Snr. Mgr. ISRO Asia and Functions

3 weeks ago


Kuala Lumpur, Malaysia Standard Chartered Bank Full time

Role Responsibilities

The Group Chief Information Security Risk Officer (CISRO) organisation is instrumental in protecting and ensuring the resilience of Standard Chartered Bank’s data and IT systems by managing Information and Cyber Security (ICS) risk across the enterprise. As a critical function reporting into the Group Chief Risk Officer (CRO), the Group CISRO team serves as the second line of defence for assuring ICS controls are implemented effectively, in accordance with the ICS Risk Framework, and for instilling a culture of cyber security within the Bank. Group CISRO is responsible for the development of ICS framework, which includes all aspects of end-to-end risk identification, assessment, management and mitigation to stay with approved risk appetite thresholds; ICS policy, assurance and red team activities, cyber resilience and stress testing, third party security risk, industry partnerships, and regulatory engagement. The team of Information Security Risk Officers (ISRO) have delegated authority for risk approval from the Group CISRO and support the implementation of the ICS risk management strategy, providing oversight, governance, and advisory across the Group’s Business, Regions, and Functions. Group CISRO is central to ensuring the Bank is able to meet its ICS commitments to internal and external stakeholders, as well as maintaining an acceptable ICS risk profile that is regularly reported to the Board

Group CISRO is proud to have a diverse workforce with a global presence in over 10 countries. More than a third of our global workforce are women and almost half represent our senior leadership roles. We also have a great ethic and generational balance in our teams and are committed to promote a workplace environment that is consciously inclusive, respects and celebrates the variety of opinions and diverse views, and where every voice is heard and acknowledged. We embrace our differences and know that our diverse and inclusive approach is a strength that drivers our success. We want all applicants to feel able to perform at their best throughout the hiring process and we’ll support you with any reasonable adjustments you need. No matter who you are, where you come from, you are welcome to CISRO.

#breakthebias – Check out the features from the females on our leadership team: and

The Information Security Risk Officer (ISRO), Asia and Functions is a permanent role based in Malaysia that requires strong business acumen and deep knowledge and experience in the ICS and risk management, along with the ability to liaise directly with Stakeholders at the most senior level in the organization and represent the Bank directly with the lead Regulators in the country. The role will act in the capacity of Risk Framework Owner for Malaysia, Brunei, Indonesia, Philippines, Australia and designated Group Functions to provide oversight and challenge of ICS risk management and control effectiveness and as a risk partner to Senior leadership as defined in the Bank’s ICS Risk Type Framework.

The role has the responsibility to be value-added risk partners by:

Providing risk stewardship and ensure efficient and effective management of ICS risk, aligning to risk appetite and strategic goals Displaying a core working knowledge of Information and Cyber Security topics to include the ICS Threat landscape, NIST & Cyber Kill Chain, Cyber Value at Risk, and Emerging technology. Partnering with stakeholders to provide guidance, expertise and oversight of the ICS risk which include communicating through complex topics and challenging constructively. Providing strategic thinking and thought leadership by connecting the dots between Country and Group and providing opinions in key focus areas Becoming threat-led focused and prioritizing high value activities and providing pragmatic and proportionate risk guidance

Responsibilities

Strategy

The successful candidate will have an excellent and demonstrable understanding of operating in a second line capacity within an ICS Risk management organisation and be able to respond flexibly and collaboratively to evolving business, regulatory and threat requirements. The role will focus on strategic thinking and connecting the dots, providing a threat led view which include prioritizing high value activities and embodying pragmatic and proportionate risk guidance. This role reports directly to the Head, ISRO Functions and Asia. The ISRO of Asia and Functions will work closely with the Group CISRO, CISO, CRO, Business Heads, and directly with the lead Regulator to address ICS as a principal risk type for the Bank and support its integration into the Bank's overall Enterprise Risk Management strategy.

Business

The primary purpose of this position is to ensure that the management of ICS risk is operating effectively and efficiently and to provide oversight that ICS risk is appropriately managed within Malaysia, Brunei, Indonesia, Philippines, Australia and designated Group Functions. The role will support the Group CISRO in their role as the Bank's executive accountable for ICS risk, along with CROs. The successful candidate will work with the Chief Information Security Processes

The major functional activities that the role will lead and manage are:

Delegation of Authority from the Group CISRO for second line ICS risk management engagement in Malaysia, Brunei, Indonesia, Philippines, Australia and designated Group Functions. Taking full Delegation of Authority (DoA) responsibilities for Group CISRO, provide risk stewardship and ensure efficient and effective management of ICS risk, aligned strategic goal and priorities Oversee and challenge 1st line ICS risk assessment and risk-taking activities. Advise on acceptable risk tolerances based on policy and control environment and the evolving regulatory and threat landscape. Monitoring of ICS risks and associated remediation plans using the CISRO Governance Risk Type Framework. Assuring the 1st lines implement appropriate controls to address risks and to comply with applicable laws and regulations and policies defined by the CISRO Policy team and escalate significant regulatory non-compliance matters and developments to CROs and Group CISRO.

People & Talent

Strong analytical skills and ability to priorities, make decisions, and work to tight timeframes. Ability to articulate residual risk with specific ability to communicate complex technology and process risk clearly to non-technical stakeholders. Strong communication skills – oral, written and presentation. Proven ability to lead highly complex activities through influence and credibility rather than command and control. Strong interpersonal and stakeholder management and influencing skills, across various levels in the organization including senior leadership teams, Must be a self-starter who is able to initiate and successfully drive programs and projects to completion with little or no management supervision. Strong integrity, independent and resilience. Sound knowledge of MS-Excel, PPT, and Word. Lead through example and help to create appropriate culture and values Work in collaboration with risk and control partner and act as their trusted advisor. Uphold and reinforce independence of second line ICS Risk function.

Risk Management

Deliver the defined aspects of the ISRO role to support the Group's ICS risk management approach and objectives. Ensure that the ISRO role is managed in accordance with the defined CISRO Governance Risk Type Framework and associated Policy and Standards in line with country governance framework and practices; and issues are identified, escalated, and addressed as appropriate. Closely track deliverables and commitments, raising concerns at the appropriate Governance forums Support the business in their identification of ICS Risk and provide risk stewardship to advise on appropriate Risk Management activities. Fulfill all responsibilities as the ICS second line Risk Framework Owner for Brunei, Indonesia, Philippines, Australia and designated Group Functions.

Governance

Establish strong ties into the relevant leadership, governance, risk and control committees to ensure adequate monitoring and governance of ICS risk. Attend the Risk Committees and Forum as a Permanent Invitee (or Member) as required, to ensure the responsibilities of the risk committees are appropriate fulfilled. the Governance forums to challenge constructively and effectively the first line in their responsibilities of ICS Risk Management. •Drive integration of ICS Risk Type Framework into respective countries.

Regulatory & Business Conduct

Display exemplary conduct and live by the . Take personal responsibility for embedding the highest standards of ethics, including regulatory and business conduct, across Standard Chartered Bank. This includes understanding and ensuring compliance with, in letter and spirit, all applicable laws, regulations, guidelines and the Group Code of Conduct. Lead the Asia and designated function, CISRO team to achieve the outcomes set out in the Bank’s Conduct Principles: [Fair Outcomes for Clients; Effective Financial Markets; Financial Crime Compliance; The Right Environment.] * Effectively and collaboratively identify, escalate, mitigate and resolve risk, conduct and compliance matters.

Key stakeholders

CEO CRO CIO / CTO CISRO CISO Compliance Officer Business Heads Group Internal Audit Banking Regulators

Qualifications

Training, licenses, memberships and certifications

Proven experience as an information security risk officer, governance, policy, risk management, or audit role, preferably in the IT security field. Strong knowledge of security frameworks (COBIT, ISF, COSO), standards (ISO, NIST, CIS), Cyber Attack Surface, Cyber Kill Chain, and information security principles and security architecture. Strong technical knowledge on risks associated with Cloud and emerging technologies. Keen understanding of IT security business process risks, threats, and internal controls in the Banking and Financial services sector. Strong leadership, negotiation and collaboration skills, and ability to work effectively in a complex multicultural and multi-time zone organization. Ability to liaise with all parts of the Bank, including senior security, risk, and business stakeholders. Excellent written, oral communication and reporting skills. Ability to collect and analyse data, establish facts, and make recommendations in written and oral form. Good knowledge of Information Cyber Security controls, including identity and access management, network security, information protection, secure logging and monitoring, security incident management, security awareness, secure configuration, system lifecycle security, and third security party management. Bachelor’s Degree in Engineering, Computer Science, Information Technology, Cybersecurity, Business Management, or other related discipline

Our Ideal Candidate 

Cyber Risk Management Analytical Thinking IT Standards, Procedures & Policies Oral communications Written Communications Emerging Technologies
  • Sales Snr Director

    4 weeks ago


    Kuala Lumpur, Malaysia Oracle Full time

    Sales Snr Director - Oracle Applications-230005EX **Applicants are required to read, write, and speak the following languages***: English **Detailed Description and Job Requirements** Overall responsibility for the regions sales, third party alliances, and customer satisfaction. Develops and implements a comprehensive strategy that maximizes Oracle's...

  • Ap Trading Center

    4 weeks ago


    Kuala Lumpur, Malaysia BASF Asia-Pacific Service Centre Sdn. Bhd. Full time

    **Do you want to work with passionate teams, providing excellent business and digital services to the Asia Pacific region?** **Do you want an open, supportive, and caring working environment?** **Do you view your development needs seriously as we do?** **If YES, then take your career to the #NextLevel with BASF !** **Objectives of the Position** The...

  • Asia EHS Leader

    5 days ago


    Kuala Lumpur, Malaysia Power Portfolio Power Conversion Full time

    **Job Description Summary**: We are a leading multinational organization forcussing on electrification and decarbonization with a diverse portfolio that spans marine, industry, power generation, oil & gas and renewables. Our commitment to excellence is reflected in our products, our people, and our practices. We prioritize the health, safety, and well-being...


  • Kuala Lumpur, Malaysia Marriott International, Inc Full time

    **Additional Information** 1 year contract **Job Number** 23204191 **Job Category** Sales & Marketing **Location** Kuala Lumpur Office, Jalan Sultan Ismail, Kuala Lumpur, Wilayah Persekutuan, Malaysia VIEW ON MAP **Schedule** Full-Time **Located Remotely?** N **Relocation?** N **Position Type** Management **JOB SUMMARY** The **Manager of Strategy...


  • Kuala Lumpur, Malaysia Lesaffre Full time

    Company Description Lesaffre is a French multinational which has more than 160 years of history, and is a global key player in yeasts and fermentation. The Company designs, manufactures and markets innovative solutions for Baking, Food taste & pleasure, Health Care and Biotechnology. Its Business Unit Biospringer benefits from the expertise of its parent...

  • Compliance Analyst

    2 weeks ago


    Kuala Lumpur, Malaysia United Overseas Bank (Malaysia) Bhd Full time

    **About UOB**: United Overseas Bank Limited (UOB) is a leading bank in Asia with a global network of more than 500 branches and offices in 19 countries and territories in Asia Pacific, Europe and North America. In Asia, we operate through our head office in Singapore and banking subsidiaries in China, Indonesia, Malaysia and Thailand, as well as branches and...


  • Kuala Lumpur, Malaysia LESAFFRE GROUP Full time

    Domaine d'activité- IT- Catégorie- Baking- Localisation- Kuala Lumpur, Malaysia- Type de contrat- Permanent Contract- Experience- 5 to 10 yearsDescription de l'offre - Functional coordinator of the IT head of all sub regions of Asia Pacific. - Ensure the group IT policies and procedures are correctly followed, especially on security. - Ensure the Group IT...

  • Customer Service

    6 days ago


    Kuala Lumpur, Malaysia MyGlit Full time

    **Role**:CRM/Cust. Service Mgr **Timings**:Shifting Schedule (Permanent) **Industry**:Telecom / ISP **Process**:Voice **Functional Area**:Banking / Insurance Key Skills: Customer Service Mandarin Cantonese english Click on the link above to read the job description and requirements


  • Kuala Lumpur, Malaysia RHB Banking Group Full time

    Working Hour - Regular Hours - Monday - Friday- Business Area - Asset Management- Location - Malaysia - Kuala Lumpur- Description **Primary Objective**: Manage the organization structure, strategy, budget, performance and personal for Partnership Business, for conventional and Islamic offering across Asset Management, to achieve the performance...

  • Mgr QA Capacity

    4 weeks ago


    Kuala Lumpur, Malaysia United Overseas Bank (Malaysia) Bhd Full time

    **About UOB**: United Overseas Bank Limited (UOB) is a leading bank in Asia with a global network of more than 500 branches and offices in 19 countries and territories in Asia Pacific, Europe and North America. In Asia, we operate through our head office in Singapore and banking subsidiaries in China, Indonesia, Malaysia and Thailand, as well as branches and...


  • Kuala Lumpur, Malaysia United Overseas Bank (Malaysia) Bhd Full time

    **About UOB**: United Overseas Bank Limited (UOB) is a leading bank in Asia with a global network of more than 500 branches and offices in 19 countries and territories in Asia Pacific, Europe and North America. In Asia, we operate through our head office in Singapore and banking subsidiaries in China, Indonesia, Malaysia and Thailand, as well as branches and...


  • Kuala Lumpur, Malaysia United Overseas Bank (Malaysia) Bhd Full time

    **About UOB**: United Overseas Bank Limited (UOB) is a leading bank in Asia with a global network of more than 500 branches and offices in 19 countries and territories in Asia Pacific, Europe and North America. In Asia, we operate through our head office in Singapore and banking subsidiaries in China, Indonesia, Malaysia and Thailand, as well as branches and...


  • Kuala Lumpur, Malaysia Standard Chartered Full time

    **Job**: Technology **Primary Location**: Asia-Malaysia-Bukit Jalil KL **Schedule**: Full-time **Employee Status**: Permanent **Posting Date**: 14/May/2024, 2:50:58 AM **Unposting Date**: Ongoing **JOB SUMMARY** - The role will be responsible for handling the Solution Architecture and Design for the ATM Switch, Debit Cards and Payment domain. The job...


  • Kuala Lumpur, Malaysia Dynisco-Viatran (M) Sdn Bhd Full time

    **Position Overview**: The Regional Sales Manager is responsible for the day-to-day sales management efforts for the assigned group of countries in the Asia Pacific Selling Region. They are responsible for the management of the sales distribution network within assigned territory to foster the achievement of business growth and revenue goals for its line of...


  • Kuala Lumpur, Malaysia Operation Underground Railroad Full time

    **About Us**: OUR Rescue is an international non-profit organization dedicated to combatting child sexual exploitation and human trafficking. With operations in five regional offices around the world, we strive to create a world where everyone can live in safety and dignity. Our team is composed of passionate, innovative, and dedicated individuals who...


  • Kuala Lumpur, Malaysia United Overseas Bank (Malaysia) Bhd Full time

    **About UOB**: United Overseas Bank Limited (UOB) is a leading bank in Asia with a global network of more than 500 branches and offices in 19 countries and territories in Asia Pacific, Europe and North America. In Asia, we operate through our head office in Singapore and banking subsidiaries in China, Indonesia, Malaysia and Thailand, as well as branches and...


  • Kuala Lumpur, Malaysia Page Executive Full time

    About Our Client Our client is an FMCG powerhouse, responsible for crafting some of the most well-known food brands globally. They boast a people-centric culture that centres on innovation and wellbeing, creating an atmosphere that pushes to the future while still caring for its people. Job Description As the Regional Supply Chain Director, you play an...


  • Kuala Lumpur, Malaysia ELITE ASIA (SG) PTE. LTD. Full time

    **Company Introduction** Since its establishment in 2006, Elite Asia has evolved into a regional powerhouse that helps businesses navigate effortlessly across East Asia and Southeast Asia. Headquartered in Singapore with offices in Malaysia, Hong Kong, and Japan, we serve multinational companies and regional firms through our innovative language services...

  • Project Lead

    4 weeks ago


    Kuala Lumpur, Malaysia ELITE ASIA (SG) PTE. LTD. Full time

    **Company Introduction** Since its establishment in 2006, Elite Asia has evolved into a regional powerhouse that helps businesses navigate effortlessly across East Asia and Southeast Asia. Headquartered in Singapore with offices in Malaysia, Hong Kong, and Japan, we serve multinational companies and regional firms through our innovative language services...


  • Kuala Lumpur, Malaysia BASF Asia-Pacific Service Centre Sdn. Bhd. Full time

    **_Do you want to work with passionate teams, providing excellent business and digital services to the Asia Pacific region? _** **_Do you want an open, supportive, and caring working environment?_** **_ Do you view your development needs seriously as we do?_** **_ If YES, then take your career to the #NextLevel with BASF !_** **Objectives of the...