service provider risk management lifecycle: due diligence, contractual clause review (including DORA-mandated contractual provisions), ongoing monitoring, concentration risk assessment, and exit strategy planning.
. Assess and classify critical/important ICT third-party providers in line with DORA and MAS outsourcing/TRM criticality criteria.
. Coordinate with procurement, legal, and vendor management teams to ensure new and existing technology contracts meet regulatory requirements.
4. Incident Management, Testing & Resilience
. Support the design and maintenance of ICT-related incident classification, escalation, and regulatory reporting processes consistent with DORA incident reporting timelines and MAS notification requirements.
. Coordinate digital operational resilience testing, including vulnerability assessments, scenario-based testing, and (where applicable) threat-led penetration testing (TLPT), working with Information Security and external testing providers.
. Support tabletop exercises, BCP/DR testing, and crisis simulation exercises to validate organisational resilience against ICT disruption.
5. Governance, Training & Stakeholder Engagement
. Act as the primary liaison with regulators, auditors, and examiners on technology risk and operational resilience matters, including preparation of regulatory submissions and responses to inspection findings.
. Design and deliver training and awareness programmes on DORA and MAS TRM obligations for technology, risk, compliance, and business stakeholders.
. Support committee reporting (Risk & Compliance Committee, ICT Risk Committee) with clear, decision-ready materials on technology risk exposure and remediation status.
. Partner with Technology, Compliance and Legal teams to embed regulatory requirements into day-to-day operational practice.
Key Qualifications & Experience
Education
. Bachelor's degree in Information Technology, Computer Science, Risk Management, Law, Finance, or a related discipline. A relevant postgraduate qualification is an advantage.
Experience
. Minimum 5-8 years of experience in technology risk management, IT audit, cybersecurity governance, or regulatory compliance within financial services, fintech, or payments industry.
. Demonstrated hands-on experience implementing or advising on DORA compliance programmes, including ICT risk frameworks, third-party risk management, and incident reporting obligations.
. Practical working knowledge of MAS Technology Risk Management Guidelines, the Notice on Cyber Hygiene, and MAS outsourcing requirements.
. Prior experience engaging directly with regulators (MAS, MFSA) on technology risk, audits, or examinations is highly preferred.
. Experience working with or advising cross-border financial institutions operating under both EU and Singapore regulatory regimes is a strong advantage.
Knowledge & Technical Skills
. Strong working knowledge of ICT risk management frameworks (e.g., NIST CSF, ISO/IEC 27001, COBIT) and how these map to DORA and MAS TRM control expectations.
. Familiarity with related EU regulatory frameworks (PSD2/PSD3, MiCA, GDPR) and Singapore frameworks (Payment Services Act, MAS Notices) to the extent they intersect with technology and operational risk.
. Understanding of ICT third-party/outsourcing risk management, cloud risk considerations, and vendor concentration risk assessment methodologies.
. Ability to interpret complex regulatory text and translate it into practical, implementable policies, controls, and reporting artefacts.
Certifications
. CISA, CRISC, CISM, CISSP, or equivalent technology risk/audit certification.
. Certificate in DORA compliance, ICT risk management, or operational resilience (e.g., from a recognised industry body) is an advantage.
Job ID: 153349135