CoinsDo
Technology Risk & Regulatory Compliance Lead

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Role Overview
We are seeking an experienced Technology Risk & Regulatory Compliance Lead, to lead and coordinate our organisation's compliance with prevailing global Technology Risk, Cybersecurity and Cyber Hygiene regulations.
This is a global role suited to a professional who can articulate and operate confidently across both global ICT resilience requirements and technology risk supervisory framework in a Financial Services environment, translating regulatory obligations into practical, auditable controls across the organisation's technology, third-party, and operational risk landscape.
The successful candidate will act as the subject-matter authority on ICT/technology risk/cyber hygiene regulations, working closely with Compliance, Legal, Technology and Senior Management to build and maintain a defensible, regulator-ready technology risk and resilience program.
Key Responsibilities
Regulatory Compliance & Gap Assessment
- Define and lead on the organisation's compliance programme against DORA (Regulation (EU) 2022/2554), its associated Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS).
- Lead and maintain compliance against the MAS Technology Risk Management Guidelines and the MAS Notice on Cyber Hygiene and related Notices/Guidelines.
- Conduct periodic gap assessments mapping current technology, cybersecurity, and third-party risk controls against DORA's five pillars (ICT risk management, incident reporting, digital operational resilience testing, third-party risk management, information sharing) and MAS TRM domains.
- Track regulatory developments, technical standards updates, and supervisory expectations issued by the ESAs (EBA, ESMA, EIOPA), MAS and translate these into internal policy and control updates.
Policy, Framework & Documentation
- Draft, review, and maintain ICT risk management frameworks, technology risk policies, business continuity and disaster recovery (BCP/DR) documentation, and third-party/outsourcing risk policies aligned to DORA and MAS TRM.
- Develop and maintain the ICT Register of Information (RoI) required under DORA, and equivalent third-party/vendor risk registers required under MAS TRM and outsourcing guidelines.
- Prepare quarterly board and monthly management-level reporting MIs, risk registers, and compliance dashboards summarising technology risk posture, control effectiveness, and regulatory readiness.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Third-Party & ICT Risk Management
- Own the third-party/ICT service provider risk management lifecycle: due diligence, contractual clause review (including DORA-mandated contractual provisions), ongoing monitoring, concentration risk assessment, and exit strategy planning.
- Assess and classify critical/important ICT third-party providers in line with DORA and MAS outsourcing/TRM criticality criteria.
- Coordinate with procurement, legal, and vendor management teams to ensure new and existing technology contracts meet regulatory requirements.
Incident Management, Testing & Resilience
- Support the design and maintenance of ICT-related incident classification, escalation, and regulatory reporting processes consistent with DORA incident reporting timelines and MAS notification requirements.
- Coordinate digital operational resilience testing, including vulnerability assessments, scenario-based testing, and (where applicable) threat-led penetration testing (TLPT), working with Information Security and external testing providers.
- Support tabletop exercises, BCP/DR testing, and crisis simulation exercises to validate organisational resilience against ICT disruption.
Governance, Training & Stakeholder Engagement
- Act as the primary liaison with regulators, auditors, and examiners on technology risk and operational resilience matters, including preparation of regulatory submissions and responses to inspection findings.
- Design and deliver training and awareness programmes on DORA and MAS TRM obligations for technology, risk, compliance, and business stakeholders.
- Support committee reporting (Risk & Compliance Committee, ICT Risk Committee) with clear, decision-ready materials on technology risk exposure and remediation status.
- Partner with Technology, Compliance and Legal teams to embed regulatory requirements into day-to-day operational practice.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Key Qualifications & Experience
Education
- Bachelor's degree in Information Technology, Computer Science, Risk Management, Law, Finance, or a related discipline. A relevant postgraduate qualification is an advantage.
Experience
- Minimum 5-8 years of experience in technology risk management, IT audit, cybersecurity governance, or regulatory compliance within financial services, fintech, or payments industry.
- Demonstrated hands-on experience implementing or advising on DORA compliance programmes, including ICT risk frameworks, third-party risk management, and incident reporting obligations.
- Practical working knowledge of MAS Technology Risk Management Guidelines, the Notice on Cyber Hygiene, and MAS outsourcing requirements.
- Prior experience engaging directly with regulators (MAS, MFSA) on technology risk, audits, or examinations is highly preferred.
- Experience working with or advising cross-border financial institutions operating under both EU and Singapore regulatory regimes is a strong advantage.
Knowledge & Technical Skills
- Strong working knowledge of ICT risk management frameworks (e.g., NIST CSF, ISO/IEC 27001, COBIT) and how these map to DORA and MAS TRM control expectations.
- Familiarity with related EU regulatory frameworks (PSD2/PSD3, MiCA, GDPR) and Singapore frameworks (Payment Services Act, MAS Notices) to the extent they intersect with technology and operational risk.
- Understanding of ICT third-party/outsourcing risk management, cloud risk considerations, and vendor concentration risk assessment methodologies.
- Ability to interpret complex regulatory text and translate it into practical, implementable policies, controls, and reporting artefacts.
Certifications
- CISA, CRISC, CISM, CISSP, or equivalent technology risk/audit certification.
- Certificate in DORA compliance, ICT risk management, or operational resilience (e.g., from a recognised industry body) is an advantage.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location