VP-IT Risk Management
About this position
Responsibilities
• Oversee IT Risk and Data Risk Management by planning, supervising, and supporting activities to achieve unit objectives.
• Develop and implement IT Risk Management policies, procedures, guidelines, and tools to address IT risks, including data risk, cyber risk, IT third-party, and IT Project.
• Established track record of IT risk related incident investigation, including those involving fraud or non-compliance, and ensure appropriate mitigation.
• Collaborate with business units to align IT risk management, identify and evaluate IT and data risks and recommend control processes.
• Review, support, and provide recommendation on IT RCA (Risk and Control Assessment), ISO 27001, CRAF (Cyber Resilience Assessment Framework), and RLA (Risk Level Assessment) processes.
• Develop and execute supervisory stress testing for IT risks, ensuring alignment with regulatory requirements and assessing the organization’s ability to withstand adverse scenarios.
• Support Business Continuity Management (BCM) activities, including disaster recovery planning, testing, and alignment with organizational resilience strategies.
• Prepare and present IT risk management reports to management and external regulators as requested.
• Promote awareness and training in IT and data risk management across the organization.
• Stay updated on emerging IT risk management trends, tools, and technologies to strengthen organizational risk practices.
• Perform other duties or special projects assigned by the supervisor.
Requirements
• Master’s/Bachelor’s degree in related or equivalent domains, preferably in IT, Cybersecurity, Computer Science.
• 10+ years of experience in IT and Data Risk Management, with at least 3 years in a managerial role.
• Strong knowledge and experience in IT Risk Management, Data Risk, IT governance, IT 3rd Party, IT Project, ISO standard, Cybersecurity and related fields.
• Experience in developing and conducting supervisory stress testing and BCM activities.
• Experience in banking, financial services, or consulting firms is required.
• Familiarity and good knowledge with regulations (e.g., BOT IT Risk Management, BOT CRAF, PDPA, etc).
• Certifications such as CRISC, CISM, CISA, or CISSP are preferred.
• High awareness of emerging data protection tools, methodologies, and technology trends.
• Strong leadership, analytical, and communication skills.
• Proficiency in English and ability to handle multiple tasks effectively.