Razer (US HQ) · Singapore
Finance & Legal
Joining Razer will place you on a global mission to revolutionize the way the world games. Razer is a place to do great work, offering you the opportunity to make an impact globally while working across a global team located across 5 continents. Razer is also a great place to work, providing you the unique, gamer-centric #LifeAtRazer experience that will put you in an accelerated growth, both personally and professionally.
Role Summary
The Risk & IT Compliance Manager is responsible for overseeing technology risk management, IT regulatory compliance, information security governance, third-party risk management, business continuity, audit coordination, and regulatory engagement activities. The role is the accountable owner for the technology-related regulatory obligations. It is also the entity's single point of coordination for Bank of Thailand submissions, examinations and audits on technology matters. Ensuring that the organization maintains an effective risk and control environment, complies with applicable regulatory requirements, and operates in a secure, resilient, and sustainable manner.
1. Technology Risk Management & Governance
Develop and maintain the organization's Technology Risk Management Framework.
Maintain the Technology Risk Register; conduct technology risk assessments and where required risk control self-assessments.
Define, monitor, and report Technology Key Risk Indicators (KRIs).
Track Technology Risk Remediation Plans through to closure and monitor remediation progress, reporting progress and overdue items.
Assess technology risks associated with new products, services, projects, and system changes.
Prepare and present technology risk reports to senior management, the Risk Committee and the Board.
Support the establishment and review of Technology Risk Appetite and Risk Tolerance statements.
2. IT Regulatory Compliance & Technology Governance
Monitor, analyze, and interpret applicable technology-related laws, regulations, and regulatory expectations.
Assess the impact of new regulatory requirements on the organization.
Conduct compliance gap assessments and identify remediation actions.
Develop and maintain the Technology Compliance Roadmap.
Review and enhance the IT Governance Framework, policies, and standards.
Coordinate compliance initiatives with Group/HQ stakeholders.
Prepare supporting evidence and documentation for regulatory reviews and inspections.
3. Information Security, Cybersecurity and PCI DSS Oversight
Monitor compliance with Information Security policies, standards, and procedures.
Review Vulnerability Assessment and Penetration Testing (VA/PT) results.
Track security findings and remediation activities.
Assess the adequacy of security and cybersecurity controls.
Oversee the management of security incidents and cyber incidents.
Oversee data breach management and response activities.
Support Data Protection Impact Assessments (DPIA) and privacy risk assessments.
Manage and assist on PCI DSS annual renewal assessment.
4. Outsourcing & Third-Party Risk Management
Assess risks associated with third-party service providers before onboarding.
Conduct periodic Vendor Risk Assessments.
Evaluate risks arising from cloud services and critical service providers.
Review service level agreements (SLAs) and control requirements.
Monitor remediation activities undertaken by vendors and service providers.
Report outsourcing and third-party risks to management.
Maintain outsourcing register for all TPSP.
5. Business Continuity & Operational Resilience
Oversee the development and maintenance of the Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP).
Facilitate and challenge the Business Impact Analysis (BIA), validate recovery time objectives against regulatory expectations and customer commitments.
Conduct BCP / DR testing at least annually or on material change, report on test outcomes and track remedial actions (where required).
Assess the operational resilience of critical business services, including dependencies on Group and third-party.
6. Audit & Regulatory Examination Management
Act as the primary coordinator for IT audits.
Coordinate activities with Internal Auditors and External Auditors.
Coordinate regulatory examinations and inspections.
Prepare and maintain audit and compliance evidence.
Track audit findings and remediation plans.
Report remediation progress and audit status to management.
7. Regulatory Reporting & Regulatory Liaison
Prepare and submit IT regulatory reports within required timelines.
Act as a liaison with regulators, government agencies, and external reviewers.
Support regulatory licensing and ongoing compliance requirements.
Track regulatory commitments and follow-up actions.
Prepare technology risk and compliance reports for management and governance committees.
Qualifications
Bachelor's Degree or Master’s Degree in Information Technology, Computer Science, Information Security, Cybersecurity, Information Systems, Risk Management, or a related field.
Minimum 8-10 years of experience in Technology Risk, IT Compliance, IT Governance, Information Security, or IT Audit.
Experience within FinTech, Payment Service Providers (PSP), Acquiring Businesses, E-Wallets, Banking, or Financial Services environments.
Strong knowledge of Technology Risk Management, Operational Risk Management, and IT Control Frameworks.
Experience working with regulators, auditors, and external assessors.
Professional certification: CISA, CRISC, CISM, CISSP or equivalent preferred.
Razer is proud to be an Equal Opportunity Employer. We believe that diverse teams drive better ideas, better products, and a stronger culture. We are committed to providing an inclusive, respectful, and fair workplace for every employee across all the countries we operate in. We do not discriminate on the basis of race, ethnicity, colour, nationality, ancestry, religion, age, sex, sexual orientation, gender identity or expression, disability, marital status, or any other characteristic protected under local laws. Where needed, we provide reasonable accommodations - including for disability or religious practices - to ensure every team member can perform and contribute at their best.
Are you game?