Associate Manager, Tech & Cyber Risk
Are you passionate about strengthening cybersecurity governance, managing technology risks, and ensuring regulatory compliance? We are looking for an Associate Manager, Tech & Cyber Risk to support the organisation's cyber resilience and risk management initiatives.
In this role, you will play a key part in driving cybersecurity governance, risk monitoring, compliance reporting, and cyber maturity initiatives to safeguard the organisation against evolving technology and cyber threats.
What You'll Be Doing:
- Support the implementation and enhancement of technology and cyber risk frameworks, policies, and governance practices.
- Monitor regulatory developments and ensure alignment with applicable cybersecurity regulations, standards, and internal policies.
- Prepare and coordinate cybersecurity Key Risk Indicator (KRI) reporting and support risk reporting to management, Board committees, and regulators.
- Conduct technology and cybersecurity risk assessments, including Business-Based Risk Assessments (BBRA) and project risk reviews.
- Facilitate internal and external audits by coordinating evidence gathering, response management, and remediation tracking.
- Coordinate cyber simulation exercises and support incident response readiness across business and technology teams.
- Drive cybersecurity awareness and risk culture initiatives through engagement sessions, workshops, surveys, and educational programmes.
- Support cyber maturity assessments by coordinating stakeholders, gathering evidence, analysing results, and recommending improvement opportunities.
What We're Looking For:
- Bachelor's Degree in Computer Science, Information Security, Risk Management, or a related field.
- 3 to 5 years of relevant experience in cybersecurity, IT governance, risk management, or compliance.
- Knowledge of cybersecurity and governance frameworks such as NIST, ISO 27001, and COBIT.
- Familiarity with regulatory requirements such as SC GTRM and BNM RMiT.
- Strong analytical, risk assessment, report writing, and stakeholder management skills.
- Relevant professional certifications such as Security+, ISO 27001, CISM, CRISC, CISSP, or CISA are an added advantage.
Why Join Us?
- Be part of a team driving technology risk and cybersecurity governance across the organisation.
- Work closely with business leaders, technology teams, regulators, and external partners.
- Contribute to meaningful initiatives that strengthen organisational resilience and cyber maturity.
- Gain exposure to enterprise-wide risk management, regulatory compliance, and strategic cybersecurity programmes.