VP, Information & Technology Risk Manager (Data & Applications Risk Oversight)
GIC Private Limited · Singapore, SG · On-site
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
GIC is one of the world’s largest sovereign wealth funds. With over 2,000 employees across 11 locations around the world, we invest in more than 40 countries globally across asset classes and businesses. Working at GIC gives you exposure to an extraordinary network of the world’s industry leaders. As a leading global long-term investor, we Work at the Point of Impact for Singapore’s financial future, and the communities we invest in worldwide.
Risk and Performance Management Department (RPMD) We work collaboratively across teams to help guard against blind spots and ensure that all relevant risks are considered and duly addressed.
Information & Technology Risk Management
You will be a part of a team that independently protects the firm’s information technology assets, including business data, from external threats and operational risks, while supporting the firm’s digitalisation journey in a secure manner.
What will you do as an VP, Information & Technology Risk Manager?
As an Information & Technology Risk Manager (Data & Applications Risk Oversight) in GIC, you will operate as part of the Second Line of Defence (2LOD), providing independent oversight, assurance, and challenge over technology risk management activities across GIC.
You will bring deep expertise in technology risk management, with a focus on data security, application security, and technology control effectiveness. The role ensures that data and application-related risks are effectively identified, assessed, and managed in alignment with GIC’s risk appetite, regulatory expectations, and industry best practices.
Data Risk Oversight
Provide independent oversight of data risk management practices, ensuring effective governance across data lifecycle activities including data acquisition, storage, processing, and usage.
Review and challenge data management controls covering data quality, classification, retention, and protection.
Assess the adequacy of data security measures, including encryption, access management, and data loss prevention.
Evaluate compliance with data-related regulatory requirements and internal policies (e.g., data privacy, cross-border data transfer, and data ethics).
Partner with data security and architecture teams to strengthen enterprise data management frameworks and control standards.
Applications Risk Oversight
Oversee application risk management activities, focusing on control design and effectiveness across the software development lifecycle (SDLC) and production environments.
Review and challenge application security controls, including secure coding, vulnerability management, and change management processes.
Assess the adequacy of controls for critical business applications, ensuring resilience, integrity, and availability.
Evaluate risks arising from application integrations, APIs, and data interfaces, ensuring appropriate segregation of duties and access controls.
Support the…