Responsibilities:
Technology Risk Management
As a part of the Risk and Control team (RCU) of Digital SG, the candidate will need to work with the stakeholders and relevant teams by:
- Technology Risk Management: Provide expertise on technology risk and regulatory compliance, focusing on digital banking platforms, APIs, and cloud technologies
- Risk Assessment and Mitigation: Oversee risk assessments, including outsourcing risk and common high-risk areas, and provide guidance on mitigation strategies
- Compliance and Governance: Assess compliance exposure to security, digital automation, AI, data analytics, and technology-related regulatory requirements, and drive remediation efforts
- Risk Management: Monitor and report risk indicators, escalate operational risk events, and collaborate on risk mitigation strategies
- Regulatory Compliance: Perform regulatory gap analysis, ensure adequate risk and control measures, and manage regulatory expectations
- Policy and Procedure Alignment: Collaborate with stakeholders to ensure departmental policies and procedures are effective, updated, and aligned with the Bank’s risk framework
Champion the Risk and Compliance Culture
- Support Head of RCU/HOD to champion Risk and Compliance culture, and provide relevant risk and compliance updates / training within the department
- Work in collaboration with 2nd LOD in developing relevant risk and compliance updates / training materials / risk culture initiatives for the department
- Ensure continuous upskilling of own capabilities on risk and compliance knowledge to enable effective risk identification, assessment and control across the functions of the department
Regulatory Compliance
- Support Head RCU/HOD/CIB in addressing requirements and audit requests of local regulators with respect to non-financial risks and regulatory compliance, ensuring departmental non-financial risk controls and practices are following the applicable banking laws, regulations, internal policies and procedures
- Stay abreast of industry trends, regulatory developments and best practices in non-financial risk and compliance risk to continuously enhance departmental risk management capabilities and operational resilience
Requirements:
Qualifications
- Degree holder, or Professional Qualification in the relevant discipline such as Banking, Finance, Computer Science, or Business
Professional Qualification and/or Regulatory, Licensing Requirements
- Professional information security certifications such as CISA, CRISC, and/or CISSP
- Sound knowledge in regulatory requirements (e.g. MAS Notice FSM-05, FSM-06, and TRM guidelines) and industry standards/ frameworks such as NIST, ISO 27001/2, Cyber Security Act, and MAS Outsourcing/Risk Management Guidelines.
- Professional or post graduate qualifications e.g. AML/CFT and TFS Certification, Regulatory Compliance Certification and the equivalent issued by an acknowledged institution and/or regulatory bodies, will be added as advantage
Relevant Work Experience
- Minimum 8 years of work experience, preferably with 1st line or 2nd line working experience in banking industry, digital transformation projects, and/or from commercial law enforcement team
- Possess strong prior experience and knowledge in technology, digital control frameworks, cyber standards and policy review, oversight and governance, risk management, and IT audit.
- Strong analytical and problem-solving skills with the ability to deliver pragmatic solutions to risk issues independently
Competencies/Skills
- Good communication skills both verbal and written
- An understanding of risk drivers and ability to articulate risk to non-risk personnel
- Understanding of how a bank operates front to back
- A deep understanding of cybersecurity, technology, cloud environments, and fraud risk management requirements of a universal bank
- Strong understanding of digital banking architectures, system requirements, APIs, data platforms, and infrastructure
- Experience in being able to contribute to methodology enhancement and assurance methodologies
- Experience working in or supporting Agile / DevOps / digital transformation environments
- Develop strong partnership and collaboration with the various business units, Risk, Compliance, Technology, and RCU teams with the achievement of the common goals in mind
Skills Required
- Degree or professional qualification in Banking, Finance, Computer Science, Business, or a relevant discipline
- Professional information security certification such as CISA, CRISC, or CISSP
- Knowledge of MAS Notice FSM-05, FSM-06, and Technology Risk Management guidelines
- Knowledge of NIST, ISO 27001/2, Cyber Security Act, and MAS Outsourcing/Risk Management Guidelines
- Minimum 8 years of relevant work experience
- Experience in banking, digital transformation projects, and/or commercial law enforcement
- Experience with technology, digital control frameworks, cybersecurity standards, policy review, governance, risk management, and IT audit
- Strong analytical and problem-solving skills
- Strong understanding of cybersecurity, technology, cloud environments, and fraud risk management in a universal bank
- Strong understanding of digital banking architectures, system requirements, APIs, data platforms, and infrastructure
- Experience supporting Agile, DevOps, or digital transformation environments
- Strong verbal and written communication skills
What We Do
CIMB Singapore is a leading universal bank operating in ASEAN's global financial gateway. Leveraging CIMB Group's extensive regional network and resources, it provides a comprehensive suite of conventional and Islamic banking solutions curated to a wide range of financial needs. The bank serves both individual and business clients, offering retail, commercial, and corporate banking services, and specializes in bridging markets across the ASEAN region.









