Apply Edge Start your job search

VP, Technology & Cyber Risk Management

AmBank Group · Federal Territory of Kuala Lumpur, Malaysia

Apply & track with Apply Edge

PurposeThe VP, Technology Risk Management & Advisory is responsible for providing independent oversight, governance, and advisory support on technology and cyber risks across the Bank. The role ensures that risks arising from the Bank's reliance on IT systems, digital processes, and emerging technologies are effectively identified, assessed, managed, and mitigated in line with regulatory requirements and industry best practices.As part of the Technology Risk function (2nd Line of Defense), the incumbent will collaborate closely with business units, project teams, information security, and technology stakeholders to provide subject matter expertise on technology and cyber risk management. The role includes reviewing and validating technology risk controls, conducting risk assessments, advising on risk mitigation strategies, and ensuring compliance with BNM RMiT, cyber resilience frameworks, Risk and Control Self-Assessments (RCSA), and other regulatory guidelines. The objective is to strengthen the Bank's cyber resilience, support the CISO's cyber risk strategy, and drive continuous improvement in technology control maturity.

Responsibilities

To plan, develop, monitor, organise and communicate effective governance and implementation of the IT risk frameworks, policies, methodology and guidelines to minimise technology and cyber risk losses and potential threats to AmBank Group (including subsidiaries i.e. AmBank, AmBank Islamic and AmInvestment Bank). Cultivate and mature the risk culture within AmBank Group including subsidiaries (i.e. AmBank, AmBank Islamic and AmInvestment Bank), and providing guidance to the first line of defense functions on risk related matters. Supporting and advising Group CISO, senior management and first line of defense stakeholders in terms of technology risk and cyber security risk management and assisting with the Group’s management and board reporting cycle. Oversight over conformance to regulatory requirements such as BNM RMiT Guidelines, SC’s Management of Cyber Risk, PayNet’s Cyber Resilience Guidelines. Providing technology risk advisory support for projects and business functions and recommendations on mitigating technology and cyber risk.Provide support in technology risk assessments for technology related projects and work in alignment with 1st line to ensure technology, data protection and cyber security risk elements are addressed. Lead and support risk assessments across key technology areas. Provide challenge to control owners and suggest areas of improvement.Coordinate remediation efforts for risk and control issues and support issue closure or risk acceptances, as needed. Work with action owners to collect and evaluate appropriateness of evidence.To lead the Cyber Offense (‘Red Team’) and ensuring the red teaming operations (‘Campaign’) should be aligned with the cyber risk strategy, play a key part in making sure the entire campaign as per Red Teaming Procedure, and ensure the red teaming is tested as per cyber adversary behaviour on the ‘Bank’, reflecting the various phases of an adversary’s attack lifecycle.Excellent analytical skills with the ability to identify emerging risks, summarize issues and explain risk trends.To drive validation exercises on conformance to BNM, SC, Paynet, Labuan guidelines and directives (any applicable regulatory bodies) Requirements:Bachelor’s Degree in Information Systems, Information Technology or related field. Minimum 10 years’ experience in a operational/technology risk and governance, audit, compliance or information security function (with accounting firm or Financial Institution) Work experience in relevant areas of technology risk, enterprise risk management, internal controls and banking operations, as well as policy / methodology role. Knowledge of security and risk management frameworks (eg: COBIT, ISF, NIST Risk Management Framework), standards (eg; ISO 27001, NIST Cybersecurity Framework), information security principles, security architecture and regulatory requirements. Experience in managing key financial regulatory bodies and their technology requirements (eg: BNM’s RMiT, SC’s Management of Cyber Risk, PayNet Cyber Resilience Guidelines) Ability to multi-task, prioritize and work with minimum supervision.Pro-active self-starter who demonstrates initiative and works independently with minimum supervision.Strong problem solving, analytical capability and ability to provide insight in a range of situations.Strong collaborative and interpersonal skills as well as an ability to communicate (verbal, written and presentation) across all levels within the organization.Passion and energy combined with a constant desire to challenge the status quo and to drive operational excellence.Ability to clearly articulate technology / cyber security risks and controls to enable stakeholders in making sound risk-based decisions. Professional Certifications eg: CISM, CRISC or ISO 27001 recommended.