Search by job, company or skills

Technology Risk & Regulatory Compliance Lead

5-8 Years
SGD 5,000 - 8,000 per month
  • Posted 17 hours ago
  • Be among the first 10 applicants

Job Description

Role Overview

We are seeking an experienced Technology Risk & Regulatory Compliance Lead, to lead and coordinate our organisation's compliance with prevailing global Technology Risk, Cybersecurity and Cyber Hygiene regulations.

This is a global role suited to a professional who can articulate and operate confidently across both global ICT resilience requirements and technology risk supervisory framework in a Financial Services environment, translating regulatory obligations into practical, auditable controls across the organisation's technology, third-party, and operational risk landscape.

The successful candidate will act as the subject-matter authority on ICT/technology risk/cyber hygiene regulations, working closely with Compliance, Legal, Technology and Senior Management to build and maintain a defensible, regulator-ready technology risk and resilience program.

Key Responsibilities

1. Regulatory Compliance & Gap Assessment

. Define and lead on the organisation's compliance programme against DORA (Regulation (EU) 2022/2554), its associated Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS).

. Lead and maintain compliance against the MAS Technology Risk Management Guidelines and the MAS Notice on Cyber Hygiene and related Notices/Guidelines.

. Conduct periodic gap assessments mapping current technology, cybersecurity, and third-party risk controls against DORA's five pillars (ICT risk management, incident reporting, digital operational resilience testing, third-party risk management, information sharing) and MAS TRM domains.

. Track regulatory developments, technical standards updates, and supervisory expectations issued by the ESAs (EBA, ESMA, EIOPA), MAS and translate these into internal policy and control updates.

2. Policy, Framework & Documentation

. Draft, review, and maintain ICT risk management frameworks, technology risk policies, business continuity and disaster recovery (BCP/DR) documentation, and third-party/outsourcing risk policies aligned to DORA and MAS TRM.

. Develop and maintain the ICT Register of Information (RoI) required under DORA, and equivalent third-party/vendor risk registers required under MAS TRM and outsourcing guidelines.

. Prepare quarterly board and monthly management-level reporting MIs, risk registers, and compliance dashboards summarising technology risk posture, control effectiveness, and regulatory readiness.

3. Third-Party & ICT Risk Management

. Own the third-party/ICT service provider risk management lifecycle: due diligence, contractual clause review (including DORA-mandated contractual provisions), ongoing monitoring, concentration risk assessment, and exit strategy planning.

. Assess and classify critical/important ICT third-party providers in line with DORA and MAS outsourcing/TRM criticality criteria.

. Coordinate with procurement, legal, and vendor management teams to ensure new and existing technology contracts meet regulatory requirements.

4. Incident Management, Testing & Resilience

. Support the design and maintenance of ICT-related incident classification, escalation, and regulatory reporting processes consistent with DORA incident reporting timelines and MAS notification requirements.

. Coordinate digital operational resilience testing, including vulnerability assessments, scenario-based testing, and (where applicable) threat-led penetration testing (TLPT), working with Information Security and external testing providers.

. Support tabletop exercises, BCP/DR testing, and crisis simulation exercises to validate organisational resilience against ICT disruption.

5. Governance, Training & Stakeholder Engagement

. Act as the primary liaison with regulators, auditors, and examiners on technology risk and operational resilience matters, including preparation of regulatory submissions and responses to inspection findings.

. Design and deliver training and awareness programmes on DORA and MAS TRM obligations for technology, risk, compliance, and business stakeholders.

. Support committee reporting (Risk & Compliance Committee, ICT Risk Committee) with clear, decision-ready materials on technology risk exposure and remediation status.

. Partner with Technology, Compliance and Legal teams to embed regulatory requirements into day-to-day operational practice.

Key Qualifications & Experience

Education

. Bachelor's degree in Information Technology, Computer Science, Risk Management, Law, Finance, or a related discipline. A relevant postgraduate qualification is an advantage.

Experience

. Minimum 5-8 years of experience in technology risk management, IT audit, cybersecurity governance, or regulatory compliance within financial services, fintech, or payments industry.

. Demonstrated hands-on experience implementing or advising on DORA compliance programmes, including ICT risk frameworks, third-party risk management, and incident reporting obligations.

. Practical working knowledge of MAS Technology Risk Management Guidelines, the Notice on Cyber Hygiene, and MAS outsourcing requirements.

. Prior experience engaging directly with regulators (MAS, MFSA) on technology risk, audits, or examinations is highly preferred.

. Experience working with or advising cross-border financial institutions operating under both EU and Singapore regulatory regimes is a strong advantage.

Knowledge & Technical Skills

. Strong working knowledge of ICT risk management frameworks (e.g., NIST CSF, ISO/IEC 27001, COBIT) and how these map to DORA and MAS TRM control expectations.

. Familiarity with related EU regulatory frameworks (PSD2/PSD3, MiCA, GDPR) and Singapore frameworks (Payment Services Act, MAS Notices) to the extent they intersect with technology and operational risk.

. Understanding of ICT third-party/outsourcing risk management, cloud risk considerations, and vendor concentration risk assessment methodologies.

. Ability to interpret complex regulatory text and translate it into practical, implementable policies, controls, and reporting artefacts.

Certifications

. CISA, CRISC, CISM, CISSP, or equivalent technology risk/audit certification.

. Certificate in DORA compliance, ICT risk management, or operational resilience (e.g., from a recognised industry body) is an advantage.

More Info

Job Type:
Industry:
Employment Type:

Job ID: 153349135

Beware of Scammers

We don’t charge money for job offers