We are looking for an experienced Technology Risk / IT Audit professional.
This role will provide independent assurance over technology governance, risk and controls, working closely with Technology, Cybersecurity, Risk and business stakeholders. We are open to candidates coming from either IT Audit or Technology Risk & Controls, provided they have strong experience assessing technology controls and challenging control effectiveness.
Key Responsibilities
- Lead and execute risk-based reviews and IT audits across technology, infrastructure, applications, cybersecurity and IT controls.
- Assess the design and operating effectiveness of technology controls and identify key risk and control gaps.
- Provide practical recommendations to strengthen the organisation's technology risk and control environment.
- Partner with Technology and Risk stakeholders to understand emerging risks, transformation initiatives and changes to the technology landscape.
- Support thematic and integrated reviews covering areas such as Cybersecurity, Cloud, Technology Resilience, Access Management, Change Management, SDLC and Third-Party Technology Risk.
- Assess alignment with relevant regulatory requirements, industry standards and internal technology-risk frameworks.
- Monitor remediation of identified control gaps and provide appropriate challenge to stakeholders.
- Contribute to risk assessments and audit planning by identifying emerging technology and cybersecurity risks.
- Communicate findings and risk themes clearly to senior Technology and business stakeholders.
What We're Looking For
- Approximately 5+ years of experience across Technology Risk, IT Risk & Controls, IT Audit, Technology Assurance, Cyber Risk or related areas.
- Candidates currently working in 1LOD Technology Risk & Controls, 2LOD Technology Risk or 3LOD IT Audit are welcome to apply.
- Strong understanding of technology risks and controls across areas such as Cloud, Cybersecurity, Infrastructure, Applications, IAM, SDLC, Technology Resilience and Third-Party Risk.
- Experience conducting control assessments, risk reviews, audit/assurance activities or independent challenge.
- Financial services experience within banking, insurance, asset management or other regulated environments is preferred.
- Familiarity with technology risk regulatory requirements in Singapore and the wider region, including MAS technology risk requirements, would be advantageous.
- Professional certifications such as CISA, CISM, CRISC, CISSP or CCSP would be beneficial.
- Strong stakeholder-management skills with the ability to challenge constructively and influence senior Technology stakeholders.
- Strong analytical, report-writing and presentation skills.
- Ability to work independently while contributing effectively within a collaborative team.
Pam Lim
Morgan Mckinley Pte Ltd
EA Licence No: 11C5502 | EAP Registration No: R1106192
