Job Summary
This role could be based in Malaysia and India. When you start the application process you will be presented with a drop down menu showing all countries, Please ensure that you select a country where the role is based.
• The Information & Cyber Security (ICS) Client & Third-Party Security (CTPS) team conducts threat-led assessments for our diverse portfolio of external third parties. As a Senior Manager within the Third-Party Security Risk (TPSR) Remediation team, you will play a crucial role in managing third-party security risk. You will be responsible for overseeing remediation portfolios, addressing observations raised during third-party security assessments across all business units and functions within Standard Chartered Bank.
• This role involves making timely and sound judgments to identify clear solutions from complex or ambiguous situations, ensuring accurate risk status reporting, and collaborating with internal and external stakeholders to mitigate third-party security risks.
• The ideal candidate will integrate a robust background in Information &Cyber Security (ICS) and assessment/audit with a risk-based decision-making approach to offer support and guidance to third-party partners and internal stakeholders, thereby facilitating effective risk remediation efforts
Key Responsibilities
Strategy
• Contribute to the development and execution of the Bank's and Team's transformation strategy.
• Share innovative ideas and insights to shape strategic thinking and direction.
• Collaborate with senior leadership to define and implement strategic objectives for the TPSR Remediation team and wider CTPS team.
Business
• Collaborate with internal and external stakeholders to address and mitigate third-party security risks/observations identified during third party security assessment.
• Make timely and sound judgments, and identify clear solutions from broad, complex or ambiguous situations.
• Provide support and guidance to third-party partners to facilitate risk remediation efforts.
Processes
• Accurate and thorough validation of observations raised during third party security assessment during their closure.
• Provide guidance and support to team members and third-party partners involved in the observation closure process.
• Contribute to the development of new or amended processes, and innovative ways of working.
People & Talent
• Providing expert technical skills and guidance to less experienced team members, fostering their development and enhancing the overall team capability.
Risk Management
• Ensure timely and accurate reporting of risk status and remediation progress for different forums and committees.
Governance
• Ensure compliance with relevant operational risk controls.
• Comply with data standards and information security policies
Regulatory & Business Conduct
• Display exemplary conduct and live by the Group’s Values and Code of Conduct.
Key stakeholders
• Group Threat Management, Client & Third-Party Security
• Business Unit stakeholders, including Contract Owners and Managers, Business Heads
• All three lines of defence within the Bank - Operational Technology Cyber Risk, Chief Information Security Officer and Audit teams.
Other Responsibilities
• Embed “Here for Good” and Group’s brand and values in the CTPS Team
• Perform other responsibilities assigned under Group, Country, Business or Functional policies and procedures.
Qualifications
• Bachelor’s degree or above from an accredited college/university in an appropriate field (master degree is advantage).
• Excellent communication skills in English (Proficiency in Mandarin would be advantageous but not mandated).
• Ideally 3-5 years of experience in information security / IT auditing, with Big 4 and/or Banking & Financial services experience
• Experience in third party audits/assessments,
• Understanding of auditing standards, compliance, risk assessment and internal control framework.
• Excellent written and verbal communication skills.
• Excellent time management skills.
• Excellent stakeholder engagement skills, and ability to interact at all levels across an organisation, and external stakeholders.
• Ability to multitask and ensure that all key priorities are delivered as per agreed timelines.
• Industry certifications is advantage (e.g. CISSP, CISM, CISA)
• Experience of direct/indirect people management.
• Intermediate competency with Microsoft Office Suite (Word, PowerPoint, Excel, Visio, SharePoint).
Skills and Experience
• ICS Audit/Assessment/Assurance
• Cybersecurity Risk Management
• Controls and Frameworks
• Technical ICS skills (Access management, Incident management, SDLC, DLP, Cryptographic Management, Network /IT Security)
• Indirect/Direct people management
• Peer review
• Soft skills (Communication, confidence, delegation, decision-making, etc.)
About Standard Chartered
We're an international bank, nimble enough to act, big enough for impact. For more than 170 years, we've worked to make a positive difference for our clients, communities, and each other. We question the status quo, love a challenge and enjoy finding new opportunities to grow and do better than before. If you're looking for a career with purpose and you want to work for a bank making a difference, we want to hear from you. You can count on us to celebrate your unique talents and we can't wait to see the talents you can bring us.
Our purpose, to drive commerce and prosperity through our unique diversity, together with our brand promise, to be here for good are achieved by how we each live our valued behaviours. When you work with us, you'll see how we value difference and advocate inclusion.
Together we:
- Do the right thing and are assertive, challenge one another, and live with integrity, while putting the client at the heart of what we do
- Never settle, continuously striving to improve and innovate, keeping things simple and learning from doing well, and not so well
- Are better together, we can be ourselves, be inclusive, see more good in others, and work collectively to build for the long term
What we offer
In line with our Fair Pay Charter, we offer a competitive salary and benefits to support your mental, physical, financial and social wellbeing.
- Core bank funding for retirement savings, medical and life insurance, with flexible and voluntary benefits available in some locations.
- Time-off including annual leave, parental/maternity (20 weeks), sabbatical (12 months maximum) and volunteering leave (3 days), along with minimum global standards for annual and public holiday, which is combined to 30 days minimum.
- Flexible working options based around home and office locations, with flexible working patterns.
- Proactive wellbeing support through Unmind, a market-leading digital wellbeing platform, development courses for resilience and other human skills, global Employee Assistance Programme, sick leave, mental health first-aiders and all sorts of self-help toolkits
- A continuous learning culture to support your growth, with opportunities to reskill and upskill and access to physical, virtual and digital learning.
- Being part of an inclusive and values driven organisation, one that embraces and celebrates our unique diversity, across our teams, business functions and geographies - everyone feels respected and can realise their full potential.