Mô tả công việc
| Main Duties: |
| Act as the senior individual contributor and technical lead within the Risk Management team, responsible for implementing, operating, and continuously improving the risk management framework across Technology and Business domains. The role bridges technical/ technology risk issues and business-impact communication for executive stakeholders and assist management to provides day-to-day technical guidance to other team members with high initiative and requiring minimal supervision from superiors. |
| Responsibilities: |
| 1. Risk Management activities
a. Tech Risk • Identify, analyze, and assess operational and technology risks across product development, engineering delivery, infrastructure & security, and data management practices. • Conduct RCSA advisory and review, maintain Risk Profile for assigned Tech domains. • Support RCA for major incidents, system/security-related losses, and high-impact technology failures. • Develop, monitor, and report Key Risk Indicators (KRIs) and early warning signals relevant to technology risk (e.g. system availability, data integrity, security incidents). • Liaise with Product, Engineering, Infrastructure & Security, Data stakeholders to ensure risk considerations are embedded in the development lifecycle. b. Ops Risk (Operations and Vertical) • Identify, analyze, and assess operational risks within Operations and Vertical processes. • Conduct RCSA advisory and review, maintain Risk Profile for assigned Business domains. • Support/Perform RCA for major incidents, operational losses, and high-impact complaints within these verticals. • Develop, monitor, and report KRIs and early warning signals for Operations and Vertical. 2. Risk Framework Operation & Continuous Improvement • Operate the existing Risk Management framework in accordance with approved policies and procedures. • Proactively identify gaps or inefficiencies in the current framework, and propose improvements aligned with recognized international practices (e.g., COSO, ISO 31000) via periodic review and enhancement; • Ensure adherence to risk control requirements and internal policies across assigned Tech and Biz domains. 3. Internal Control Monitoring & Reporting • Maintain and update Risk Profiles, LDC, KRIs, CAPA tracking within the assigned scope. • Prepare periodic and ad-hoc risk reports for senior management, translating technical/technology risk findings into business-impact language suitable for executive-level audiences. • Evaluate the effectiveness of existing controls across Tech and Biz domains and recommend improvements to mitigate risk exposure. • Continuously monitor operational and technology-related activities and provide timely risk alerts to management |
Yêu cầu công việc
| Experience
• Minimum 5-7 years of experience in Risk Management, Operational Risk, or Internal Control. • Prior working experience at a platform economy/super-app company is strongly preferred. • Demonstrated exposure to risk management spanning both technology and business/ operations is strongly preferred. Technical Competencies • Solid understanding of Risk Profile, RCSA, KRIs, and operational risk management practices. • Working knowledge of incident management, fraud risk controls, and governance frameworks. • Sufficient working knowledge of technology/IT risk concepts (system architecture basics, infrastructure & security risk, data governance) to assess risk and engage credibly with Engineering/ Security/ Data stakeholders. • Strong analytical skills with the ability to interpret data and identify risk patterns across both Tech and Biz domains. Soft Skills • Strong problem-solving and critical thinking capability. • Excellent communication skills, specifically the ability to translate technology-heavy or technical risk issues into business-impact language. • Effective stakeholder management and internal consulting skills across Tech & Biz functions. • Ability to work independently while maintaining a strong risk sensitivity & control mindset. Certifications • CIA (Certified Internal Auditor)/ CRMA (Certification in Risk Management Assurance)/ ISO 31000 Lead Risk is an advantage; • Demonstrate practical working knowledge of relevant technology and security standards (e.g. ISO/IEC 27001, PCI DSS, NIST CSF, ISO/IEC 27701, ITIL, COBIT, GDPR,…). |