Job Summary
This role could be based in Malaysia and Poland. When you start the application process you will be presented with a drop down menu showing all countries, please ensure that you select a country where the role is based.
The role is to perform various Information and Cyber Security Risk and Control activities for the supported function. This team provides risk management, risk governance and assurance services, as well as advocating and imparting lessons and good practice to shape the design and implementation of information and cyber security controls. Person in this role is supporting functions, risks and processes assigned.
Key Responsibilities
• Perform all risk and control activities related to all people, processes and assets within the Information and Cyber Security for the assigned functions, processes and risks.
• Act as the confidant to the ‘Process Owner(s)’ responsible for developing, prioritizing and implementing controls.
• Act as a point of contact during various assurance activities run by internal and external teams and authorities. That includes delivery of quality responses to Requests for information.
• Drive compliance with the Bank’s risk frameworks and policies.
• Deliver risk focused, timely and re-performable deep dive reviews.
• Support design and maintenance of internal processes that allow to dynamically monitor risk as well as effectively mitigate identified gaps.
• Maintain, update and monitor controls and corresponding metrics.
• Provide timely and accurate risk & control MI to the management within risk management systems and repositories.
• Support stakeholders in defining remediation actions to address identified control weaknesses as well as track remediation, check and challenge delivery status.
• Perform other Risk and Control tasks as assigned by the manager.
Strategy
• Awareness and understanding of the Group's business strategy as well as Technology & Operations (T&O) and ICS strategies and operating model appropriate to the role.
• Anticipates how changes in technology, cyber threat landscape, or regulatory expectations may impact the function’s risk profile.
Processes
• Demonstrates deep understanding of end-to-end process flows within supported functions and associated control points.
• Understanding of risk management processes established in the Bank
People & Talent
• Acts as a trusted advisor and confidant to Process Owners.
• Builds strong cross-functional relationships across teams.
• Consults stakeholders on control and metrics design best practice and risk management principles.
Processes
• Demonstrates deep understanding of end-to-end process flows within supported functions and associated control points.
• Understanding of risk management processes established in the Bank
People & Talent
• Acts as a trusted advisor and confidant to Process Owners.
• Builds strong cross-functional relationships across teams.
• Consults stakeholders on control and metrics design best practice and risk management principles.
Risk Management
• Support Process owners in the execution of their risk management accountabilities.
• Work with other control assurance teams to drive efficiency, effectiveness, control maturity and reduce duplication
• Perform control assessments, review assurance activities outcomes and adequacy of the related remediation actions.
• Provide robust challenge and escalation to senior management to ensure activities achieve risk remediation and reduction.
• Support activities related to control design, assessment, testing processes and drive continuous improvement.
• Support liaison with Group Internal Audit and any third party or regulatory inspections.
Governance
• Awareness and understanding of the regulatory requirements and expectations relevant to the role.
Regulatory & Business Conduct
• Display exemplary conduct and live by the Group’s Values and Code of Conduct.
• Take personal responsibility for embedding the highest standards of ethics, including regulatory and business conduct, across Standard Chartered Bank. This includes understanding and ensuring compliance with, in letter and spirit, all applicable laws, regulations, guidelines and the Group Code of Conduct.
• Effectively and collaboratively identify, escalate, mitigate and resolve risk, conduct and compliance matters.
Key stakeholders
• Group Process Owners
• Service Heads and Team leads
• Operational, Technology and Cyber Risk (OTCR)
• Group Internal Audit
• Internal Control Testing teams
• Other teams in T&O Risk Management
Other Responsibilities
• Embed Here for good and Group’s brand and values in ICS Risk Control Team
• Perform other responsibilities assigned under Group, Country, Business or Functional policies and procedures
Skills and Experience
• Cybersecurity Risk Management
• Information Security Audits
• Information Security Management
• Security Information and Event Management (SIEM)
• Information Security Operation Center (ISOC)
Qualifications
• Bachelor qualifications in Computer Science or other relevant areas or similar knowledge adequately documented.
• 8+ years in Cybersecurity or IT/Cyber Audit and/or Cyber Risk Management or similar.
• Professional qualifications such as CISA / CRISC / CISM / CISSP will be advantageous.
• Technical knowledge on security controls best practices across different platforms, systems and security tools.
• Good understanding of security processes, risks and controls, audit and testing methodologies.
About Standard Chartered
We're an international bank, nimble enough to act, big enough for impact. For more than 170 years, we've worked to make a positive difference for our clients, communities, and each other. We question the status quo, love a challenge and enjoy finding new opportunities to grow and do better than before. If you're looking for a career with purpose and you want to work for a bank making a difference, we want to hear from you. You can count on us to celebrate your unique talents and we can't wait to see the talents you can bring us.
Our purpose, to drive commerce and prosperity through our unique diversity, together with our brand promise, to be here for good are achieved by how we each live our valued behaviours. When you work with us, you'll see how we value difference and advocate inclusion.
Together we:
- Do the right thing and are assertive, challenge one another, and live with integrity, while putting the client at the heart of what we do
- Never settle, continuously striving to improve and innovate, keeping things simple and learning from doing well, and not so well
- Are better together, we can be ourselves, be inclusive, see more good in others, and work collectively to build for the long term
What we offer
In line with our Fair Pay Charter, we offer a competitive salary and benefits to support your mental, physical, financial and social wellbeing.
- Core bank funding for retirement savings, medical and life insurance, with flexible and voluntary benefits available in some locations.
- Time-off including annual leave, parental/maternity (20 weeks), sabbatical (12 months maximum) and volunteering leave (3 days), along with minimum global standards for annual and public holiday, which is combined to 30 days minimum.
- Flexible working options based around home and office locations, with flexible working patterns.
- Proactive wellbeing support through Unmind, a market-leading digital wellbeing platform, development courses for resilience and other human skills, global Employee Assistance Programme, sick leave, mental health first-aiders and all sorts of self-help toolkits
- A continuous learning culture to support your growth, with opportunities to reskill and upskill and access to physical, virtual and digital learning.
- Being part of an inclusive and values driven organisation, one that embraces and celebrates our unique diversity, across our teams, business functions and geographies - everyone feels respected and can realise their full potential.