Senior Vice President, Technology Risk Management - Singapore - DBS Bank

    DBS Bank
    DBS Bank Singapore

    1 month ago

    Default job background
    $180,000 - $300,000 per year Banking / Loans
    Description

    Security (Information & Communication Technology)Risk Management Group works closely with our business partners to manage the bank's risk exposure by balancing its objective to maximise returns against an acceptable risk profile.

    We partner with origination teams to provide financing, investments and hedging opportunities to our customers. To manage risk effectively and run a successful business, we invest significantly in our people and infrastructure.
    Technology is key to enabling the DBS vision of being the leading bank in Asia.

    We are constantly challenged by ever changing technology landscape, increasing customer sophistication / demands and introduction of new / updated regulatory requirements.

    We need passionate Technology Risk Managers who play a high impact role as second line function in enhancing the bank's technology risk and cybersecurity posture.

    This includes identifying potential technology and cybersecurity risks associated with existing, evolving and new technology systems and business processes, assessing potential impacts and engaging with other technology leaders on the risk treatment options based on enterprise risk appetite.

    Risks and mitigation plans are reported to senior leadership for review and attention.

    The RoleCross-discipline exposure to open source, virtualization/cloud, automated processes, platform, middleware technologies, storage, database, network, desktops, servers, security, DevOps, etc., are essential for this position.

    The incumbent is a driven, self-starter, who plays an active role working in a dynamic environment with the Technology risk teams to conduct independent assurance of risk management and drive IT risk management initiatives.

    The role is expected to have a proven record of positively influencing stakeholders at all levels of the organisation and is responsible to promote risk culture.

    Additionally, the incumbent needs to have analytical skills to assess information and identify potential risks, possess problem-solving skills to be able to determine how to reduce those risks, and introduce more forward-looking measures of risk.

    The Incumbent should be inquisitive on risks and controls issues and rationalize their mitigation.

    Communication skills are important to inform management about potential risk issues, provide actionable reports, including articulating impact on policy changes.

    There will be frequent opportunities to represent Technology Risk's view in risk forums and different levels of risk committees.

    The demands and high-visibility nature of this position require an expert with a proven ability to work independently in a fast-paced environment and who can begin contributing immediately.

    ResponsibilitiesPartner with first line peers to succinctly assess, frame and report on infrastructure and cybersecurity risks relative to risk appetite.

    Ability to review and challenge infrastructure resiliency design, monitoring thresholds, define and initiate scenarios for stress testing for various disaster recovery scenarios.

    Oversight of remediation of issues arising from first line identification of control deficiencies, internal and external incidents, including deep dive reviews to identify root cause.

    Ability to use analytical thinking and automation (scripting) to identify infrastructure, security gaps, risks, control issues and mitigation strategies.
    Conduct independent assurance to evaluate effectiveness of IT controls.

    Constructively debate issues and connect the dots across various customer journeys and systems, perform scenario analysis, stress testing and challenge of proposed mitigation plans and risk acceptances.

    Work with stakeholders across Group Technology to manage Technology Risks relating to Site Reliability Engineering (SRE), Cyber Security and Emerging Technology, including but not limited to Blockchain, 5G, IoT, AI and Public Cloud.

    Demonstrate strong judgment to balance being both a trusted advisor to the business and driving effective challenge.
    Leverage business and tech/cyber domain expertise to raise the level of challenge activities to a strategic focus.
    Identify opportunities to influence risk-taking strategies and ensure that aggregate risk is understood.
    Encourage Line of Business to balance trade-offs between risk and returns in order to achieve business objectives.

    Analyse trends, anomalies and behaviours and work with technology stakeholders to design and implement technical IT risk measure that are relevant to the Lines of Business.

    Enhance the business' understanding of regulatory/compliance requirements and the implications to individual initiatives and the broader firm.
    Provide robust risk management oversight in supporting various internal, external audits and regulatory inspections/examinations.
    Perform thematic second line assurance reviews, including short and targeted focused reviews for areas of topical and key concern.
    Monitor outstanding risk items and audit issues to ensure proper ownership and follow-up.

    Engage with technology stakeholders to proactively identify risks at a detailed and technical level and ensure that IT is effectively driving remediation activities and to continuously improve IT risk posture.

    Ability to work independently, prepare and write comprehensive reports for senior management on technology risk management activities and risk events for presentation to risk committees.

    Ability to communicate complex technology risk concepts in a clear and concise manner.
    Mentor more junior members of the team.
    Stay current on emerging cyber threats and potential implications to the organisation.
    RequirementsDegree holder in Information Technology, Computer Science or related discipline.
    Minimum 12-15 years of working experience in relevant field....

    Degree holder in Information Technology, Computer Science or related discipline.
    Minimum 12-15 years of working experience in relevant field....

    Company information

    Registration No EReport this job advert

    Don't provide your bank or credit card details when applying for jobs.

    #J-18808-Ljbffr