jobs in TECSTATION PTE. LTD.

TECSTATION PTE. LTD. Hiring! Full Time Technology Risk - Regulatory Compliance Lead in Central Region (Singapore), Earn up to SGD 8,000 - Ricebowl

Technology Risk - Regulatory Compliance Lead

TECSTATION PTE. LTD.

SGD5,000 - SGD8,000 Per Month

Tanjong Pagar, Central Region (Singapore)

Share
Save

Working Location

  • Tanjong Pagar Central Region (Singapore) Singapore

Job Description

Responsibilities

Role Overview

We are seeking an experienced Technology Risk & Regulatory Compliance Lead, to lead and coordinate our organisation's compliance with prevailing global Technology Risk, Cybersecurity and Cyber Hygiene regulations.

This is a global role suited to a professional who can articulate and operate confidently across both global ICT resilience requirements and technology risk supervisory framework in a Financial Services environment, translating regulatory obligations into practical, auditable controls across the organisation's technology, third-party, and operational risk landscape.

The successful candidate will act as the subject-matter authority on ICT/technology risk/cyber hygiene regulations, working closely with Compliance, Legal, Technology and Senior Management to build and maintain a defensible, regulator-ready technology risk and resilience program.

Key Responsibilities

1. Regulatory Compliance & Gap Assessment

  • Define and lead on the organisation's compliance programme against DORA (Regulation (EU) 2022/2554), its associated Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS).
  • Lead and maintain compliance against the MAS Technology Risk Management Guidelines and the MAS Notice on Cyber Hygiene and related Notices/Guidelines.
  • Conduct periodic gap assessments mapping current technology, cybersecurity, and third-party risk controls against DORA's five pillars (ICT risk management, incident reporting, digital operational resilience testing, third-party risk management, information sharing) and MAS TRM domains.
  • Track regulatory developments, technical standards updates, and supervisory expectations issued by the ESAs (EBA, ESMA, EIOPA), MAS and translate these into internal policy and control updates.
2. Policy, Framework & Documentation

  • Draft, review, and maintain ICT risk management frameworks, technology risk policies, business continuity and disaster recovery (BCP/DR) documentation, and third-party/outsourcing risk policies aligned to DORA and MAS TRM.
  • Develop and maintain the ICT Register of Information (RoI) required under DORA, and equivalent third-party/vendor risk registers required under MAS TRM and outsourcing guidelines.
  • Prepare quarterly board and monthly management-level reporting MIs, risk registers, and compliance dashboards summarising technology risk posture, control effectiveness, and regulatory readiness.
3. Third-Party & ICT Risk Management

  • Own the third-party/ICT service provider risk management lifecycle: due diligence, contractual clause review (including DORA-mandated contractual provisions), ongoing monitoring, concentration risk assessment, and exit strategy planning.
  • Assess and classify critical/important ICT third-party providers in line with DORA and MAS outsourcing/TRM criticality criteria.
  • Coordinate with procurement, legal, and vendor management teams to ensure new and existing technology contracts meet regulatory requirements.
4. Incident Management, Testing & Resilience

  • Support the design and maintenance of ICT-related incident classification, escalation, and regulatory reporting processes consistent with DORA incident reporting timelines and MAS notification requirements.
  • Coordinate digital operational resilience testing, including vulnerability assessments, scenario-based testing, and (where applicable) threat-led penetration testing (TLPT), working with Information Security and external testing providers.
  • Support tabletop exercises, BCP/DR testing, and crisis simulation exercises to validate organisational resilience against ICT disruption.
5. Governance, Training & Stakeholder Engagement

  • Act as the primary liaison with regulators, auditors, and examiners on technology risk and operational resilience matters, including preparation of regulatory submissions and responses to inspection findings.
  • Design and deliver training and awareness programmes on DORA and MAS TRM obligations for technology, risk, compliance, and business stakeholders.
  • Support committee reporting (Risk & Compliance Committee, ICT Risk Committee) with clear, decision-ready materials on technology risk exposure and remediation status.
  • Partner with Technology, Compliance and Legal teams to embed regulatory requirements into day-to-day operational practice.
Key Qualifications & Experience

Education

  • Bachelor's degree in Information Technology, Computer Science, Risk Management, Law, Finance, or a related discipline. A relevant postgraduate qualification is an advantage.
Experience

  • Minimum 5-8 years of experience in technology risk management, IT audit, cybersecurity governance, or regulatory compliance within financial services, fintech, or payments industry.
  • Demonstrated hands-on experience implementing or advising on DORA compliance programmes, including ICT risk frameworks, third-party risk management, and incident reporting obligations.
  • Practical working knowledge of MAS Technology Risk Management Guidelines, the Notice on Cyber Hygiene, and MAS outsourcing requirements.
  • Prior experience engaging directly with regulators (MAS, MFSA) on technology risk, audits, or examinations is highly preferred.
  • Experience working with or advising cross-border financial institutions operating under both EU and Singapore regulatory regimes is a strong advantage.
Knowledge & Technical Skills

  • Strong working knowledge of ICT risk management frameworks (e.g., NIST CSF, ISO/IEC 27001, COBIT) and how these map to DORA and MAS TRM control expectations.
  • Familiarity with related EU regulatory frameworks (PSD2/PSD3, MiCA, GDPR) and Singapore frameworks (Payment Services Act, MAS Notices) to the extent they intersect with technology and operational risk.
  • Understanding of ICT third-party/outsourcing risk management, cloud risk considerations, and vendor concentration risk assessment methodologies.
  • Ability to interpret complex regulatory text and translate it into practical, implementable policies, controls, and reporting artefacts.
Certifications

  • CISA, CRISC, CISM, CISSP, or equivalent technology risk/audit certification.
  • Certificate in DORA compliance, ICT risk management, or operational resilience (e.g., from a recognised industry body) is an advantage.

Important Information

Never provide your bank or credit card details when applying for jobs. Do not transfer any money or complete unrelated online surveys. If you see something suspicious, Report this Job ad.

Learn More