Butiran Jawatan
Keperluan Kewarganegaraan: Malaysia
Huraian Kerja / Deskripsi Jawatan
KEY ACCOUNTABILITIES
Technology Risk Management
Support the CCGO and HOR in maintaining and enhancing the Company's Technology Risk Management Framework and Cyber Resilience Framework.
Provide independent second-line oversight and challenge on technology, cyber security and information security risks across the organisation.
Review and challenge technology risk assessments relating to new projects, system implementations, major system changes, cloud adoption, outsourcing arrangements and emerging technologies.
Facilitate technology-related Risk and Control Self-Assessments (RCSA), Key Risk Indicators (KRI) monitoring and issue management activities.
Monitor technology risk exposures, incidents, control weaknesses and remediation actions, escalating material concerns where appropriate.
Assess technology-related operational risk events and ensure root causes, corrective actions and lessons learned are appropriately identified and tracked.
Monitor emerging technology and cyber security threats, assessing their potential impact on the Company's risk profile.
Provide independent review and challenge over technology risk reporting submitted by the First Line.
3.2 Regulatory Compliance and Governance
Monitor compliance with BNM's Risk Management in Technology (RMiT) policy requirements and other applicable technology-related regulatory requirements.
Coordinate and oversee technology risk regulatory assessments, gap analyses and remediation programmes.
Support the maintenance of technology risk policies, standards and governance documents.
Provide risk input into outsourcing, cloud computing and third-party technology risk assessments.
Ensure technology risks are appropriately reflected within the Enterprise Risk Management framework and reporting processes
3.3 Data Protection Officer Responsibilities
Serve as the designated Data Protection Officer (DPO) for the Company.
Oversee the implementation and ongoing effectiveness of the Company's data protection and privacy framework.
Provide advice to business units on personal data protection requirements, privacy risks and data protection impact assessments.
Monitor compliance with applicable personal data protection laws, regulations and internal policies.
Coordinate assessments and investigations of personal data incidents and breaches, including escalation and regulatory notification requirements where applicable.
Maintain oversight of privacy-related risks and remediation activities.
Prepare periodic management and Board reporting on data protection and privacy matters.
3.4 Reporting and Committee Support
Prepare technology risk, cyber risk and data protection reports for Management Committees, Board Committees, Group Office and regulators.
Support the preparation of risk dashboards, risk appetite monitoring and risk reporting.
Escalate material technology, cyber security and data protection issues through the appropriate governance channels.
Provide independent risk insights and recommendations to Management and Board Committees on technology and data protection matters.
3.5 Risk Culture and Advisory
Promote awareness and understanding of technology risk, cyber security and data protection risks across the organisation to promote a strong risk culture.
Provide risk advisory support to business and support functions on technology and data protection matters.
Perform other duties as assigned by the CCGO or HoR.
SECTION 4: GOVERNANCE & CONTROL
Maintain independence from day-to-day technology operations and technology decision-making activities.
Provide objective oversight, challenge and advice on technology, cyber security and data protection risks.
Support continuous enhancement of technology risk governance, cyber resilience and data protection practices across the organisation.
QUALIFICATIONS / EXPERIENCE
Bachelor's Degree in Information Technology, Computer Science, Information Security, Risk Management, Business, Finance or a related discipline.
Minimum 8 years' relevant experience in Technology Risk, Cyber Security, Information Security, IT Audit, Operational Risk, Data Protection or related risk management functions, preferably within the financial services industry.
Strong knowledge of technology risk management, cyber security, data protection and regulatory requirements, including BNM's Risk Management in Technology (RMiT) policy.
Experience engaging with regulators, auditors, senior management and cross-functional stakeholders with strong analytical and communication skills.
Professional certifications such as CRISC, CISA, CISSP, CISM, ISO 27001, CDPO or equivalent would be an advantage.