C

Technology and Third-Party Risk Head

Job Description - Technology and Third-Party Risk Head

The Head, Technology & Third-Party Risk is responsible for establishing, implementing, and overseeing the Company's Technology Risk Management and Third-Party Risk Management frameworks. The role provides independent oversight of technology-related risks, including cyber security, information security, digital platforms, cloud services, outsourced service providers, and critical and non-critical third-party vendors.

The incumbent works closely with Technology, Information Security, General Administration, Legal, Compliance, Business Units, and Internal Audit to ensure that technology and outsourcing risks are effectively identified, assessed, monitored, and mitigated in accordance with the Company's risk appetite and applicable regulatory requirements.

This role is part of the Second Line of Defense and is independent from Technology Operations.

Responsibilities:

  • Technology Risk Management
    Develop, implement, and maintain the Company's Technology Risk Management Framework.
  • Establish methodologies for identifying, assessing, monitoring, and reporting technology-related risks.
  • Perform independent technology risk assessments for systems, applications, infrastructure, cloud services, and digital initiatives.
  • Assess technology risks associated with new products, digital transformation initiatives, and system implementations.
  • Monitor technology risk indicators and recommend appropriate risk mitigation measures.
  • Prepare technology risk reports for Senior Management, Risk Committees, and the Board.
  • Provide independent oversight of cyber security and information security risks across the organization.
  • Review and challenge cyber security controls implemented by Technology and Information Security functions.
  • Assess the effectiveness of information security governance, policies, and control frameworks.
  • Monitor emerging cyber threats and assess their potential impact on the Company's risk profile.
  • Participate in cyber security risk assessments, vulnerability management reviews, and security
    governance activities.
  • Monitor cyber risk metrics and key risk indicators (KRIs).

Third-Party Risk Management

  • Develop and maintain the Company's Third-Party Risk Management Framework.
  • Conduct risk assessments of vendors, outsourced service providers, cloud providers, fintech partners, and other   third parties.
  • Perform due diligence reviews before onboarding new vendors.
  • Assess operational resilience, cyber security, information security, financial, legal, compliance, and operational risks associated with third parties.
  • Maintain the Company's third-party risk register and risk rating methodology.
  • Monitor ongoing vendor performance and periodic risk reassessments.
  • Review critical outsourcing arrangements and recommend risk mitigation measures.

Governance and Compliance

  • Develop technology and third-party risk policies, standards, and procedures.
  • Ensure alignment with the Enterprise Risk Management Framework and Risk Appetite Statement.
  • Support management committees and Board Risk Oversight Committee by providing technology
    and outsourcing risk reports.
  • Review technology-related policy exceptions and recommend appropriate actions.
  • Monitor regulatory developments relating to technology risk, cyber security, outsourcing, and
    information security.
  • Coordinate remediation of technology and third-party risk findings.
  • Ensure compliance with applicable laws, regulations, and industry standards.
  • Participate in the independent review of technology incidents, cyber security events, and major service disruptions.
  • Assess root causes, control weaknesses, and residual risks arising from technology incidents.
  • Monitor remediation activities and verify closure of significant risk issues.
  • Identify emerging technology risks and recommend proactive mitigation strategies.

Qualifications:

  • Bachelor's degree preferably in Information Technology, Computer Science, Business, Information Systems, Cyber Security, or Engineering gained in a reputable college/university.
  • With at least 7 - 10 years relevant work experience Technology Risk Management, Information
    Security Risk, Cyber Security Risk, Third-Party Risk Management, and Outsourcing Risk gained
    in a bank, fintech, or financial institution.
  • Previous people management or project leadership experience is preferred.
  • Experience conducting independent risk assessments of technology projects, cloud
    environments, cyber security controls, and outsourced service providers.
  • Excellent professional writing skills with a proven ability to draft formal governance documents,
    standard operating procedures, and technical policy frameworks.
  • Strong communication skills that foster harmonious collaboration with other business units.
  • Ability to explain technical risk outcomes and policy changes to non-technical stakeholders.

Professional Certifications (Preferred)
One or more of the following:

  • CRISC (Certified in Risk and Information Systems Control)
  • CISA (Certified Information Systems Auditor)
  • CISSP (Certified
    Systems Security Professional)
  • CISM (Certified Information Security Manager)
  • ISO/IEC 27001 Lead Implementer or Lead Auditor
  • COBIT Foundation or COBIT Design & Implementation
  • Certified Third-Party Risk Professional (CTPRP) or equivalent (advantage)

Technical Knowledge

  • Technology Risk Management Frameworks
  • Cyber Security Risk Management
  • Information Security Governance
  • Third-Party and Outsourcing Risk Management
  • Cloud Risk Assessment
  • IT General Controls (ITGC)
  • Identity and Access Management concepts
  • Vulnerability and Patch Management concepts
  • Business Continuity and Disaster Recovery
  • Operational Resilience
  • Risk and Control Self-Assessments (RCSA)
  • Key Risk Indicators (KRIs)
  • Incident and Issue Management

Location: Taguig
Work schedule: Dayshift
Work set up: Onsite

By Applying, you give consent to collect, store, and/or process personal and/or sensitive information for the purpose of recruitment and employment may it be internal to Cobden & Carter International and/or to its clients

Original job Technology and Third-Party Risk Head posted on GrabJobs ©. To flag any issues with this job please use the Report Job button on GrabJobs.
Share Job
Share Job

Similar Technology and Third-Party Risk Head Jobs in the Philippines

GrabJobs is the no1 job portal in the Philippines, connecting you to thousands of jobs fast! Find the best jobs in the Philippines, apply in 1 click and get a job today!

Mobile Apps

Copyright © 2026 Grabjobs Pte.Ltd. All Rights Reserved.