Jobs and Careers
GI

SVP, Information & Technology Risk (Infrastructure, Security & Resilience Risk Oversight)

GIC Private Limited
SingaporeRemotefull_timeVerifiedPosted 20 Aug 2026

About the role

GIC is one of the world’s largest sovereign wealth funds. With over 2,000 employees across 11 locations around the world, we invest in more than 40 countries globally across asset classes and businesses. Working at GIC gives you exposure to an extraordinary network of the world’s industry leaders. As a leading global long-term investor, we Work at the Point of Impact for Singapore’s financial future, and the communities we invest in worldwide.

 

Risk and Performance Management Department (RPMD)
We work collaboratively across teams to help guard against blind spots and ensure that all relevant risks are considered and duly addressed.


Information & Technology Risk Management

You will be a part of a team that independently protects the firm’s information technology assets, including business data, from external threats and operational risks, while supporting the firm’s digitalisation journey in a secure manner.

 

What will you do as an SVP, Information & Technology Risk (Infrastructure, Security & Resilience Risk Oversight)?

As a Senior Vice President, Information & Technology Risk (Infrastructure, Security & Resilience Risk Oversight) in GIC, you will operate as part of the Second Line of Defence (2LOD), leading independent oversight, assurance, and challenge over technology and cyber risk management activities across GIC. The role reports to the Head of Second Line of Defence / Information & Technology Risk Management within the Chief Risk Officer organisation.

 

You will bring deep expertise in infrastructure, cloud, cybersecurity, and operational resilience risk. The role ensures that technology infrastructure, security, and resilience risks are effectively identified, assessed, and managed in alignment with GIC’s risk appetite, regulatory expectations, and industry best practices.

 

Key Responsibilities

 

Infrastructure & Cloud Risk Oversight

  • Provide independent oversight of risk management practices across the technology infrastructure estate, including data centres, compute, storage, networks, and end-user computing.
  • Review and challenge the design and operating effectiveness of controls over hybrid and multi-cloud platforms, including configuration management, workload isolation, and cloud entitlement management.
  • Assess infrastructure hygiene controls patching, hardening, asset and configuration management, capacity, and technology currency and challenge remediation of control gaps.
  • Evaluate risks arising from infrastructure change, platform migrations, and automation, ensuring appropriate governance and rollback controls.

 

Cybersecurity Risk Oversight

  • Provide independent oversight and challenge of the cybersecurity control environment, including identity and access management, privileged access, threat detection, and security operations (SOC).
  • Review and challenge vulnerability and threat management practices, including penetration testing, and remediation of critical exposures within agreed risk tolerances.
  • Assess the adequacy of security monitoring, logging, and incident detection capabilities against GIC’s threat profile.
  • Advise on emerging cyber risks, including ransomware, supply-chain compromise, and AI-enabled threats, and challenge the sufficiency of mitigating controls.

 

Technology & Operational Resilience Oversight

  • Provide independent oversight of technology and operational resilience arrangements, including availability management, disaster recovery, backup integrity, and cyber recovery capability.
  • Review and challenge the identification of critical business services, impact tolerances, and mapping of supporting technology dependencies.
  • Assess the scope, rigour, and outcomes of resilience and recovery testing, including scenario and severe-but-plausible testing, and challenge remediation of identified weaknesses.

 

Third-Party Technology Risk Oversight

  • Provide independent oversight of technology and cyber risk arising from third parties, including cloud service providers, managed service providers, and material outsourcing arrangements.
  • Review and challenge third-party due diligence, contractual control requirements, ongoing mo

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

GIC Private Limited

View company profile →