Logo for GIC

VP/SVP, Risk & Controls Officer (Infrastructure), Technology Group

Role overview

Qualifications

  • Minimally 12 years for senior appointments or minimally 7 years for mid-level appointments in technology risk, IT controls, operational risk, or IT audit within financial services
  • Strong understanding of technology risk domains including data privacy, segregation-of-duties, and compliance requirements
  • Knowledge of control frameworks (e.g., COSO, COBIT) and operational risk methodologies (ORSA)
  • Degree in Information Systems, Computer Science, Finance, or a related field; relevant certifications (e.g., CISA, CRISC, CISSP) are advantageous

Responsibilities

  • Partner with infrastructure and data platform teams to identify, assess, and manage risks
  • Design and embed controls across the technology lifecycle
  • Support system resilience, disaster recovery, and service continuity frameworks
  • Act as a liaison between technology teams, IT risk management, and internal audit

About the company

GIC logo

GIC

Investment Management

Established in 1981 to manage Singapore's foreign reserves, we strive to achieve good long-term real returns on assets under our management to preserve and enhance the value of Singapore's reserves. We have investments in over 40 countries and are headquartered in Singapore, with 11 offices in key financial cities worldwide.

Company details

Company typeLarge
IndustryInvestment Management
Company size1001 - 5000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

 

 Location: Singapore

Job Function: Technology Group 

Job Type: Permanent

Req ID: 17425 

 

 

GIC is one of the world’s largest sovereign wealth funds. With over 2,000 employees across 11 locations around the world, we invest in more than 40 countries globally across asset classes and businesses. Working at GIC gives you exposure to an extraordinary network of the world’s industry leaders. As a leading global long-term investor, we Work at the Point of Impact for Singapore’s financial future, and the communities we invest in worldwide.

 

Technology Group
We experiment, design, and lead a 24×7 global business where we support core capabilities in asset management, trading, investment operations, and risk management. We deliver secure, reliable, and integrated solutions, and provide insights on new, and emerging technologies. 

 

Infrastructure & Cybersecurity Resilience (ICR)
We design, build, and secure the technology foundations that power GIC’s global investment operations. We aim to deliver resilient, scalable, and secure infrastructure that empowers our people and businesses to perform securely, efficiently, and effectively.

 

What impact can you make in this role?

We are seeking a Risk & Controls (R&C) professional to be embedded within the Technology function supporting investment and corporate business units. This role will be part of the R&C function which comprises team members driving R&C Strategy and Standards settings.

 

Operating within the First Line of Defence, this role partners with engineering, architecture, and platform teams to ensure technology risks are effectively managed and controls are embedded across systems and delivery processes. The role focuses on enabling secure, resilient, and well-governed platforms that support investment decision-making and operations.

 

What will you do as a VP/SVP Risk & Controls Officer (Infrastructure)?

Risk Identification & Assessment

  • Partner with infrastructure and data platform teams to identify, assess, and manage risks across data centre and network services; compute and storage services spanning cloud and on-premise environments; end-user computing, device management, inventory, and deployment services; and databases and data pipelines

  • Provide risk input into infrastructure and platform design, capacity planning, and major change initiatives, recognising these as foundational services supporting all technology solutions

  • Ensure preventative controls are applied consistently across all infrastructure services, working closely with each infrastructure domain

  • Contribute to risk assessments of AI foundation platforms within the broader infrastructure scope

  • Translate technical risks into clear business impact and mitigation actions, with attention to data integrity and lineage

 

Controls Design, Implementation & Monitoring

  • Design and embed controls across the technology lifecycle (SDLC, change management, access controls, data governance) within the domain

  • Ensure controls are integrated into delivery workflows (e.g., DevOps, CI/CD) and validate adherence to governance processes, evidenced by Key Control Indicators (KCIs)

  • Maintain and enhance Operational Risk Self-Assessments (ORSA), progressing toward evidence-based, continuous controls monitoring (CCM)

 

Operational Resilience & Incident Management

  • Support system resilience, disaster recovery, and service continuity frameworks

  • Contribute to incident and problem management: drive Root Cause Analysis (RCA) and manage Corrective and Preventive Actions (CAPA) to ensure control gaps are permanently fixed

  • Ensure timely closure of control gaps and sustainable remediation

 

Monitoring & Reporting

  • Develop and track Key Risk Indicators (KRIs) and Key Control Indicators (KCIs) for the domain

  • Produce risk dashboards and insights for senior stakeholders

  • Highlight emerging risks across systems, platforms, and dependencies

 

Compliance with Standards & Procedures

  • Adhere to, and provide feedback on, the standards and Standard Operating Procedures (SOPs) defined for the first line of defence

  • Support internal compliance checks against defined standards relevant to the domain

 

Audit & Third-Party Governance

  • Support internal and external audit engagements: collate and review control artefacts, and provide domain input to management responses

  • Support risk assessments and controls for vendors and service providers, ensuring appropriate oversight of outsourced technology services

 

Stakeholder Engagement

  • Act as a liaison between technology teams (first line), IT risk management (second line), and internal audit (third line)

  • Build strong relationships with engineering and platform teams

  • Promote a risk-aware culture while supporting delivery and innovation

 

What qualifications or skills should you possess in this role?

  • Minimally 12 years for senior appointments, or minimally 7 years for mid-level appointments, in technology risk, IT controls, operational risk, or IT audit within financial services; senior appointments also include team or workstream leadership

  • Experience working closely with technology or engineering teams supporting front-office, public or private markets, or corporate functions

  • Familiarity with one or more of the following is a strong plus: systems supporting trading, portfolio management, analytics or asset servicing; private assets, deal workflows or valuations; risk management, treasury or holdings platforms and their data flows; enterprise or corporate application landscapes (e.g., ERP, HCM)

  • Strong understanding of technology risk domains (access management, SDLC, cloud, data governance), including data privacy, segregation-of-duties, and compliance requirements in corporate systems, and of the elevated control expectations required of business-critical systems

  • Knowledge of control frameworks (e.g., COSO, COBIT) and operational risk methodologies (ORSA)

  • Ability to balance risk management with delivery priorities; strong stakeholder management and communication skills

  • Degree in Information Systems, Computer Science, Finance, or a related field; relevant certifications (e.g., CISA, CRISC, CISSP) are advantageous

 

Work at the Point of Impact
We need to be forward-looking to attract the right people to help us become the Leading Global Long-term Investor. Join our ambitious, agile, and diverse teams - be empowered to push boundaries and pursue innovative ideas, share your views, and be heard. Be anchored on our PRIME Values: Prudence, Respect, Integrity, Merit and Excellence, which guides us in how we make our day-to-day decisions. We strive to inspire. To make an impact. 

 

GIC is a Great Place to Work

At GIC, our offices are vibrant hubs for ideation, professional growth, and interpersonal connection.  At the same time, we believe that flexibility allows us to do our best work and be our best selves.  Thus, our teams come into the office four days per week to harness the benefits of in-person collaboration, but have the flexibility to choose which days they work from home and adjust this arrangement as situational needs arise. 

 

GIC is an equal opportunity employer 
As an employer, we passionately believe every individual brings with them unique diversity of thought and perspectives to meaningfully enrich perspectives of GIC teams to drive competitive performance. An inclusive environment yields exceptional contribution.

 

Learn more about our Technology Group here: 
https://gic.careers/group/technology-group/

 

 

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Risk Management Specialist Related jobs

Other jobs at GIC

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.