Vice President, Technology Business Advisory
2 days ago
Job Purpose:
- Supports the Director of Technology and Cyber Security Management in managing IT and Cyber Risks that may impact the organization's profitability, operational resilience, and reputation.
- The role is responsible for identifying, assessing, and evaluating technology-related threats, and recommending appropriate measures to mitigate, avoid, reduce, or transfer those risks.
- Key responsibilities include supporting IT security advisory efforts, facilitating internal assessments and audit engagements, and aligning with recognized risk and control frameworks. The role also serves as the single point of contact for technology risk matters across CIMB offices in the respective country, ensuring consistent risk oversight and alignment with group-level risk management practices.
Key Responsibilities:
- Ensure the Board of Directors and Senior Management have clear and adequate oversight of the organization's cyber risk posture, supporting the protection of employees, customers, reputation, assets, and stakeholder interests (including shareholders and regulators).
- Drive consistency and compliance in IT Risk Management policies, methodologies, and processes across the organization.
- Oversee the effective and timely execution of IT project risk assessments to ensure technology initiatives are aligned with risk tolerance and regulatory expectations.
- Manage the implementation and management of Operational Risk and Control Self-Assessment (RCSA), Loss Event (LED), Risk Hotspot, Idiosyncratic storyboard telling, Risk Posture Scorecard within the CISO function to strengthen internal control awareness and accountability.
- Provide independent risk assessments for system developments, tool/platform onboarding, and production readiness to identify and address potential cyber and technology risks.
- Conduct comprehensive cyber risk assessments aligned with regulatory and internal standards.
- Communicate effectively, both verbally and in writing, with technical and non-technical stakeholders, and deliver high-quality documentation and presentations.
Job Specification:
- The scope of this role encompasses information, security, and technology risk management, covering areas such as enterprise risk, regulatory and operational risk, corporate governance, and acting as a supporting function for business continuity.This will be achieved through the following responsibilities:
- Assess and evaluate information technology risks across business operations, and implement appropriate action plans, policy enhancements, and procedural changes for risk avoidance and mitigation.
- Support business owners in identifying, assessing, documenting, managing, and monitoring IT risks, controls, and mitigation actions, in alignment with the company's risk management framework.
- Ensure periodic review of risk limitations and control strategies to accurately reflect the evolving IT risk profile, leveraging appropriate strategies aligned with the organization's risk appetite.
- Evaluate alignment between the IT risk posture and the company's mission and business objectives, ensuring obligations to stakeholders are met through sound risk oversight.
- Drive full compliance with all applicable regulatory requirements relating to technology and cyber risk management.
- Review and assess the organization's IT risk framework, guidelines, programs, and processes to ensure relevance, effectiveness, and alignment with regulatory expectations and industry standards.
- Design the development and execution of the Technology Risk Framework and Cyber Risk Framework, including supporting policies, guidelines, and standards applicable across CIMB and its operating entities.
- Conduct periodic reviews of the IT risk profile, supported by self-assessments of risks and controls to ensure risk exposures are identified, managed, and reported in a timely and consistent manner.
- Oversee the risk profile of the CISO Office, ensuring periodic reviews of risk tolerance and control strategies are conducted and aligned with the overall risk appetite.
- Co-develop risk papers and assessments for Management attention or decision-making.
- Customize risk checklists for vendor/platform assessments, including outsourcing service providers (OSPs).
- Conduct cyber risk assessments on OSPs and third-party vendors managing company data.
- Identify gaps and propose mitigation plans; guide vendors on regulatory and internal security policy requirements.
- Ensure internal cyber risk assessments are conducted for CIMB on an annual basis.
- Translate technical security or risk-related terms into clear business language for non-technical stakeholders.
-
Vice President Fund Accounting
2 days ago
Malaysia Ascent Full time**Vice President Fund Accounting** **JOB DESCRIPTION** Headquartered in Singapore, ASCENT Group is an Independent Global Fund Administrator that provides a full range of fund administration services for Alternative funds such as Hedge Funds, Private Equity Funds, Venture Capital, Crypto Funds, VCC, Retail Estate Funds, etc., which include reviewing fund...
-
Assistant Vice President, Gcad
4 days ago
Malaysia CIMB Group Full time**Advisory Assignment** - Responsible to ensure the accuracy and completeness of the information obtained for audit planning purposes via Audit Planning Memorandum. - Analyze data from the data sources / data points as information feeds to micro-risk assessment for all risk factors on annual audit plan - Lead and execute advisory assignments including...
-
Assistant Vice President, Risk
2 days ago
Malaysia CIMB Group Full time 90,000 - 120,000 per yearDescriptionJob Purpose:As the second line of defence, responsible for the development, implementation and on-going maintenance of an effective and consistent Third Party Risk Management framework with coverage of outsourcing, partnerships and vendors/suppliers engagements.The responsibility includes providing governance, oversight and advisory to support...
-
Vice President, Tcj
1 week ago
Malaysia CIMB Group Full timeDevelop the technology design and architecture working in tandem with the unit’s respective Enterprise Application Delivery (EAD) and CIMB Group Enterprise Architecture Services (EAS) teams and within CIMB Group’s Enterprise Architecture standards, IT governance and policies including Information Security, Disaster Recovery/Business Continuity Planning...
-
Vice President
2 days ago
OCBC Malaysia, Menara GE OCBC Full time 80,000 - 120,000 per yearWHO WE ARE:As Singapore's longest established bank, we have been dedicated to enabling individuals and businesses to achieve their aspirations since 1932. How? By taking the time to truly understand people. From there, we provide support, services, solutions, and career paths that meet their individual needs and desires. Today, we're on a journey of...
-
Assistant Vice President, Finance
1 week ago
Malaysia CIMB Group Full timeConduct, direct and oversee modelling methodology and model development through statistical analyses and research papers and make recommendation for improved/new financial impairment model design and methodology that provides the most efficient and effective forward-looking measurement of expected credit losses (ECL). - Collaborate with Group Risk and...
-
Vice President, APP
2 days ago
Malaysia CIMB Group Full time 100,000 - 180,000 per yearDescriptionKey ResponsibilitiesProcess review and update investment products workflow to ensure full compliance with the latest regulatory requirements and adherence to internal governance standards.Collaborate with Digital/Technology team and translate business requirements to technical solutions.Create requirements on digital journey and ensure the flow is...
-
Vice President, GR
2 days ago
Malaysia CIMB Group Full time 120,000 - 240,000 per yearDescriptionKey ResponsibilitiesProvide second line of defense risk oversight on IT architectural initiatives and large-scale technology projectsEvaluate and challenge architectural designs, frameworks and strategies for security, resilience and regulatory alignmentPerform risk assessments on emerging technologies and major IT projects including system...
-
Vice President
1 week ago
Malaysia Hays Full time**Your new company** Based in Cyberjaya, it is a premier organisation at the forefront of cybersecurity innovation. **Your new role** In this role, you will be responsible for crafting and executing strategies that proactively identify, assess, and mitigate potential cyber risks and threats through advanced technology research and intelligence. - **...
-
Security Advisory
2 days ago
Malaysia Telenor Full timeThis is a Security Advisory evaluate existing security systems to determine the potential risk of a breach. The consultant develops policies and procedures that minimize the risk to properties, employees and computer systems. Consultants may also provide evaluations and assessments in collaboration with 3rd party solution/ product normalization for the...