AVP, Information Security & Digital Risk Management Specialist
ocbc.wd102.myworkdayjobs.com
WHO WE ARE: As Singapore’s longest established bank, we have been dedicated to enabling individuals and businesses to achieve their aspirations since 1932. How? By taking the time to truly understand people. From there, we provide support, services, solutions, and career paths that meet their individual needs and desires. Today, we’re on a journey of transformation. Leveraging technology and creativity to become a future-ready learning organisation.
But for all that change, our strategic ambition is consistently clear and bold, which is to be Asia’s leading financial services partner for a sustainable future. We invite you to build the bank of the future. Innovate the way we deliver financial services. Work in friendly, supportive teams. Build lasting value in your community. Help people grow their assets, business, and investments. Take your learning as far as you can.
Or simply enjoy a vibrant, future-ready career. Your Opportunity Starts Here. Why Join Protecting our customers' assets and information is at the heart of what we do at OCBC Group. As an Information Security and Digital Risk Management Specialist, you will play a key role in safeguarding the Group's digital ecosystem and strengthening its resilience against evolving technology and cyber risks.
In this role, you will conduct independent reviews of digital risks arising from third‑party service arrangements. This includes assessing the design and operating effectiveness of controls implemented by third‑party service providers and providing assurance on compliance with Group policies and regulatory requirements applicable to the arrangement, as well as relevant industry best practices. How you succeed To succeed in this role, you will combine strong domain knowledge, sound professional judgement, and effective stakeholder engagement skills.
You are expected to stay abreast of emerging technology, information, and cyber risk trends, and translate these developments into practical risk insights and actionable mitigation strategies. You will work closely with technology, business, and control functions to identify material risks, provide constructive and independent challenge to existing controls where appropriate, and ensure that security policies, standards, and practices remain effective, proportionate, and aligned with business objectives.
What you do Conduct digital risk assessments, due diligence reviews, and ongoing monitoring of third-party service providers. Support the development, implementation, and maintenance of third-party policies, procedures and frameworks in alignment with regulatory requirements and industry best practices. Collaborate with technology, business, and control functions to ensure effective end-to-end risk management for third-party service arrangements.
Drive or support continuous improvement initiatives for the Third-Party Risk Management programme, including process optimisation, automation, and operating model enhancements. Lead or support data-driven initiatives leveraging enterprise data platforms to analyse risk data, identify trends and emerging risks, and provide clear, actionable insights to support risk-informed decision-making. Perform or support ongoing risk monitoring and management reporting on the Group’s technology and cyber risk posture relating to third-party services, highlighting key issues and trends to senior management and relevant committees.
Support Group‑wide initiatives to facilitate compliance with applicable legal and regulatory requirements, including the MAS Cyber Hygiene Notice, MAS Technology Risk Management Guidelines and MAS Guidelines on Outsourcing. Provide training and awareness to stakeholders on technology risk and third-party risk management to promote consistent understanding and application across the Group. Who you are More than eight years of relevant experience in technology, information, or cyber risk management, or information security, with at least five years of hands-on exp