Vice President, OTCR, CISO & COO

Standard Chartered · Bangalore, IND · India

Vice President, OTCR, CISO & COO (India, Malaysia) senior · Risk & Compliance

Job Description Apply now Requisition Number: 60807 Job Location: Bangalore, IND Global Grade: Band 5 Work Type: Office Working Employment Type: Permanent Posting Start Date: 21/09/2026 Posting End Date: 07/10/2026 Job Description:

Job Summary

This role could be based in India and Malaysia. When you start the application process you will be presented with a drop down menu showing all countries, please ensure that you select a country where the role is based.

The Group Operational, Technology and Cybersecurity Risk (OTCR) organisation is instrumental in protecting and ensuring the resilience of Standard Chartered Bank’s data and IT systems by managing technological, information and cyber security (ICS) risks across the enterprise. 

As a critical function reporting into the Group Chief Risk Officer (CRO), Group OTCR serves as the second line of defence for assuring Operational, Technology and ICS controls are implemented effectively and in accordance with the Enterprise Risk Management Framework (ERMF) and the ICS Risk Type Framework, and for instilling a positive culture of Operational, Technology and Cybersecurity risk management within the Bank. 

As part of the function, the team of OTCR, CISO & COO performs a pivotal role as an extension of the OTCR  in supporting the Tech and ICS risk management strategy, governance, advisory and assurance roles that face off to the Client Businesses, Regions, and Functions. 

Strong technical knowledge in ICS controls domains – Identity and Access Management, Authentication Security, privilege Access Management and cloud IAM solutions.

Key Responsibilities

Strategy
• The Operational, Tech and Cybersecurity Risk Officer for Group Transformation, Technology & Operations (TTO) is a permanent strategic role that requires strong business acumen, deep knowledge and in-depth experience of Technology and Information and Cyber Security (ICS), particularly technical understanding of Authentication & Authorisation Security, Expertise in Privilege Access Management, Cloud IAM across multiple CSPs and hybrid identity integrations, exposure to UEBA and Zero Trust controls for Identity Security and Knowledge of identity-based attack techniques.
• The successful candidate will have a strong understanding of operating in a second line capacity within an ICS or risk management organisation, and can respond flexibly and collaboratively to evolving business, regulatory and threat requirements. This role within OTCR  for TTO CISO & COO will work with other OTCR Coverage and SME teams to address Tech and ICS as a principal risk types for the Bank and support its integration into the Bank's overall Enterprise Risk Management strategy. The role will provide oversight and challenge of Tech and ICS risk management and control effectiveness as a risk partner to TTO as defined in the Bank’s Enterprise Risk Management Framework (ERMF) and ICS Risk Type Framework under delegation from the Global Head of OTCR.

Business
• The role delivers services that continually monitor the Tech and ICS threat landscape, undertake constructive and robust oversight of the effectiveness of Tech and ICS controls and risk remediation strategies, and ensure accurate, insightful, and transparent Tech and ICS risk reporting is provided to senior management to provide them appropriate assurance and confidence on the TTO CISO & COO risk profile.

• We are seeking an information and cyber security risk specialist to deliver a range of activities associated with the discharging of OTCR second line responsibilities. This role will have considerable engagement with all business units, risk committees, and other stakeholders across the bank, but especially those in TTO covering Cyber Operations and Group Threat Management domains.  

Processes
The major functional activities that the OTCR, CISO & COO will lead and manage are:
• Overseeing and challenging 1st line Tech and ICS risk proposals and risk-taking activities for Identity and Access Management, Privilege Access Management ensuring least-privilege, segregation of duties, and zero trust principles.
• Ensures that privileged access risks are identified, assessed, and effectively mitigated across critical systems, cloud platforms, and enterprise applications.
• Intervening in 1st line activities if they are not in line with existing or adjusted Risk Appetite. 
• Monitoring of Tech and ICS risks and associated remediation plans across business lines using the Threat Scenario Risk Assessment (TSRA) Framework.
• Assuring the 1st line implements controls to comply with applicable laws and regulations as defined by the ICS Policy, Standards and escalate significant regulatory non-compliance matters and developments to the Global Head, OTCR TTO.
• Advise on emerging identity threats and assess adequacy of detection and response.
• Promoting a healthy Tech and ICS risk culture and good conduct within Transformation, Technology & Operations of key ICS domains.

People & Talent
• Lead through example and build the appropriate culture and values.
• Employ, engage, and retain high quality people, with succession planning for critical roles. 
• Uphold and reinforce the independence of the second line OTCR function. 
• Provide guidance and training for businesses and functions on managing risks associated with Cyber Operations and Group Threat Management domains.

Risk Management
• Support the assessment of Tech and ICS risk and reporting by TTO 1st line teams.
• Support the OTCR TTO team in the use of the Tech and ICS risk frameworks and other techniques from a 2nd line perspective.
• Raise visibility of Tech and ICS weaknesses to drive improvements and upliftment.
• Highlight gaps or control weaknesses against security standards and regulations in the key ICS domains.
• Create risk mitigation plans calling out where these are ineffective or insufficiently followed.
• Perform thematic reviews as required by the OTCR TTO team. 
Governance
• Work with teams within TTO and participate in work groups and other meetings to understand, advise, and challenge on Tech and ICS matters, specifically for Authentication and Authorisation Security. 
• Report any Tech and ICS risks/issues during T&O NFRC which require attention and support.
• Ensure consistency of reporting and production of high-quality documentation and materials.
• Provide recommendations and feedback to OTCR teams based on experience with TTO.

Regulatory & Business Conduct
• Display exemplary conduct and live by the Group’s Values and Code of Conduct. 
• Take personal responsibility for embedding the highest standards of ethics, including regulatory and business conduct, across Standard Chartered Bank. This includes understanding and ensuring compliance with, in letter and spirit, all applicable laws, regulations, guidelines and the Group Code of Conduct.
• Effectively and collaboratively identify, escalate, mitigate, and resolve risk, conduct and compliance matters.

Key stakeholders
• Group OTCR Leadership Team
• Group OTCR TTO Leadership Team
• Group TTO Risk Management and Cloud Governance Heads and teams
• Group CISO
• OTCR for Functions, Businesses and Regions 
• Other OTCR teams 
• Group Internal Audit 
• Identified business stakeholders

Other Responsibilities
• Perform other responsibilities assigned under Group, Country, Business or Functional policies and procedures within OTCR TTO covering other domains beyond main domains of responsibility. 

Skills and Experience

• Cyber Security frameworks, standards, and principles
• Identity and Access Management
• Authentication Security
• Privilege Access Management
• Cloud and Container Security 

Qualifications

• A degree in Information and Cyber Security or Technology or equivalent
• Minimum 10 years’ experience in information security or risk management, preferably in Banking and Financial sector, with at least 5 years hands-on experience in IAM protocols and standards (SAML, OAuth2, OIDC, LDAP, Kerberos, SCIM) and expertise in Privilege Identity Management platforms. Strong knowledge of MITRE ATT&CK, identity-based threat vectors and attack techniques.
• Strong knowledge of cybersecurity frameworks, standards and principles
• Strong knowledge of IAM security best practices and frameworks (e.g., CIS Benchmarks, NIST Cybersecurity Framework)
• Professional Certifications such as CISSP/CISM, CRISC, CCSK/CCSP are desirable
• Excellent written and oral communication and reporting skills in English, ability to present complex Cyber Operational and Threat Management concepts to non-technical stakeholders 

About Standard Chartered

We're an international bank, nimble enough to act, big enough for impact. For more than 170 years, we've worked to make a positive difference for our clients, communities, and each other. We question the status quo, love a challenge and enjoy finding new opportunities to grow and do better than before. If you're looking for a career with purpose and you want to work for a bank making a difference, we want to hear from you. You can count on us to celebrate your unique talents and we can't wait to see the talents you can bring us.

Our purpose, to drive commerce and prosperity through our unique diversity, together with our brand promise, to be here for good are achieved by how we each live our valued behaviours. When you work with us, you'll see how we value difference and advocate inclusion.

Together we:

What we offer

In line with our Fair Pay Charter, we offer a competitive salary and benefits to support your mental, physical, financial and social wellbeing.

Apply now Information at a Glance

Similar Jobs

Director, OTCR, Strategic & Emerging Risks (AI)Guangzhou, CHN Governance, Risk Management & ComplianceRequisition Number60874ChinaAssistant Vice President, OTCR, Stress TestingBangalore, IND Governance, Risk Management & ComplianceRequisition Number62093IndiaSpecialist, CRCTianjin, CHN OperationsRequisition Number58270ChinaDirector, 2LOD Quality Assurance and Improvement (Bangalore/Malaysia/Poland)Kuala Lumpur, MYS Governance, Risk Management & ComplianceRequisition Number56187Malaysia Job SkillsKey SkillsCyber SecurityGovernance Risk Management and ComplianceIdentity and Access ManagementIT Security StandardsIT Risk ManagementZero Trust Network AccessMitre Att&ckRelevant SkillsOffensive SecurityRisk AssessmentSecurity Assertion Markup Language (SAML)OpenIDInformation TechnologyUser AuthenticationElearningRisk ManagementEnterprise Software ApplicationsCommercial KnowledgeSelf MotivationRisk AppetiteCIS BenchmarksMental HealthCloud ComputingKnowledge of FinanceWriting of ReportsInnovationSegregation of DutiesOAuthGeographyContinuous TrainingLightweight Directory Access Protocols (LDAP)Risk AnalysisAuditing SkillsLeadershipCommunication SkillsRisk TakerSuccession PlanningConsultingKubernetes SecurityMitigating ControlPerseveranceSafety PrinciplesGovernanceTask ManagementKerberos (Protocol)Cyber WarfareBanking ServicesEnglishTechnical SkillsThreat ManagementAssertivenessMore

Skills Matching

Upload Your CVUse your CV to see how well your skills match up with this jobGet Started

Encuentra más ofertas como esta

Explora más ofertas activas de esta empresa o crea una cuenta en Insider Jobs para buscar, guardar y seguir oportunidades en todo el job board.