Information Risk Management
3 hours ago
The Opportunity
This position will be assisting the Chief Risk Officer in the management of Information and Technology Risk Management for Manulife Insurance Berhad in alignment with the mandates and objectives from Global/Asia Information Risk Management (IRM) and regulatory requirements, as well as ensuring the company is compliant with the standards and guidelines of BNM Risk Management in Information Technology (RMIT) policy document.
Position Responsibilities:
Participate in governance of information risk management as 2nd Line oversight function to support the implementation of internal risk framework, practices, and controls.
Perform the 2nd Line IRM oversight on the Technology RCSA program, issues and the associated corrective action plan, and incidents.
Keep apprised of current and emerging risks which could potentially affect the company's risk profile.
Provide guidance and support on implementation of global technology initiatives.
Provide advisory and guidance on local information, cybersecurity and technology operational activities and regulatory risk to business.
Work closely with Asia IRM to ensure IRM assessment/s is/are aligned with Manulife Global Standards.
Work closely with local IT Governance to ensure holistic incident management, ensuring adequate communication, response and handling in the event of information/security risk incident/s and report to the management and regulator, if required.
Work closely with relevant stakeholders to assess privacy incidents, Data Leak Prevention (DLP) cases etc. and escalate to the management and regulator, if required.
Assume the Chief Information Security Officer (CISO) role and responsible for the technology risk management function of the financial institution and ensuring the company is compliant with BNM Risk Management in Information Technology (RMIT) policy document.
Advise on critical technology projects and ensuring critical issues that may have an impact on the company's risk tolerance are adequately deliberated or escalated in a timely manner.
Provide independent views to the board and senior management on third party assessments per RMIT and deliberate the outcome to the Board.
Conduct 2nd line review of cloud risk assessment of initiatives/projects involving cloud adoption and consider key risks and control measures (specified in RMIT Appendix 10) for BNM review and consultation sessions.
Perform periodic gap analysis of existing practices in managing technology risk against RMIT requirements and highlight key implementation gaps and ensure the company maintains continuous compliance.
Responsible for ensuring the company's information assets and technologies are adequately protected, which includes formulating appropriate policies for the effective implementation of TRMF and CRF, enforcing compliance with these policies, frameworks, and other technology-related regulatory requirements; and advising senior management on technology risk and security matters, including developments in the financial institution's technology security risk profile in relation to its business and operations.
Required Qualifications:
Holds a bachelor's degree in Information Technology (IT) or Information Security (IS)
5 years' experience in IRM / Information Security related roles within the financial industry
Excellent technical skills in Technology Risk Management (TRM) and Information Security Management (ISM)
Excellent communication skills
Appreciation of different cultures
Professional certificate holder – CISSP, CRISC, CISA, CSSLP, or CISM and/or others
Experience in the following will be added advantage -Information Risk Assessment, IT/IS security controls review and Business continuity and disaster recovery
When you join our team:
We'll empower you to learn and grow the career you want.
We'll recognize and support you in a flexible environment where well-being and inclusion are more than just words.
As part of our global team, we'll support you in shaping the future you want to see.
About Manulife and John Hancock
Manulife Financial Corporation is a leading international financial services provider, helping people make their decisions easier and lives better. To learn more about us, visit
Manulife is an Equal Opportunity Employer
At Manulife/John Hancock, we embrace our diversity. We strive to attract, develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals. We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy and pregnancy-related conditions), sexual orientation, genetic characteristics, veteran status, gender identity, gender expression, age, marital status, family status, disability, or any other ground protected by applicable law.
It is our priority to remove barriers to provide equal access to employment. A Human Resources representative will work with applicants who request a reasonable accommodation during the application process. All information shared during the accommodation request process will be stored and used in a manner that is consistent with applicable laws and Manulife/John Hancock policies. To request a reasonable accommodation in the application process, contact
Working Arrangement
Hybrid-
Kuala Lumpur, Kuala Lumpur, Malaysia Ryt Bank Full time 100,000 - 200,000 per yearAre you passionate about safeguarding sensitive data and ensuring regulatory compliance? We are seeking a dynamic Senior Executive, Cybersecurity, to join our Data, Technology & Cyber Risk function in managing the cybersecurity posture across YTL Digital Bank.Job Description:The Senior Executive will assist the Chief Information Security Officer to establish...
-
IT Risk Manager
2 days ago
Kuala Lumpur, Kuala Lumpur, Malaysia Allianz Insurance Full time 125,000 - 250,000 per yearDo you want to work in a high-trust culture where you'll feel empowered to make decisions that result in impact?You're responsible for developing and maintaining robust Information Security and IT risk management program to ensure Information assets and technologies are adequately protected. Key areas include identification, assessment, and mitigating...
-
Risk Manager
2 days ago
Kuala Lumpur, Kuala Lumpur, Malaysia Ploy Full time 180,000 - 250,000 per yearSummary:We are seeking an experiencedSenior Third-Party Risk Managerto lead and manage third-party risk activities across the Technology & Operations (T&O) function. This role requires a strong understanding of enterprise risk, vendor management, governance frameworks, and regulatory expectations. The ideal candidate will establish and embed a pan-risk...
-
Manager, Risk
2 days ago
Kuala Lumpur, Kuala Lumpur, Malaysia CIMB Full time 120,000 - 180,000 per yearKey ResponsibilitiesDrive the implementation of compliance of GTD units with the Operational Risk Framework , Group Technology Risk Management Framework (GTRMF) , Cyber Resilience Framework (CRF), Cloud Risk Management Framework (CRMF) and BNM's Risk Management in Technology (RMiT) which includes providing advisory and guidance to business units to...
-
Manager, Risk Management
2 days ago
Kuala Lumpur, Kuala Lumpur, Malaysia Talent Work Full time 120,000 - 180,000 per yearOur client is a leading solutions provider in the oil and gas industry, the company specializes in delivering high-quality products and services tailored to the exploration and production sector. We are seeking a person skilled and experienced in corporate governance and sustainability to join their dynamic organisation. The successful candidate will be...
-
Kuala Lumpur, Kuala Lumpur, Malaysia Etiqa Insurance and Takaful Full time 60,000 - 120,000 per yearJob DescriptionSupport implementation of MRM policies and procedures to create enhancements on organizational culture and various stakeholders' expectations of Model Risk ManagementSupport development and maintenance of model inventory protocol, model inventory design and model maintenanceCollaborate with relevant stakeholders to drive MRM initiatives.Lead...
-
Information Security Manager – APAC
2 days ago
Kuala Lumpur, Kuala Lumpur, Malaysia Chubb Full time 120,000 - 180,000 per yearPurposeAre you interested in spearheading cybersecurity excellence in a growth and diverse region? Chubb is seeking a seasoned Information Security Manager to lead our information security initiatives across multiple countries in the APAC region. This is a unique opportunity to make a significant impact by shaping the regional security culture and enabling...
-
Head, Information Systems and Technology
2 hours ago
Kuala Lumpur, Kuala Lumpur, Malaysia AHAM Asset Management Berhad Full time 90,000 - 120,000 per yearPosition Objective:The Head of Information Systems and Technology is responsible for leading the strategic planning, implementation, and governance of all technology systems within the firm. This role ensures compliance with the Securities Commission Malaysia's Guidelines on Technology Risk Management (GTRM), supports business operations, and safeguards the...
-
Risk Manager
2 days ago
Kuala Lumpur, Kuala Lumpur, Malaysia Standard Chartered Bank Full time 120,000 - 240,000 per yearRequisition Number: 36854Job Location: Kuala Lumpur, MYSWork Type: Office WorkingEmployment Type: PermanentPosting Start Date: 12/11/2025Posting End Date::Job SummaryThis role could be based in India and Malaysia. When you start the application process you will be presented with a drop down menu showing all countries, Please ensure that you select a country...
-
Risk Manager
3 hours ago
Kuala Lumpur, Kuala Lumpur, Malaysia Standard Chartered Full time 80,000 - 150,000 per yearJob SummaryThis role could be based in India and Malaysia. When you start the application process you will be presented with a drop down menu showing all countries, Please ensure that you select a country where the role is based.We are seeking an accomplished and forward-thinking professional to join our organisation as the Operational Risk Manager for...