Lead and continuously enhance the enterprise-wide Technology Risk Management function, providing independent oversight and governance over all technology-related risks including Cybersecurity, Information Security, Artificial Intelligence (AI), Cloud, On-Premise Infrastructure, Operational Technology (OT), Data Protection, Third-Party/Vendor, Digital Transformation, and Emerging Technology risks.
The role ensures technology risks are identified, assessed, prioritized, reported, and managed within the organization's risk appetite while supporting business growth, innovation, operational resilience, regulatory compliance, and digital transformation initiatives.
Act as a strategic advisor to executive management, technology leadership, risk committees, and board-level governance forums on technology risk matters.
Key Responsibilities
Technology Risk Governance
- Establish and maintain the Enterprise Technology Risk Management Framework.
- Define technology risk policies, standards, methodologies, risk appetite, and governance processes.
- Ensure alignment with Enterprise Risk Management (ERM) and Group Risk requirements.
Enterprise Technology Risk Oversight
- Lead identification, assessment, monitoring, and reporting of risks across:
- Cybersecurity & Information Security
- Cloud & Hybrid Infrastructure
- On-Premise Infrastructure
- Artificial Intelligence (AI) & Generative AI
- Operational Technology (OT), ICS & IoT
- Applications & Digital Platforms
- Data Protection & Privacy
- Third-Party & Supply Chain Technology Risk
- Technology Projects & Digital Transformation
- Business Continuity & Operational Resilience
- Oversee risk treatment plans and ensure timely remediation of control gaps.
Risk Advisory & Business Partnership
- Provide independent technology risk advisory services to business and IT stakeholders.
- Support strategic initiatives, digital transformation, cloud adoption, AI implementation, and technology modernization programs.
- Challenge risk decisions and ensure alignment with organizational risk appetite.
Regulatory Compliance & Assurance
- Ensure compliance with applicable regulatory, legal, and industry requirements.
- Coordinate technology risk assessments, audits, certifications, and regulatory reviews.
- Monitor remediation of audit findings and compliance gaps.
Risk Reporting & Executive Engagement
- Develop and maintain technology risk dashboards, KRIs, KPIs, and executive reporting.
- Present technology risk posture, emerging threats, and key issues to management committees and senior leadership.
- Provide insights and recommendations to support risk-based decision-making.
Leadership & Risk Culture
- Promote a strong risk-aware culture across business and technology functions.
- Mentor and guide risk owners, control owners, and technology teams.
- Lead and develop a high-performing Technology Risk Management capability.
Qualifications & Experience
Education
- Bachelor's Degree in Information Technology, Cyber Security, Risk Management, Computer Science, or related discipline.
- Master's Degree is an advantage.
Experience
- 8 - 10+ years of experience in Technology Risk, Cybersecurity, Information Security, IT Governance, IT Audit, or Enterprise Risk Management.
- Minimum 5 years in a leadership or management role.
- Experience in, shared services, manufacturing, industrial, or highly regulated environments is preferred.
Preferred Certifications
- CRISC
- CISSP
- CISM
- CISA
- CGEIT
- ISO 27001 Lead Auditor / Lead Implementer
- CCSP or equivalent Cloud Security certification
Technical Knowledge
Strong understanding of:
- ISO 27001
- NIST Cybersecurity Framework
- COBIT
- ISO 31000 / COSO ERM
- Cloud Security (AWS, Aliyun, Google Cloud (Optional))
- AI & Generative AI Governance
- OT/ICS Security
- Third-Party Risk Management
- Data Protection & Privacy Regulations
- Business Continuity & Operational Resilience