About this role
WHO WE ARE:
As Singapore’s longest established bank, we have been dedicated to enabling individuals and businesses to achieve their aspirations since 1932. How? By taking the time to truly understand people. From there, we provide support, services, solutions, and career paths that meet their individual needs and desires.
Today, we’re on a journey of transformation. Leveraging technology and creativity to become a future-ready learning organisation. But for all that change, our strategic ambition is consistently clear and bold, which is to be Asia’s leading financial services partner for a sustainable future.
We invite you to build the bank of the future. Innovate the way we deliver financial services. Work in friendly, supportive teams. Build lasting value in your community. Help people grow their assets, business, and investments. Take your learning as far as you can. Or simply enjoy a vibrant, future-ready career.
Your Opportunity Starts Here.
Description: Group Operations and Technology (O&T) provides IT and backroom support across the Bank's business such as Group Consumer Financial Services, Group Corporate Banking, Global Treasury, and corporate functions, e.g., Group Risk Management, Group Finance, and Group Human Resources. It supports regional operations and drives resilience, service quality, productivity, and responsible technology adoption across Singapore, Malaysia, and other markets.
Group O&T Risk & Prevention (R&P) provides independent risk governance, oversight, and advisory support to Group Operations & Technology. The team promotes a strong risk and compliance culture, supports effective implementation of operational risk and regulatory requirements, and oversees the identification, escalation, and timely resolution of key risks and control issues.
Role Description: As Third-Party Risk Manager, the successful candidate will help shape and strengthen third-party and outsourcing risk governance across Group Operations & Technology. You will provide risk oversight, constructive challenge, and practical risk advisory support to Service Owners throughout the third-party lifecycle. This role will proactively identify and assess emerging risks, partnering with stakeholders to develop practical mitigation strategies and ensure risks are effectively managed.
In this role, you will partner with senior stakeholders across Technology, Operations, Procurement, Information Security, Legal, Compliance, Operational Risk, and Internal Audit in the different markets, to govern material outsourcing arrangements and critical third-party relationships. The successful candidate will be responsible for strengthening the division's third-party risk governance and ensuring that vendor engagements and outsourcing arrangements are managed in accordance with internal policies, MAS Guidelines on Outsourcing, MAS Notice 658, MAS Technology Risk Management (TRM) Guidelines, and other applicable regulatory requirements
This role provides an opportunity for the successful candidate to shape the third-party risk governance within a large regional Operations & Technology environment. The role entails collaboration with senior stakeholders across the region and various functions across the Bank. It offers valuable experience in regulatory requirements, outsourcing oversight, operational resilience, as well as emerging technology and cybersecurity risks.
Duties and Responsibilities:
• Governance and oversight of the vendor lifecycle, including onboarding, periodic reviews, renewals, and termination processes.
• Maintain vendor inventory, outsourcing registers, risk ratings, and vendor classification records.
• Monitor risk events, issues, audit findings, and remediation activities to ensure timely closure.
• Prepare risk dashboards, governance committee materials, management reports, and key risk indicators (KRIs).
• Support the implementation and continuous improvement of the bank’s TPRM and outsourcing governance frameworks, standards, and procedures within GO&T.
• Provide advisory support on MAS Guidelines on Outsourcing, MAS Notice 658, MAS TRM Guidelines, and internal TPRM requirements.
• Assist Service Owners in determining outsourcing applicability, materiality, and criticality in accordance with MAS requirements and internal policies.
• Review and challenge identified risks, control gaps, and mitigation plans to ensure appropriate risk management outcomes.
• Support audits, regulatory inspections, thematic reviews, and governance reviews relating to third party risk and outsourcing.
• Review technology and cybersecurity assessment outcomes for third-party providers and outsourcing arrangements.
• Assess vendor assurance reports and supporting documentation, including SOC reports, ISO certifications, and security assessments.
• Drive regional alignment and maturity uplift of third-party risk governance practices, including process simplification, control effectiveness, and consistent application of standards across O&T markets.
Key Outcomes / Success Measures
• Maintain robust oversight of material outsourcing and critical third-party arrangements to ensure regulatory and policy compliance.
• Work closely with Service Owners to promptly identify, assess, escalate, and resolve third-party risk issues, with effective tracking through to closure and sustainable resolution.
• Ensure consistent adoption and execution of Third-Party Risk Management (TPRM) standards, frameworks, and governance requirements across the region, promoting a strong and effective risk culture.
• Deliver clear, insightful, and actionable management reporting and governance committee updates, enabling informed decision-making and effective risk oversight.
• Provide advisory support, effective challenge, and decision-support to Service Owners and key stakeholders, strengthening risk management practices while supporting business objectives.
Pre-requisites (Knowledge/ Experience/ Skills) Required Experience:
• Strong working knowledge of regulatory requirements, such as MAS Guidelines on Outsourcing, MAS Notice 658, MAS TRM Guidelines, Third Party Risk Management frameworks & etc.
• Understanding of regional regulatory requirements is a plus.
• Experience assessing Material Outsourcing Arrangements and Critical Service Providers.
• Familiarity with operational resilience, recovery objectives, resilience testing, and concentration risk assessments.
• Experience reviewing and challenging independent assurance reports and certifications. Experience supporting Service Owners throughout the vendor lifecycle.
Preferred Experience:
• Prior working experience in a bank, insurance company, or other regulated financial institution.
• Hands-on experience operating in a First Line or 1.5 Line control function.
• Experience from Banking TPRM teams, Technology Risk teams, Cyber Risk teams, Big 4 Technology Risk practices, or Outsourcing Governance functions will be highly regarded.
Academic: A university degree in Business Administration, Technology, Cybersecurity, or a similar field, and at least 6–10+ years of experience in third party, operational, or technology risk management is required. Relevant certifications in Third Party Risk Management, Outsourcing Governance, Information Security, Technology Risk, or Risk Management are preferred.
What we offer:
Competitive base salary. A suite of holistic, flexible benefits to suit every lifestyle. Community initiatives. Industry-leading learning and professional development opportunities. Your wellbeing, growth and aspirations are every bit as cared for as the needs of our customers.