Jobs › Companies › FWD Group › Senior Manager, Technology Risk and Data Protection

About this Senior Manager, Technology Risk and Data Protection role at FWD Group

FWD Group · Onsite · Malaysia - KL Eco City

About FWD Group

FWD Group (1828.HK) is a pan-Asian life and health insurance business that serves approximately 40 million customers across 10 markets, including BRI Life in Indonesia. FWD’s customer-led and tech-enabled approach aims to deliver innovative propositions, easy-to-understand products and a simpler insurance experience. Established in 2013, the company operates in some of the fastest-growing insurance markets in the world with a vision of changing the way people feel about insurance. FWD Group is listed on the main board of the Hong Kong Stock Exchange under the stock code 1828.

For more information, please visit www.fwd.com


About FWD Takaful Berhad

FWD Takaful Berhad (“FWD Takaful”) is a takaful provider in Malaysia that offers family takaful services. FWD Takaful is licensed under the Islamic Financial Services Act 2013 and is regulated by Bank Negara Malaysia. FWD Takaful is a takaful business unit of FWD Group.


Visit https://www.fwd.com.my


Join us


We’re proud to be a company that encourages and nurtures fearless innovation in achieving our vision of changing the way people feel about takaful. Our teams come from a wide variety of industries and backgrounds because we value developing a truly diverse pool of talent that brings different perspectives and experiences. Our values – committed, innovative, proactive, open, and caring – define who we are and what we do as we work together to bring our vision to life, every single day.



KEY ACCOUNTABILITIES

 

 

Technology Risk Management

  • Support the CCGO and HOR in maintaining and enhancing the Company's Technology Risk Management Framework and Cyber Resilience Framework.
  • Provide independent second-line oversight and challenge on technology, cyber security and information security risks across the organisation.
  • Review and challenge technology risk assessments relating to new projects, system implementations, major system changes, cloud adoption, outsourcing arrangements and emerging technologies.
  • Facilitate technology-related Risk and Control Self-Assessments (RCSA), Key Risk Indicators (KRI) monitoring and issue management activities.
  • Monitor technology risk exposures, incidents, control weaknesses and remediation actions, escalating material concerns where appropriate.
  • Assess technology-related operational risk events and ensure root causes, corrective actions and lessons learned are appropriately identified and tracked.
  • Monitor emerging technology and cyber security threats, assessing their potential impact on the Company's risk profile.
  • Provide independent review and challenge over technology risk reporting submitted by the First Line.

3.2 Regulatory Compliance and Governance

  • Monitor compliance with BNM's Risk Management in Technology (RMiT) policy requirements and other applicable technology-related regulatory requirements.
  • Coordinate and oversee technology risk regulatory assessments, gap analyses and remediation programmes.
  • Support the maintenance of technology risk policies, standards and governance documents.
  • Provide risk input into outsourcing, cloud computing and third-party technology risk assessments.
  • Ensure technology risks are appropriately reflected within the Enterprise Risk Management framework and reporting processes

3.3 Data Protection Officer Responsibilities

  • Serve as the designated Data Protection Officer (DPO) for the Company.
  • Oversee the implementation and ongoing effectiveness of the Company's data protection and privacy framework.
  • Provide advice to business units on personal data protection requirements, privacy risks and data protection impact assessments.
  • Monitor compliance with applicable personal data protection laws, regulations
  • and internal policies.
  • Coordinate assessments and investigations of personal data incidents and breaches, including escalation and regulatory notification requirements where applicable.
  • Maintain oversight of privacy-related risks and remediation activities.
  • Prepare periodic management and Board reporting on data protection and privacy matters.

3.4 Reporting and Committee Support

  • Prepare technology risk, cyber risk and data protection reports for Management Committees, Board Committees, Group Office and regulators.
  • Support the preparation of risk dashboards, risk appetite monitoring and risk reporting.
  • Escalate material technology, cyber security and data protection issues through the appropriate governance channels.
  • Provide independent risk insights and recommendations to Management and Board Committees on technology and data protection matters.

3.5 Risk Culture and Advisory

  • Promote awareness and understanding of technology risk, cyber security and data protection risks across the organisation to promote a strong risk culture.
  • Provide risk advisory support to business and support functions on technology and data protection matters.


SECTION 4: GOVERNANCE & CONTROL

  • Maintain independence from day-to-day technology operations and technology decision-making activities.
  • Provide objective oversight, challenge and advice on technology, cyber security and data protection risks.
  • Support continuous enhancement of technology risk governance, cyber resilience and data protection practices across the organisation.

QUALIFICATIONS / EXPERIENCE

 

  • Bachelor's Degree in Information Technology, Computer Science, Information Security, Risk Management, Business, Finance or a related discipline.
  • Minimum 8 years' relevant experience in Technology Risk, Cyber Security, Information Security, IT Audit, Operational Risk, Data Protection or related risk management functions, preferably within the financial services industry.
  • Strong knowledge of technology risk management, cyber security, data protection and regulatory requirements, including BNM's Risk Management in Technology (RMiT) policy.
  • Experience engaging with regulators, auditors, senior management and cross-functional stakeholders with strong analytical and communication skills.
  • Professional certifications such as CRISC, CISA, CISSP, CISM, ISO 27001, CDPO or equivalent would be an advantage.
Ready to apply to FWD Group?
Apply to FWD Group

About FWD Group

FWD Group (1828.HK) is a pan-Asian life and health insurance business that serves approximately 40 million customers across 10 markets, including BRI Life in Indonesia.

See all jobs at FWD Group →

Similar jobs

Sign up for suggestions tailored to the jobs you open and the searches you save.

More jobs at FWD Group

See all jobs at FWD Group →

Apply now
🤖

Whoa — hold up

JobsRadar was built for real people having a rough time in their job search — not for automated requests. You're clicking way too fast and you're now temporarily blocked.

Come back later. If you're genuinely job hunting, we've got your back — just act like a human.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Get an edge on your job hunt.

Join our Telegram channel for the stuff that helps you land the role — salary benchmarks, the weekly market pulse, and new-feature drops. No spam, just signal.

Join the channel — it's free