The GCIO Chief Control Office (CCO) team plays an important role in enabling the bank to operate within its risk appetite by ensuring efficient and effective risk and control management. We do this by providing operational risk and control expertise, specialist technical knowledge and a deep understanding of the businesses and functions we serve.
Key activities include implementation and oversight of the Group’s Risk Management Framework, ongoing and targeted controls assessments, implementing and maintaining robust risk governance, and championing a proactive risk culture. GCIO CCO works closely with partners across all lines of defence and is responsible for maintaining positive relationships with our regulators and external partners.
The role holder will be responsible for:
· Partnering with the GCIO CCO function to oversee the risk and control portfolio related to the services Singapore or consumes from the Group.
· You will be a leader within the GCIO Chief Control Office (GCIO CCO) Function that directly supporting Singapore
This will be achieved by:
· Acting as trusted advisor for senior management by partnering to manage their operational risk i.e., risk assessments, control environment, issues management, audits.
· Promoting accountable risk and control decision-making based on quality data and analysis, actively challenging poor, inefficient or excessive controls, related tasks and behaviours.
· Providing specialist risk and control knowledge and insights, leading efforts to continuously improve the control environment and monitoring of risk, including behaviours
· Advising and designing process and controls in a commercially viable, practical and effective manner.
· Identifying trends to anticipate future developments in the risk and control environment.
· Influencing and shaping the development and implementation of future-fit risk management and regulatory frameworks.
· Providing Senior Management with updates on any relevant changes to policy or projects related to operational risk that have an impact on their area of responsibility.
The role is part of a global team and will be expected to support and collaborate with other team members across multiple regions, as well as manage their portfolio while maintaining an acceptable risk profile.
Governance and Committee Memberships
Attendance of the Singapore Technology RCMM and other related committees and forums
Principal Accountabilities and Responsibilities
Stakeholder Management
· Facing off to senior management and managing respective portfolios. Responsible for embedding risk and control management framework, including control monitoring and assurance
· Managing stakeholders across multi-faceted geographies, businesses and functions.
· Presenting and reporting complex risk and control information in ways that are meaningful for different stakeholders
· Applying professional understanding, expertise and judgement to oversee the health of the end-to-end control environment
· Leveraging opportunities to implement more automated, effective and cost-efficient controls and measures of effectiveness
· Providing advice, support and challenge to stakeholders to help them understand and manage controls and risks effectively
Functional Risk & Controls lead for Singapore CIO
· Analyzing and interpreting risk and control related information to provide insight and improvement with clear and measurable outcomes.
· Delivering clear, concise and consumable messages based on good evidence and informed judgement that support risk and control related decision making
· Monitoring and analysing the performance of the control environment to drive more effective design and operation of controls
GCIO CCO function
· Support CCO operating model, service catalogue, procedures, and toolkits
· Constructive challenge on control environment and assessment of risk across GCIO
· Ensuring lessons learnt in one line of business/impacting incident are properly understood for all GCIO with associated actions implemented in a timely manner
· Embed risk culture and change delivery capability across the GCIO CCO function
External environment
· Interpret, implement, and monitor compliance with local Regulator(s) within the markets and industry standards across Cyber and Technology.
· Participate in regulatory inspections and audits, providing necessary documentation and explanations.
Leadership & Team Management
· Lead by example, demonstrating core behaviors and values including teamwork, focus, drive and determination.
· Act in a manner that transparently promotes the organization’s values and delivers in an aligned manner.
· Cultivate an environment that supports diversity and reflects the HSBC brand
· Models open communication and collaboration across the team and with stakeholders
· Understanding and energizing others to attain individual and team outcomes and performance targets
· Successfully delivering change through people initiatives
Leadership& Teamwork
· Develops and maintains long term relationships with stakeholders internally and externally
· Experience of working in a globally dispersed team
· Experience of working within a complex matrix environment
· Experience working across cultures
· Experience building high performing teams
Functional Knowledge
· 10 years hands on experience in Technology Risk Management, IT Audit, Information Security, or IT Compliance within the financial services industry.
· Strong understanding of IT general controls (ITGC), application controls, and infrastructure security.
· Strong knowledge and practical experience of at least one local technology regulation
· Familiar with other key technology standards/frameworks (NIST Cybersecurity, COBIT, ITIL)
· Previous experience of identifying and solving problems that have impact on your work or the wider business.
· Strong communication skills to influence and challenge stakeholders.
· Strong written, verbal and presentation skills to support board paper submissions.
· Flexible and adaptable, able to handle and prioritise competing demands in a fast-paced environment.
Active industry recognized certificates will be an asset, e.g. CISA, CISSP, CRISC, CCSP etc.
You’ll achieve more at HSBC.
HSBC is committed to building a culture where all employees are valued, respected and opinions count. We take pride in providing a workplace that fosters continuous professional development, flexible working and opportunities to grow within an inclusive and diverse environment. Personal data held by the Bank relating to employment applications will be used in accordance with our Privacy Statement, which is available on our website.
Issued by The Hong Kong and Shanghai Banking Corporation Limited.
Copyright © 2026 Grabjobs Pte.Ltd. All Rights Reserved.