Roles & Responsibilities
Identify Key Controls and Design Test Strategy
· Assess the existing processes in Enterprise IT Operations, Projects and security against COBIT & ITIL practices Head Office Policies and Rules, Local IT Regulatory requirements and MAS TRMG guidelines and identify the key controls for testing
· Define required controls, objectives, checklists and procedures for effective risk management and ability to write risk statements surrounding the IT controls
· Highlight key concerns to mitigate technology risk and conduct root cause analysis
· Partner with key stakeholders to define regular reviews against defined IT controls
Mitigate Risks and Resolve Deficiencies
· Establish and upkeep the list of Checklists on IT Operations, Technology Projects and IT Security with respect to the current processes/procedures defined.
· Plan and initiate IT Controls Checking Assignment with stakeholders and process owners in accordance with the IT Controls Objectives.
· Highlight areas of non-compliance and ensure required mitigation by teams
· Understand overall IT risk profile to identify and prioritize areas of improvement/ risk mitigation to define an improvement/ mitigation roadmap
· Engage with stakeholders to socialize/ plan out the roadmap and form core teams for mitigation
· Proactively identify and escalate any delays/ risks for timely resolution
· Foster a continual improvement culture with communication to stakeholders and guidance on risk & controls
Requirement:
· More than 10 years of experience in Banking domain with the last 5 years till current is in IT Tech Risk/IT Tech Control or IT Compliance capacity
· Working Knowledge of IT security, Risk Management and Security Control and experience in designing IT test steps to determine IT control effectiveness
· A sense of initiative and proactive action is expected
· Excellent written and verbal communication skills,
Certification (either of the following)
· Certified Information Security Auditor (CISA)
· Certified Risk and Information Systems Control (CRISC)
· ISO27001 Certified auditor
Certification Good to have
· ITIL certification
· PMP certification