Technology and Operational Risk Manager
zhongan · 南区, 香港, 中国
About The Role
Responsibilities • Maintain corporate-wide technology & operational risk management, operational and cyber resilience policy and process in compliance with the regulator’s requirements; • As a second line of defense, assist risk owners in identifying and measuring risks to build a corporate-wide cyber, technology and operational risks profile; • Assist senior management in overseeing cyber, technology and operational risks by ensuring controls are properly designed, implemented and operated as intended, and ascertain the consistency of risk assignment; • Perform thematic review over bank technology & operational-related operations and provide advisory towards new products or services • Review residual risk level and control effectiveness to make recommendations for risk treatment; • Assist team head to interpret key risk statistics for reporting to senior management on regular basis; • Assist the coordination for evaluation on emerging cyber threat scenario for continuous improvement on cyber security response preparation for Business Continuity Management (BCM); • Promote security awareness and ensure compliance with applicable security standards; • Keep abreast of cyber threat trend to gauge the prevailing cyber threat landscape, and make recommendation on improving the bank risk posture; • Keep abreast of technological knowledge in managed area of responsibility, and provide recommendations for adaptation of new technologies and standard with reference to prevailing industry best practices; • Assist senior management overseeing the technology and operational related incident management; • Oversee the coordination and governance of New Product Committee (NPC) activities, including organizing meetings, maintaining centralized records of product/service approvals, tracking completion of the review, and ensuring documentation is properly archived for audit and independent review Requirement: • University degree preferably in information technology, information security or related discipline; • Minimum 5 years of experience in information security, technology risk management, operational risk management or IT Audit field; • Holder of cybersecurity/ operational risk certificates - CRISC, CISA, CISM, CISSP, AORP or other equivalent certificates is preferred; • Practical experience and knowledge in risk management framework and methodology; • Knowledge in control frameworks such as C-RAF, TM-E-1, TM-G-1, SA-2, OR-1, OR-2, TM-G-2 and relevant circulars published by the HKMA, SWIFT Customer Security Programme, PCI DSS, etc. are preferred; • Experience in working for major financial institutions; • Experience in project coordination and key stakeholder management and • A good team player with sound interpersonal and communication skills, good command of English language and proficiency in Mandarin. Mandatory Reference Checking Scheme Mandatory Reference Checking Scheme (MRC Scheme) may be applicable for certain relevant positions. It is a standardised reference-checking arrangement that is designed to support the integrity of "authorized institutions" regulated by the Hong Kong Monetary Authority (HKMA). Pursuant to the MRC scheme, our Bank will conduct a mandatory reference check by requesting information from each relevant former and current employer of applicants. For more details about the MRC Scheme, please visit the website of the Hong Kong Association of Banks: Applicants who are not invited for an interview within the 8 weeks after submission of application may assume their applications are unsuccessful. We may review applications received for suitability for other posts within the Company. All personal data provided will be treated in strict confidence and used strictly for recruitment-related purposes only. We shall retain the personal data of unsuccessful applicants for a period of 24 months upon receipt of such application.
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring