Job Location:
- Head Office, Phnom Penh
Main Duties and Responsibilities:
- Conduct technology and cybersecurity risk assessments to identify potential vulnerabilities, threats, control weaknesses, and emerging risks across the Bank.
- Develop, maintain, and enhance technology and cybersecurity risk management policies, frameworks, procedures.
- Establish and monitor Technology and Cyber Risk Key Risk Indicators (KRIs), risk appetite, risk thresholds, and risk reporting mechanisms to identify and escalate material risk exposures in a timely manner.
- Provide independent second-line oversight and challenge over technology and cybersecurity risk management activities.
- Collaborate with IT, Cybersecurity, Digital, Business Units, Compliance, Internal Audit, and other relevant functions to ensure effective identification, assessment, treatment, and monitoring of technology and cyber risks.
- Provide risk advice and oversight for new technology initiatives, projects, products, digital channels, system changes, and third-party technology arrangements.
- Provide training, guidance, and risk awareness to employees and relevant stakeholders on technology and cybersecurity risk management practices.
- Perform other tasks as required by management.
Key Selection Criteria and Qualification:
- Bachelor/Master’s degree in Information Technology, Computer Science, Cybersecurity, Information Security, Risk Management, Finance, or a related field.
- Minimum 7–10 years of relevant experience in technology risk, IT risk, cybersecurity, information security, IT audit, operational risk, or related areas.
- At least 3 years in a managerial or supervisory role, preferably within a bank, financial institution, or other highly regulated organization.
- Relevant certifications (CISSP, EEH, CISM, or GIAC) preferred.
- Expertise in SIEM, threat intelligence, incident response, and cybersecurity tools.
- Knowledge of compliance frameworks (ISO 27001, NIST, GDPR, PCI-DSS).
- Knowledge of banking regulatory requirements and technology/cyber risk expectations is highly desirable.
- Strong experience in developing or implementing Technology Risk Management Frameworks, Cyber Risk Management Frameworks, IT governance, risk assessment, and control frameworks.
- Good understanding of risk identification, assessment, treatment, monitoring, and reporting.
- Good at English speaking, writing and listening.
- Good personal characteristic, including soft, friendly and good communication skills and ability to work in a team spirit.
Interested candidates are requested to fill Employment Application Form and attach the relevant documents including 4X6 photos (01 sheet), family book, birth certificate, National ID card and other diplomas (photocopies only) to the Head Office in Phnom Penh, located at № 212, St. 271, Toul Tumpung 2, Chamkarmorn, Phnom Penh or by E-mail: recruitment@kbprasacbank.com.kh to Apply.
Note: For more information, please contact via phone: 023 962 062 / 081 233 697. Only shortlisted candidates will be contacted via phone for writing test or interview.
