Job offer

Head of IT Governance and Risk, Asia

The Head of IT Governance and Risk for Asia at Julius Baer in Singapore leads regional IT governance and risk management, including the development of control frameworks and ensuring regulatory compliance. The position requires at least 10 years of experience in IT risk management, as well as a deep understanding of modern technology landscapes and GRC processes.

GENERAL DESCRIPTION

  • IT Governance and Risk Management is a regional function in Asia responsible for technology governance across key pillars and for overseeing risk management. This function works to ensure that technology aligns with IT functions to support the value of the services. Primary responsibilities include risk management and compliance with applicable laws and regulations.

Tasks

  • Lead the design, implementation, and ongoing enhancement of the bank's enterprise IT and risk framework, including policies, standards, and procedures. Ensure the effectiveness of all key elements of the technology architecture.
  • Develop and enhance the effectiveness of the bank's IT controls for risk, access management, change management, incident/problem management, and patch management. Develop enhancements and controls to ensure they remain responsive as threats evolve, as the regulatory environment changes, and to incorporate lessons learned from audits, problems, and incidents.
  • Own and maintain the risk register. Ensure regular coordination with department heads regarding the delivery of the product.
  • Coordinate and escalate relevant IT risk processes within the risk framework—including technology, cybersecurity, compliance, and privacy—while also providing input to the governance framework in the capacity of the risk management function.
  • Develop and support the definition and implementation of effective key risk indicators (KRIs) on a regular basis to proactively identify risks and implement effective controls.
  • Liaise with risk auditors on key topics related to IT governance and risk where assessment activities are required to provide advice on identified risks and agree on remediation programs.
  • Liaise and coordinate IT risk activities with internal and external auditors during the follow-up process to ensure that remediation activities are completed and documented.
  • Work closely with Information Security Risk to ensure compliance with security and regulatory requirements, including PCI-DSS, and any related controls pertaining to the IT team in Asia Pacific.
  • Partner with key stakeholders in the Middle East and North Africa (MENA) across the three lines in Asia Pacific, ensuring consistent governance of IT risk and controls throughout the region.
  • Produce a clear report on data, trends, and risk indicators related to technology risk.
  • Coordinate IT key risk governance dashboards and provide support for IT risk management programs; identify risks and manage risk acceptance levels, including tracking risk remediation.
  • Ensure proactive engagement. Develop and strengthen relationships with operational resilience, risk management, and IT functions across Asia.
  • Lead testing of operational resilience and capabilities related to IT risk activities, including preparedness in the event of incidents.
  • Develop and operate the cybersecurity testing process to identify risks and strengthen controls and data protection globally.

Requirements

  • Ensure the ongoing onboarding of new staff into IT policies and procedures (to further strengthen their understanding of these policies and procedures and embed secure practices at a foundational level) and the delivery of targeted awareness training.
  • Demonstrate the ability to operate at the senior level, aligning senior stakeholders and departments, and driving change across functions.
  • An effective communicator with strong interpersonal and relationship management skills, and a proven track record of negotiating, building relationships, and engaging with and advising senior leadership—all of which help convey risks to the executive team, both verbally and in writing.
  • Experience supporting IT business processes and delivery models, demonstrating professionalism and a stakeholder-oriented approach, combined with business acumen.
  • At least 10 years of experience in IT governance, risk, and audit.
  • Excellent and in-depth understanding of technology risks and controls associated with modern cloud, hybrid, and on-premises systems and solutions.
  • A well-rounded, self-motivated individual seeking to make a difference in the banking industry.
  • Extensive experience in the risk domain, combined with a strong technological background.
  • A proactive and thoughtful problem solver—able to see both the big picture and the details.
  • Personnel with extensive experience in the risk domain who are familiar with the delivery of a large-scale program and capable of reporting on the issue.
  • Data acumen and the ability to analyze and report on data.
  • Strong domain knowledge of IT and security risks and the regulatory environment (GRC).
  • Responsible for developing IT risk assessments and operational resilience plans.

Job details

© 2025 House of Skills by skillaware. All rights reserved.
Our website uses cookies to make navigation easier for you and to analyze the use of the site. You can find more information in our privacy policy.