Responsibilities:- A. Thematic Risk Assurance *Plan and execute thematic assurance reviews across key cyber and technology risk domains, including, but not limited to cyber hygiene, identity and access management, vulnerability management, third-party security risk management, technology governance, cloud security, operational resilience, as well as other priority risk areas identified by management *Design and execute evidence-based validation activities to assess control design and operating effectiveness through walkthroughs, document and configuration reviews, sampling and targeted controls testing against regulatory, industry and internal standards *Identify systemic control weaknesses, recurring risk themes, and underlying root causes that may expose the Bank to elevated cyber or technology risks *Develop and operationalise AI-enabled continuous monitoring use cases to automate control testing, detect control deviations and emerging risk indicators, and provide timely risk intelligence to management and governance committees *Support continuous identification of control gaps, improvement opportunities, and emerging areas of concern. B. Emerging Threat-Informed Assurance *Assess whether existing controls remain effective against evolving threat actor tactics, emerging attack techniques and new technology risks *Incorporate relevant cyber threat intelligence, industry incidents and regulatory developments into thematic assurance reviews *Evaluate the Bank's preparedness against emerging risks including AI-enabled threats, third-party ecosystem attacks, cloud-native threats and identity-based attacks. C. Independent Challenge and Validation *Challenge assumptions in risk assessments, control evaluations, residual risk decisions and remediation strategies, while identifying blind spots and alternative risk perspectives *Review responses to audit findings, regulatory observations and risk assessments; validate that action plans address the risk exposure and that completed remediation is effective and sustainable *Assess whether accepted risks remain within the Bank's risk appetite and escalate significant or unresolved exposures through appropriate governance channels. D. Root Cause and Systemic Risk Analysis *Identify recurring findings and systemic weaknesses across technology domains and determine underlying root causes *Assess whether recurring issues indicate broader governance, process, capability or cultural weaknesses. E. Assurance Reporting, Governance & Remediation Oversight *Produce concise, risk-focused and evidence-based assurance reports, dashboards and control health metrics, and present findings and thematic observations to senior management and governance committees *Track management commitments and remediation activities through to closure *Validate remediation effectiveness and sustainability *Identify recurring issues and escalate significant concerns through governance channels. F. Stakeholder Engagement *Collaborate with Technology, Cyber Security, Control and Prevention, Risk Management, Internal Audit, Compliance, and business teams *Promote a culture of strong risk management, continuous improvement, and cyber resilience.