Head of IT Risk

🗓️ Posted 2026-08-12 Bangkok City, Thailand Full-time Hybrid ICT

Company shared salary

NA

Market rate

THB 150,000–THB 250,000/mo (THB 1,800,000–THB 3,000,000/yr)

Based on similar roles (title + domain + location).

About the Company

Ascend Money is a leading fintech company providing innovative payment and financial services across 7 countries in the Southeast Asian Region. Established in 2013, Ascend Money became Thailand's first fintech unicorn in 2021. Its flagship service TrueMoney today has become the most popular digital financial application that enables ease of payments and convenient financial lifestyle. TrueMoney's extensive agent network as well as offline and online payment services also enable millions of users across the region to access innovative financial services, leading them to better lives. We seek person, who can working with a cross-functional team of technical and non-technical key stakeholders to effectively aggregate risk data to consistently drive decision-making, track risk mitigation, and strengthen our risk management program. Participate in the IT Risk and Control Self-Assessment (RCSA), IT Key Risk Indicators (KRIs) and Control Framework (CF) Review and maintain IT Risk Management Policy, and 3rd Party Risk Management Policy with related Standards, Guidelines, and Operating Procedures Provide IT Risk Advisory Service on IT projects in a manner to address the current risks and supervise the proper controls to mitigate risk by complying with internal and external regulations and laws.Also preparation reporting to internal meeting i.e.Committee , BOD Implementation of IT risk assessment, support to IT and business units to conduct IT related self-assessment such as IT project, Cloud, DLP, Mobile Digital applications project, or related projects. Measure process or control IT risk to inform business/product and program level IT risk assessment. Recommendations to related team on opportunities for risk mitigation based on established risk tolerance. Building and maintaining strong and positive working relationships and effective means of communication with other risk associates, including the IT Risk Management, Operational Risk Management, and

Requirements

  • 5+ years of IT Risk Management experience in banking, payment company or a related industry.
  • Bachelor's degree in Information Technology, Computer Engineering, Management Information Systems, Computer Science or related field.
  • Knowledge skill: IT Risk management, IT security standard, Mobile Security Testing Guide (MSTG), business risk analysis and making complex business/risk trade-off recommendations and decisions.
  • Good knowledge and understanding in regulations and international standards such as ISO27001, ISO31000, COBIT 5 for Risk, etc.
  • Certified in Risk and Information System Control (CRISC), ISO27001 ISMS Lead Auditor IRCA, ISO27001 ISMS Lead Implementer, is an advantage.
  • Good consulting skills can work under pressure or manage multiple assignments simultaneously to provide deliverables on time.
  • Experience developing and refining technical or mobile digital developer or business operational processes.
  • Ability to communicate clearly with technical and non-technical teams across multiple businesses; written, verbal, presentation, and interpersonal skills.
  • Effectively manage multiple projects and priorities in a fast-paced, deadline-driven environment.
  • Works effectively as an individual and part of a team.
  • Strategic thinker with the ability to see/understand the big picture.
  • Manger level, Written and verbal English skill
  • Leadership, teamwork and collaboration skills.
  • Track record for being detail-oriented with a demonstrated ability to self-motivate and follow-through on projects.
  • Ability to solve problems and bring clarity to ambiguous situations.
  • Analytical and quantitative skills to use hard data and metrics to back up assumptions and develop business cases.