Search by job, company or skills

Resilient Risk Management (Specialist)

5-7 Years
  • Posted 4 days ago
  • Be among the first 10 applicants

Job Description

Job Purpose:

To conduct operational risk management function for the life insurance business, covering IT risk and business continuity management (BCM), to ensure operational risks across the insurance value chain — underwriting, policy administration, claims, distribution are identified, assessed, monitored, and controlled within the Board-approved risk appetite, and in compliance with insurance regulatory requirements (e.g., OIC regulations, ERM/ORSA).

Key Responsibilities:

Operational Risk Management

  • Develop, implement, and maintain the operational risk management framework aligned with the company's ERM framework and ORSA (Own Risk and Solvency Assessment) process.
  • Facilitate Risk & Control Self-Assessments (RCSA) across insurance functions: underwriting, new business, policy servicing, claims, actuarial operations, bancassurance distribution, and investment back-office.
  • Design and monitor Key Risk Indicators (KRIs) such as claims processing errors, policy issuance turnaround breaches, mis-selling complaints and system downtime.
  • Manage the operational loss event database; investigate incidents (e.g., claims payment errors, premium collection failures, fraud events and system failure), perform root cause analysis, and track remediation
  • Monitor market conduct and mis-selling risk in coordination with Compliance, particularly for agency and bancassurance channels.
  • Prepare risk reports for the Risk Management Committee (RMC), Risk Oversight Committee of the Board, and regulatory submissions.

IT Risk

  • Oversee IT and cyber risk assessment for core insurance systems (policy administration, claims, agent portal, e-payment, customer-facing digital platforms)
  • Review IT risks in digital transformation initiatives (online sales platforms, e-KYC, AI/automation in underwriting and claims)
  • Assess third-party and cloud outsourcing risk, ensuring compliance with regulatory outsourcing notifications and requirements.
  • Coordinate with IT Security on cyber incident response, penetration testing and IT security follow-up, and IT control effectiveness.

Business Continuity Management (BCM)

  • Own and maintain the company's BCM framework, BCP, in line with ISO 22301 and insurance regulator BCM requirements.
  • Conduct Business Impact Analysis (BIA) prioritizing critical insurance services — claims payment, policy issuance, premium collection, call center, and policyholder services — and define RTO/RPO
  • Ensure continuity arrangements for critical outsourced services.
  • Plan and execute annual BCP/DR exercises including call tree tests, alternate site tests, and cyber crisis simulations; report results to the RMC
  • Serve as BCM coordinator during actual disruptions (floods, pandemics, cyber incidents, system outages)

Governance, Culture & Regulatory

  • Embed a three-lines-of-defense risk culture; deliver operational risk and BCM training to business units.
  • Act as key contact for OIC examinations, external audits, and internal audit reviews related to operational risk, IT risk, and BCM.

Qualifications:

  • Bachelor's degree or higher in Risk Management, Insurance, Actuarial Science, IT, Finance, or related field.
  • 5-7 years of experience in operational risk, IT risk, or BCM, preferably in life insurance, insurance, banking, or financial services.
  • Knowledge of insurance regulations and frameworks: OIC ERM/ORSA requirement.
  • Familiarity with standards: COSO, ISO 31000, ISO 22301 (BCM), ISO 2700 - Information Security Certifications an advantage: ISO 22301/27001, CBCI/AMBCI.
  • Strong analytical, report-writing, and presentation skills; able to communicate risk matters to senior management, committees, and regulators.
  • Good command of English (for communication with company joint venture.

More Info

Job Type:
Industry:
Function:
Employment Type:

Job ID: 151440257