
Risk & Compliance Senior Manager
- Regulatory Compliance
- AML
- Risk Management
- Risk Management Framework
- Penetration Testing
- CISA
- CRISC
- CISM
- CISSP
Joining Razer will place you on a global mission to revolutionize the way the world games. Razer isa place to do great work, offering you the opportunity to make an impact globally while working across a global team located across 5 continents. Razer is alsoa great place to work, providing you the unique, gamer-centric #LifeAtRazer experience that will put you in an accelerated growth, both personally and professionally.
Job Responsibilities :
The Senior Compliance & Risk Manager will be responsible for building and operating the regulatory compliance framework required to launch and sustain Bank of Thailand (BOT) regulated payment services in Thailand, ensuring full adherence to all license conditions, BOT notifications, AML/CFT requirements, and internal governance standards. The role also covers ongoing legal entity compliance, including management of the Foreign Business License (FBL) and the appointment and oversight of the Data Protection Officer (DPO) function under the PDPA. The role is further responsible for drafting, implementing, and enforcing compliance policies, procedures, and internal controls, and for delivering training and awareness programs for all relevant teams and employees.Role SummaryÂ
The Risk & IT Compliance Manageris responsible for overseeing technology risk management, IT regulatory compliance, information security governance, third-party risk management, business continuity, audit coordination, and regulatory engagement activities.The role is the accountable owner for the technology-related regulatory obligations. It is also the entity's single point of coordination for Bank of Thailand submissions,examinations and audits on technology matters.Ensuring that the organizationmaintains an effective risk and control environment,complies with applicable regulatory requirements, andoperates in a secure, resilient, and sustainable manner.Â
Â
Â
1. Technology Risk Management & GovernanceÂ
Develop andmaintain the organization's Technology Risk Management Framework.Â
Maintain the Technology Risk Register; conduct technology risk assessments andwhere required risk controlself-assessments.Â
Define, monitor, andreport Technology Key Risk Indicators (KRIs).Â
Track Technology Risk Remediation Plansthrough to closureandmonitor remediation progress, reportingprogress and overdue items.Â
Assess technology risks associated with new products, services, projects, and system changes.Â
Prepare and present technology risk reports to senior management, the RiskCommitteeand the Board.Â
Support the establishment and review of Technology Risk Appetite and Risk Tolerance statements. Â
Â
2. IT Regulatory Compliance & Technology GovernanceÂ
Monitor, analyze, and interpret applicable technology-related laws, regulations, and regulatory expectations.Â
Assess the impact of new regulatory requirements on the organization.Â
Conductcompliance gap assessments andidentify remediation actions.Â
Develop andmaintain the Technology Compliance Roadmap.Â
Review and enhance the IT Governance Framework, policies, and standards.Â
Coordinate compliance initiatives with Group/HQ stakeholders.Â
Prepare supporting evidence and documentation for regulatory reviews and inspections.Â
Â
3. Information Security,Cybersecurityand PCI DSSOversightÂ
Monitor compliance with Information Security policies, standards, and procedures.Â
Review Vulnerability Assessment and Penetration Testing (VA/PT) results.Â
Track security findings and remediation activities.Â
Assess the adequacy of security and cybersecurity controls.Â
Oversee the management of security incidents and cyber incidents.Â
Oversee data breach management and response activities.Â
Support Data Protection Impact Assessments (DPIA) and privacy risk assessments. Â
Manage andassist on PCI DSSannualrenewalassessment.Â
Â
4. Outsourcing & Third-Party Risk ManagementÂ
Assess risks associated with third-party service providers before onboarding.Â
Conduct periodic Vendor Risk Assessments.Â
Evaluate risks arising from cloud services and critical service providers.Â
Review service level agreements (SLAs) and control requirements.Â
Monitor remediation activities undertaken by vendors and service providers.Â
Report outsourcing and third-party risksto management.Â
Maintain outsourcing register for all TPSP.Â
Â
5. Business Continuity & Operational ResilienceÂ
Oversee the development and maintenance of the Business Continuity Plan (BCP) andDisaster Recovery Plan (DRP).Â
Facilitate and challenge theBusiness Impact Analysis (BIA),validate recovery timeobjectives against regulatory expectations and customer commitments.Â
ConductBCP/ DR testing at least annually or on material change, report on test outcomes and track remedial actions (whererequired).Â
Assess the operational resilience of critical business services, including dependencies on Group and third-party.Â
Â
6. Audit & Regulatory Examination ManagementÂ
Actas the primary coordinator for IT audits.Â
Coordinate activities with Internal Auditors and External Auditors.Â
Coordinate regulatory examinations and inspections.Â
Prepare andmaintain audit and compliance evidence.Â
Track audit findings and remediation plans.Â
Report remediation progress and audit status to management. Â
Â
7. Regulatory Reporting & Regulatory LiaisonÂ
Prepare andsubmitITregulatory reports withinrequired timelines.Â
Act as a liaison with regulators, government agencies, and external reviewers.Â
Support regulatory licensing and ongoing compliance requirements.Â
Track regulatory commitments and follow-up actions.Â
Prepare technology risk and compliance reports for management and governance committees.Â
Â
Â
Â
Pre-Requisites :
QualificationsÂ
Bachelor's Degree orMaster’s Degree in Information Technology, Computer Science, Information Security, Cybersecurity, Information Systems, Risk Management, ora related field.Â
Minimum 8-10 years of experience in Technology Risk, IT Compliance, IT Governance, Information Security, or IT Audit.Â
Experience within FinTech, Payment Service Providers (PSP),Acquiring Businesses, E-Wallets, Banking, or Financial Services environments.Â
Strong knowledge of Technology Risk Management, Operational Risk Management, and IT Control Frameworks.Â
Experience working with regulators, auditors, and external assessors.Â
Professional certification: CISA, CRISC, CISM, CISSP or equivalentpreferred.Â
Razer is proud to be an Equal Opportunity Employer. We believe that diverse teams drive better ideas, better products, and a stronger culture. We are committed to providing an inclusive, respectful, and fair workplace for every employee across all the countries we operate in. We do not discriminate on the basis of race, ethnicity, colour, nationality, ancestry, religion, age, sex, sexual orientation, gender identity or expression, disability, marital status, or any other characteristic protected under local laws. Where needed, we provide reasonable accommodations - including for disability or religious practices - to ensure every team member can perform and contribute at their best.
Are you game?
Risk & Compliance Senior Manager · Razer Merchant Services Sdn. Bhd.