SVP/ VP, Technology Risk Management - Infrastructure, Risk Management Group
DBS Bank
- Singapore
- Permanent
- Full-time
- Partner with first line peers to succinctly assess, frame and report on infrastructure and cybersecurity risks relative to risk appetite.
- Ability to review and challenge infrastructure resiliency design, monitoring thresholds, define and initiate scenarios for stress testing for various disaster recovery scenarios.
- Oversight of remediation of issues arising from first line identification of control deficiencies, internal and external incidents, including deep dive reviews to identify root cause.
- Ability to use analytical thinking and automation (scripting) to identify infrastructure, security gaps, risks, control issues and mitigation strategies.
- Conduct independent assurance to evaluate effectiveness of IT controls.
- Constructively debate issues and connect the dots across various customer journeys and systems, perform scenario analysis, stress testing and challenge of proposed mitigation plans and risk acceptances.
- Work with stakeholders across Group Technology to manage Technology Risks relating to Site Reliability Engineering (SRE), Cyber Security and Emerging Technology, including but not limited to Blockchain, 5G, IoT, AI and Public Cloud.
- Demonstrate strong judgment to balance being both a trusted advisor to the business and driving effective challenge.
- Leverage business and tech/cyber domain expertise to raise the level of challenge activities to a strategic focus.
- Identify opportunities to influence risk-taking strategies and ensure that aggregate risk is understood.
- Encourage Line of Business to balance trade-offs between risk and returns in order to achieve business objectives.
- Analyse trends, anomalies and behaviours and work with technology stakeholders to design and implement technical IT risk measure that are relevant to the Lines of Business.
- Enhance the business’ understanding of regulatory/compliance requirements and the implications to individual initiatives and the broader firm.
- Provide robust risk management oversight in supporting various internal, external audits and regulatory inspections/examinations.
- Perform thematic second line assurance reviews, including short and targeted focused reviews for areas of topical and key concern.
- Monitor outstanding risk items and audit issues to ensure proper ownership and follow-up.
- Engage with technology stakeholders to proactively identify risks at a detailed and technical level and ensure that IT is effectively driving remediation activities and to continuously improve IT risk posture.
- Ability to work independently, prepare and write comprehensive reports for senior management on technology risk management activities and risk events for presentation to risk committees.
- Ability to communicate complex technology risk concepts in a clear and concise manner.
- Mentor more junior members of the team.
- Stay current on emerging cyber threats and potential implications to the organisation.
- Degree holder in Information Technology, Computer Science or related discipline.
- Minimum 12-15 years of working experience in relevant field.
- Professional memberships and security certifications would be considered favourably (e.g., CISA, CISSP, CISM, CCSP, etc.):
- Professional security or risk management certifications.
- Certified Risk & Information Systems Control (CRISC).
- Certified Cloud Security Professional (CCSP).
- Certifications related to SRE such as SRE Practitioner.
- Excellent in leadership skills.
- Moderate to master proficiency in developing & coaching, communication, business focus, planning & organising, teamwork & collaboration, and problem solving.
- Change/innovation oriented, takes ownership of results, and is customer focused.
- Strong proficiency in technical/product expertise and knowledge in relevant fields.
- IT professional with good understanding of technology platform with specialisation in infrastructure domain (e.g. network, storage, database, middleware technologies, microservices, virtualisation, cloud, desktops, servers).
- Experienced with technical security solutions surrounding various technologies such as but not limited to: IDS, IPS, firewall management, anti-virus, content filtering, secure email solutions, network sniffing, log management & analysis, forensics, VPN, load balancing, routing, switching and network management.
- Experienced IS or risk professional with experience and exposure to Agile, DevOps, and SRE.
- Practical experience assessing or building controls for AWS, GCP, Azure or other cloud services.
- Prior experience in either banking, IT risk management, security-related or IT audit.
- Sound knowledge in regulatory requirements (e.g. MAS Notice 644, 655, and TRM guidelines) and industry standards/ frameworks such as ITIL, SANS, COBIT, NIST, ISO 27001/2, Cyber Security Act, Banking Act, Personal Data Protection Act.
- Superb interpersonal and communication skills that include active listening, writing and executive presentation skills.
- Excellent influencing and persuasion skills.
- Proven critical analytical, including and the ability to express a point of view supported by data (with both technical and non-technical audiences).
- Comfort raising concerns early and knows when to escalate, including the ability to raise issues and facilitate constructive problem-solving at all levels of the organization.
- Experience in a second-line or oversight role at a financial institution or regulatory agency (preferred).
- Good planning and other project management skills, including strong organisation skills.
- Must be solutions oriented; ability to work with all levels of management and staff.
- Self-driven, passionate about hands-on learning on emerging technologies and its risks.
- Self-starter, performance-oriented individuals.
- Passionate about driving change through innovation.
- General understanding of overall banking business.
- Support the Head of Unit in discharging the responsibilities of the team.
- Strong ability in knowledge sharing with peers.
- Contribute as a member of Team and collaborate with fellow team members and technology managers.
- Develop relationships with peer in the technology organisation.