Back to all jobs
S

AVP, Technology Governance & Control Specialist

Sumitomo Mitsui Banking Corporation

sg 2h ago

Job description

The Technology Governance & Control Team (TGCT), under the Security Architecture Group (SAG) at SMBC Singapore, is responsible for driving technology governance, control oversight, regulatory readiness, and continuous improvement across key technology management domains. Working closely with technology, business, risk, compliance, and audit stakeholders, the team supports governance functions including Identity & Access Management (IAM), IT Service Management (ITSM), System Development Life Cycle (SDLC), technology operations governance, and management reporting. TGCT plays an important role in strengthening the Bank's control environment, operational resilience, and alignment with regulatory and industry best practices. The Technology Governance & Control Specialist (AVP) is responsible for strengthening governance, control effectiveness, regulatory compliance, and operational excellence across key technology management domains within the Bank. The role will support and enhance governance frameworks covering Information Technology Service Management (ITSM), System Development Life Cycle (SDLC), Identity & Access Management (IAM), Privileged Access Management (PAM), Non-Human Identity (NHI) governance, technology operations, and related control functions. Working closely with business stakeholders, technology teams, Risk Management, Compliance, Audit, and regional branches, the incumbent will drive process standardization, governance maturity improvements, control transformation initiatives, management reporting, and regulatory readiness activities. This position plays a key role in supporting the Bank's technology governance agenda through effective oversight, continuous improvement, and delivery of strategic governance initiatives across the APAC region. Key Responsibilities Technology Governance & Control Oversight Support governance and control oversight across key technology management domains, including: Identity & Access Management (IAM) Privileged Access Management (PAM) Non-Human Identity (NHI) Governance IT Service Management (ITSM) System Development Life Cycle (SDLC) Technology Operations and Support Functions Monitor control effectiveness and identify improvement opportunities to strengthen operational resilience and risk management. Support implementation and maintenance of governance frameworks, standards, policies, and procedures. IAM Governance & Control Management Drive governance over end-user identities, privileged identities, and non-human identities across the technology environment. Enhance controls covering: User provisioning Access modification Access revocation Access recertification Segregation of duties Privileged access governance Joiner-Mover-Leaver processes Support continuous improvement of IAM operating models, governance frameworks, and control processes. Collaborate with technology teams to improve identity lifecycle management and access governance capabilities. Audit, Risk & Regulatory Management Strengthen technology governance practices to support audit and regulatory compliance requirements. Coordinate and support responses to internal audit, external audit, regulatory examinations, and risk assessments. Track remediation activities and drive closure of identified control gaps. Ensure governance processes remain aligned with applicable regulatory, corporate, and internal policy requirements. Governance Reporting & Data Analytics Develop and maintain governance dashboards, management reports, KPIs, KRIs, and performance metrics. Analyse governance and control data to identify trends, risks, process inefficiencies, and improvement opportunities. Present management insights and recommendations to senior stakeholders. Enhance reporting automation and data quality to support effective decision-making. Process Improvement & Transformation Lead and coordinate governance-related improvement initiatives to increase process maturity, efficiency, and control effectiveness. Drive standardization, documentation, and optimization of governance and operational processes. Identify opportunities for automation and digitization to improve service quality and governance outcomes. Support implementation of strategic technology governance and control transformation programmes. Stakeholder & Regional Engagement Partner with technology teams, branch stakeholders, and regional governance representatives to drive governance adoption and control compliance. Facilitate governance forums, workshops, and stakeholder engagements. Provide governance advisory support to project teams and operational functions. Promote awareness of governance standards, policies, and control requirements across the organization. Skills & Experience Required Essential Minimum 7-10 years of experience in Technology Governance, IAM, Information Security, Technology Risk, IT Controls, ITSM, or related disciplines. Strong understanding of: IT Governance and Control Frameworks Technology Risk Management KPI/KRI Design and Governance Reporting Identity & Access Management (IAM) Identity Governance & Administration (IGA) Privileged Access Management (PAM) Non-Human Identity (NHI) Management Identity Lifecycle Management Access Certification & Recertification Experience driving governance, control enhancement, process improvement, or transformation initiatives. Experience engaging with Risk, Compliance, Audit, and technology stakeholders. Strong analytical, problem-solving, presentation, and communication skills. Ability to manage multiple initiatives and work effectively in a dynamic environment. Preferred Experience within banking, financial services, or other highly regulated industries. Familiarity with industry frameworks and standards, including: COBIT ITIL NIST ISO 27001 Regulatory technology risk requirements Exposure to IAM, IGA, PAM, ITSM, or workflow automation platforms. Understanding of cloud identity governance, directory services, and enterprise application onboarding processes. Experience supporting regional or multi-country governance programmes. Qualifications Bachelor's Degree in Information Technology, Information Security, Computer Science, Engineering, Business Information Systems, or related discipline. Relevant professional certifications will be an advantage, including: CISSP CISM CRISC CGEIT ITIL IAM / IGA / PAM Certifications Work Location One@ChangiCity

Similar open jobs