Talent.com
Cobden & Carter International
Technology and Third-Party Risk HeadCobden & Carter International • Metro Manila, Philippines
Technology and Third-Party Risk Head

Technology and Third-Party Risk Head

Cobden & Carter International • Metro Manila, Philippines
8 days ago
Job description

The Head, Technology & Third-Party Risk is responsible for establishing, implementing, and overseeing the Company's Technology Risk Management and Third-Party Risk Management frameworks. The role provides independent oversight of technology-related risks, including cyber security, information security, digital platforms, cloud services, outsourced service providers, and critical and non-critical third-party vendors. The incumbent works closely with Technology, Information Security, General Administration, Legal, Compliance, Business Units, and Internal Audit to ensure that technology and outsourcing risks are effectively identified, assessed, monitored, and mitigated in accordance with the Company's risk appetite and applicable regulatory requirements. This role is part of the Second Line of Defense and is independent from Technology Operations. Responsibilities: Technology Risk Management Develop, implement, and maintain the Company's Technology Risk Management Framework. Establish methodologies for identifying, assessing, monitoring, and reporting technology-related risks. Perform independent technology risk assessments for systems, applications, infrastructure, cloud services, and digital initiatives. Assess technology risks associated with new products, digital transformation initiatives, and system implementations. Monitor technology risk indicators and recommend appropriate risk mitigation measures. Prepare technology risk reports for Senior Management, Risk Committees, and the Board. Provide independent oversight of cyber security and information security risks across the organization. Review and challenge cyber security controls implemented by Technology and Information Security functions. Assess the effectiveness of information security governance, policies, and control frameworks. Monitor emerging cyber threats and assess their potential impact on the Company's risk profile. Participate in cyber security risk assessments, vulnerability management reviews, and security governance activities. Monitor cyber risk metrics and key risk indicators (KRIs). Third-Party Risk Management Develop and maintain the Company's Third-Party Risk Management Framework. Conduct risk assessments of vendors, outsourced service providers, cloud providers, fintech partners, and other third parties. Perform due diligence reviews before onboarding new vendors. Assess operational resilience, cyber security, information security, financial, legal, compliance, and operational risks associated with third parties. Maintain the Company's third-party risk register and risk rating methodology. Monitor ongoing vendor performance and periodic risk reassessments. Review critical outsourcing arrangements and recommend risk mitigation measures. Governance and Compliance Develop technology and third-party risk policies, standards, and procedures. Ensure alignment with the Enterprise Risk Management Framework and Risk Appetite Statement. Support management committees and Board Risk Oversight Committee by providing technology and outsourcing risk reports. Review technology-related policy exceptions and recommend appropriate actions. Monitor regulatory developments relating to technology risk, cyber security, outsourcing, and information security. Coordinate remediation of technology and third-party risk findings. Ensure compliance with applicable laws, regulations, and industry standards. Participate in the independent review of technology incidents, cyber security events, and major service disruptions. Assess root causes, control weaknesses, and residual risks arising from technology incidents. Monitor remediation activities and verify closure of significant risk issues. Identify emerging technology risks and recommend proactive mitigation strategies. Qualifications: Bachelor's degree preferably in Information Technology, Computer Science, Business, Information Systems, Cyber Security, or Engineering gained in a reputable college/university. With at least 7 - 10 years relevant work experience Technology Risk Management, Information Security Risk, Cyber Security Risk, Third-Party Risk Management, and Outsourcing Risk gained in a bank, fintech, or financial institution. Previous people management or project leadership experience is preferred. Experience conducting independent risk assessments of technology projects, cloud environments, cyber security controls, and outsourced service providers. Excellent professional writing skills with a proven ability to draft formal governance documents, standard operating procedures, and technical policy frameworks. Strong communication skills that foster harmonious collaboration with other business units. Ability to explain technical risk outcomes and policy changes to non-technical stakeholders. Professional Certifications (Preferred) One or more of the following: CRISC (Certified in Risk and Information Systems Control) CISA (Certified Information Systems Auditor) CISSP (Certified Systems Security Professional) CISM (Certified Information Security Manager) ISO/IEC 27001 Lead Implementer or Lead Auditor COBIT Foundation or COBIT Design & Implementation Certified Third-Party Risk Professional (CTPRP) or equivalent (advantage) Technical Knowledge Technology Risk Management Frameworks Cyber Security Risk Management Information Security Governance Third-Party and Outsourcing Risk Management Cloud Risk Assessment IT General Controls (ITGC) Identity and Access Management concepts Vulnerability and Patch Management concepts Business Continuity and Disaster Recovery Operational Resilience Risk and Control Self-Assessments (RCSA) Key Risk Indicators (KRIs) Incident and Issue Management Location: Savya Financial Center Pulse Street, ARCA South, Taguig Work schedule: Dayshift Work set up: Onsite By Applying, you give consent to collect, store, and/or process personal and/or sensitive information for the purpose of recruitment and employment may it be internal to Cobden & Carter International and/or to its clients

Create a job alert for this search

Technology and Third-Party Risk Head • Metro Manila, Philippines

Similar jobs

Technology Advisory Senior Associate

Our ClientsMakati City, Metro Manila, Philippines
Quick Apply

Technology Advisory Senior Associate.Technology Advisory Senior Associate.In this role, you will lead and support consulting engagements focused on technology risk, information security, cybersecur... Show more

NFS Third Party Risk Management Senior Consultant

Ernst & Young Advisory Services Sdn BhdTaguig, Metro Manila, PH

NFS Third Party Risk Management Senior Consultant.Other locations: Primary Location Only.At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclus... Show more

 • Promoted

Technology Advisory Associate

Our ClientsMakati City, Metro Manila, Philippines
Quick Apply

We are hiring a Technology Advisory Associate to support consulting engagements focused on information security, cybersecurity governance, IT governance, and business continuity.This position offer... Show more

Operational Risk Management Lead

Globe Telecom, Inc.Metro Manila, PH

We are looking for a Lead in Operational Risk Management to support the development and execution of risk management strategies.This role will focus on managing operational risk assessments, identi... Show more

 • Promoted

Technology Risk Associate

Our ClientsMakati City, Metro Manila, Philippines
Quick Apply

Join a growing Technology Advisory team as a Technology Risk Associate, where you will help organizations strengthen their information security, IT governance, and business resilience programs thro... Show more

Head of Operational Risk & Strategy

Globe Telecom, Inc.Metro Manila, PH

A pivotal aspect of this role involves striking a delicate balance between mitigating risks and enabling business activities.This equilibrium is achieved through a thorough examination of the impac... Show more

 • Promoted

IT Audit Section Head - Information Systems Audit

EastWest BankMakati, Metro Manila, Philippines
Quick Apply

IT Audit Section Head - Information Systems Audit.In this role you will assist the Department Head in developing, implementing, and monitoring the annual audit plan based on robust risk assessment,... Show more

Head of Application Policy Servicing

Prudential Hong Kong LimitedManila, Metro Manila, PH

Head of Application Policy ServicingApplylocations: Metro Manilatime type: Full timeposted on: Posted Todayjob requisition id: 26060070Prudential’s purpose is to be partners for every life and prot... Show more

 • Promoted

Director, Risk Strategy (Fraud & AML | Fiat + Crypto)

Coins.phTaguig, Metro Manila, PH

We are looking for an experienced Risk Strategy Leader to lead the design and execution of our end-to-end risk control framework across both fiat and crypto ecosystems.This role owns fraud preventi... Show more

 • Promoted

Head of Fraud and Risk

First CircleManila, Metro Manila, PH

First Circle is one of the fastest-growing FinTech companies in the country, providing financial services to under-served SMEs.We've already transformed access to credit for thousands of businesses... Show more

 • Promoted

Cloud Engineering Head

EastWest BankMakati, Metro Manila, Philippines
Quick Apply

Senior Assistant Vice President .Our Information Technology team is looking for experienced professionals to join us in Makati City with the role of Cloud Engineering Head.In this role, you wi... Show more

Technology Manager

Payreto Group.Makati, Metro Manila, PH

Professional Development Opportunities.The Technology Manager oversees and leads in providing solutions to helpdesk-related and web-related issues and concerns of the different facets of the Suppor... Show more

 • Promoted

Technology and Third-Party Risk Head

Cobden & Carter InternationalTaguig, Metro Manila, Philippines
Quick Apply

The Head, Technology & Third-Party Risk is responsible for establishing, implementing, and overseeing the Company's Technology Risk Management and Third-Party Risk Management frameworks.The rol... Show more

Unit Head

BDO UnibankMandaluyong, Metro Manila, PH

Select how often (in days) to receive an alert:.Mandaluyong City, National Capital Region, PH.Business Unit: Information Technology Group.Philippines’ leading full-service bank, offering a wide ran... Show more

 • Promoted

Associate – Technology Risk Consulting & IT Auditors (Multiple Roles)

HRTXMakati City, Metro Manila, Philippines
Quick Apply

Associate – Technology Risk Consulting.Associate – Technology Risk Consulting.In this role, you will support external client engagements focused on.IT governance, information security, cybersecurit... Show more

Head of Technology Strategy and Planning

Prudential Hong Kong LimitedManila, Metro Manila, PH

Head of Technology Strategy and PlanningApplylocations: Metro Manilatime type: Full timeposted on: Posted Todayjob requisition id: 26070085Prudential’s purpose is to be partners for every life and ... Show more