
Manager, Risk and Control
- Kuala Lumpur
- Permanent
- Full-time
- Conduct Testing of IT controls related to Group Technology Risk Management (GTRM) to evaluate control design and control operating effectiveness.
- Develop and execute test plans, test steps, and test procedures based on control objectives across Technology, Cybersecurity, Operations, Data, and Privacy domains.
- Use Artificial Intelligence, Automation and Machine Learning tools to design, develop and execute automated test steps to evaluate the effectiveness of IT controls & processes.
- Continuously monitor and improve automated testing processes to ensure efficiency, effectiveness and accuracy in GTRM Controls testing.
- Conduct walkthroughs, fieldwork, demo sessions, and meetings with group technology teams and Local Business Units (LBUs) to identify and understand the controls for testing.
- Document and Report testing activities, workpapers, including test plans, test scripts, test procedures, test results, findings, observations, and recommendations.
- Collaborate with IT, audit, and compliance teams to develop remediation plans for ensuring timely resolution of identified issues.
- Review and validate the implementation of corrective actions taken by management to ensure control effectiveness.
- Provide support during internal and external audits, including preparing and presenting control testing progress and results. Collaborate with internal and external stakeholders as and when required.
- Assist in the development and maintenance of the GTRM Controls Library.
- Stay updated on industry standards, best practices, and regulatory requirements related to IT controls testing, Artificial Intelligence, Automation and Machine Learning.
- 5 plus years of experience in IT control testing/IT auditing, with a focus on automation.
- Strong understanding of IT control frameworks such as NIST, ISO 27001, COBIT and regulatory requirements of IT SOX.
- Ability to work in a developing environment and willing to take on related tasks.
- Proficiency in designing and executing automated tests for IT controls.
- •Excellent analytical and problem-solving skills with strong communication skills.
- •Relevant certifications such as CISA, CRISC, CISSP, CISM are a plus.