This role will provide independent assurance over technology governance, risk and controls, working closely with Technology, Cybersecurity, Risk and business stakeholders. We are open to candidates coming from either IT Audit or Technology Risk & Controls, provided they have strong experience assessing technology controls and challenging control effectiveness.
Key Responsibilities
- Lead and execute risk-based reviews and IT audits across technology, infrastructure, applications, cybersecurity and IT controls.
- Assess the design and operating effectiveness of technology controls and identify key risk and control gaps.
- Provide practical recommendations to strengthen the organisation's technology risk and control environment.
- Partner with Technology and Risk stakeholders to understand emerging risks, transformation initiatives and changes to the technology landscape.
- Support thematic and integrated reviews covering areas such as Cybersecurity, Cloud, Technology Resilience, Access Management, Change Management, SDLC and Third-Party Technology Risk.
- Assess alignment with relevant regulatory requirements, industry standards and internal technology-risk frameworks.
- Monitor remediation of identified control gaps and provide appropriate challenge to stakeholders.
- Contribute to risk assessments and audit planning by identifying emerging technology and cybersecurity risks.
- Communicate findings and risk themes clearly to senior Technology and business stakeholders.
- Support ad-hoc reviews, investigations and continuous monitoring of emerging technology risks.
Requirements:
- Approximately 5+ years of experience across Technology Risk, IT Risk & Controls, IT Audit, Technology Assurance, Cyber Risk or related areas.
- Candidates currently working in 1LOD Technology Risk & Controls, 2LOD Technology Risk or 3LOD IT Audit are welcome to apply.
- Strong understanding of technology risks and controls across areas such as Cloud, Cybersecurity, Infrastructure, Applications, IAM, SDLC, Technology Resilience and Third-Party Risk.
- Experience conducting control assessments, risk reviews, audit/assurance activities or independent challenge.
- Financial services experience within banking, insurance, asset management or other regulated environments is preferred.
- Familiarity with technology risk regulatory requirements in Singapore and the wider region, including MAS technology risk requirements, would be advantageous.
- Professional certifications such as CISA, CISM, CRISC, CISSP or CCSP would be beneficial.
- Strong stakeholder-management skills with the ability to challenge constructively and influence senior Technology stakeholders.
- Strong analytical, report-writing and presentation skills.
- Ability to work independently while contributing effectively within a collaborative team.
Candidates with Technology Risk & Controls experience who have exposure to IT audit, control assurance, risk assessments or independent control reviews are encouraged to apply.
Interested candidates may apply by submitting their updated CV
Pam Lim
Morgan Mckinley Pte Ltd
EA Licence No: 11C5502
EAP Registration No: R1106192
