Job Description - Technology and Third-Party Risk Head
The Head, Technology & Third-Party Risk is responsible for establishing, implementing, and overseeing the Company's Technology Risk Management and Third-Party Risk Management frameworks. The role provides independent oversight of technology-related risks, including cyber security, information security, digital platforms, cloud services, outsourced service providers, and critical and non-critical third-party vendors.
The incumbent works closely with Technology, Information Security, General Administration, Legal, Compliance, Business Units, and Internal Audit to ensure that technology and outsourcing risks are effectively identified, assessed, monitored, and mitigated in accordance with the Company's risk appetite and applicable regulatory requirements.
This role is part of the Second Line of Defense and is independent from Technology Operations.
Responsibilities:
Technology Risk Management Develop, implement, and maintain the Company's Technology Risk Management Framework.
Establish methodologies for identifying, assessing, monitoring, and reporting technology-related risks.
Perform independent technology risk assessments for systems, applications, infrastructure, cloud services, and digital initiatives.
Assess technology risks associated with new products, digital transformation initiatives, and system implementations.
Monitor technology risk indicators and recommend appropriate risk mitigation measures.
Prepare technology risk reports for Senior Management, Risk Committees, and the Board.
Provide independent oversight of cyber security and information security risks across the organization.
Review and challenge cyber security controls implemented by Technology and Information Security functions.
Assess the effectiveness of information security governance, policies, and control frameworks.
Monitor emerging cyber threats and assess their potential impact on the Company's risk profile.
Participate in cyber security risk assessments, vulnerability management reviews, and security governance activities.
Monitor cyber risk metrics and key risk indicators (KRIs).
Third-Party Risk Management
Develop and maintain the Company's Third-Party Risk Management Framework.
Conduct risk assessments of vendors, outsourced service providers, cloud providers, fintech partners, and other third parties.
Perform due diligence reviews before onboarding new vendors.
Assess operational resilience, cyber security, information security, financial, legal, compliance, and operational risks associated with third parties.
Maintain the Company's third-party risk register and risk rating methodology.
Monitor ongoing vendor performance and periodic risk reassessments.
Review critical outsourcing arrangements and recommend risk mitigation measures.
Governance and Compliance
Develop technology and third-party risk policies, standards, and procedures.
Ensure alignment with the Enterprise Risk Management Framework and Risk Appetite Statement.
Support management committees and Board Risk Oversight Committee by providing technology and outsourcing risk reports.
Review technology-related policy exceptions and recommend appropriate actions.
Monitor regulatory developments relating to technology risk, cyber security, outsourcing, and information security.
Coordinate remediation of technology and third-party risk findings.
Ensure compliance with applicable laws, regulations, and industry standards.
Participate in the independent review of technology incidents, cyber security events, and major service disruptions.
Assess root causes, control weaknesses, and residual risks arising from technology incidents.
Monitor remediation activities and verify closure of significant risk issues.
Identify emerging technology risks and recommend proactive mitigation strategies.
Qualifications:
Bachelor's degree preferably in Information Technology, Computer Science, Business, Information Systems, Cyber Security, or Engineering gained in a reputable college/university.
With at least 7 - 10 years relevant work experience Technology Risk Management, Information Security Risk, Cyber Security Risk, Third-Party Risk Management, and Outsourcing Risk gained in a bank, fintech, or financial institution.
Previous people management or project leadership experience is preferred.
Experience conducting independent risk assessments of technology projects, cloud environments, cyber security controls, and outsourced service providers.
Excellent professional writing skills with a proven ability to draft formal governance documents, standard operating procedures, and technical policy frameworks.
Strong communication skills that foster harmonious collaboration with other business units.
Ability to explain technical risk outcomes and policy changes to non-technical stakeholders.
Professional Certifications (Preferred) One or more of the following:
CRISC (Certified in Risk and Information Systems Control)
CISA (Certified Information Systems Auditor)
CISSP (Certified Systems Security Professional)
CISM (Certified Information Security Manager)
ISO/IEC 27001 Lead Implementer or Lead Auditor
COBIT Foundation or COBIT Design & Implementation
Certified Third-Party Risk Professional (CTPRP) or equivalent (advantage)
Technical Knowledge
Technology Risk Management Frameworks
Cyber Security Risk Management
Information Security Governance
Third-Party and Outsourcing Risk Management
Cloud Risk Assessment
IT General Controls (ITGC)
Identity and Access Management concepts
Vulnerability and Patch Management concepts
Business Continuity and Disaster Recovery
Operational Resilience
Risk and Control Self-Assessments (RCSA)
Key Risk Indicators (KRIs)
Incident and Issue Management
Location: Taguig Work schedule: Dayshift Work set up: Onsite
By Applying, you give consent to collect, store, and/or process personal and/or sensitive information for the purpose of recruitment and employment may it be internal to Cobden & Carter International and/or to its clients
All Job Ads are subject to GrabJobs’s Terms of Service. We allow users to flag postings that may be in violation of those terms. Job Ads may also be flagged by GrabJobs moderation team. However, no moderation system is perfect, and flagging a posting does not ensure that it will be removed.
Be the first to receive the latest Others Full-Time Jobs in the Philippines.
Setup your job alert:
By activating job alerts, I agree to GrabJobs Terms & Privacy Policy. I can unsubscribe to job alerts anytime.
Skip
GrabJobs is the no1 job portal in the Philippines, connecting you to thousands of jobs fast!
Find the best jobs in the Philippines, apply in 1 click and get a job today!