- Location
- TW01 - Taipei, Taiwan
- Type
- Full-time
- Department
- Legal
- Seniority
- Entry
- Education
- Bachelor
- Source
- Workday
Description
Summary
Neuberger is seeking a Taiwan-based Junior GRC (Governance, Risk, and Compliance) Analyst to join our Global Technology organization. This role is responsible for developing and leading efforts to maintain and improve the security posture of the Taiwan environment, interfacing with local regulatory bodies as required, and supporting broader APAC compliance efforts. This is a highly visible, client-facing role with regular interaction across business lines, including senior and executive leadership, throughout APAC.
The successful candidate must maintain appropriate segregation of duties between Information Security, Internal Audit, and operational IT functions. GRC oversight activities are performed independently from audit assurance and day-to-day operational control execution, with clear delineation of responsibilities to support regulatory compliance and FSC examination readiness.
Responsibilities
- Assist in the development, implementation, and maintenance of GRC policies and procedures aligned with the company’s business goals and legal requirements.
- Conduct risk assessments and support the identification of potential compliance and security risks.
- Monitor and report on compliance with internal policies and external regulations.
- Ensure regular reviews are performed to assist with refining company’s GRC policies, leveraging technology and industry best practices to drive efficiency.
- Serve as a trusted advisor to business and IT teams on information security and regulatory compliance matters for Taiwan.
- Collaborate with global and local teams to support internal and external regulatory requirements.
- Plan, coordinate, and complete official filing and closing drills in accordance with SITCA and other regulatory requirements.
- Lead and execute cybersecurity incident reporting drills, including scenario development, system walkthroughs, drill execution, and post-drill reporting.
- Track, coordinate, and ensure completion of SITCA-mandated annual IT training hours for applicable Taiwan office employees.
- Co-sign the Annual Statement on Internal Control.
- Maintain drill records, supporting evidence, and submission materials for regulatory review.
- Support SITCA surveys, such as AI risk assessments, by gathering input from relevant business and technology stakeholders.
- Own and lead the development, implementation, and maintenance of GRC and information security policies and procedures aligned with business objectives and legal requirements.
- Support implementation of the risk management framework and help ensure ongoing actions are completed in line with SITCA and other APAC regulatory requirements.
- Complete the mandatory 15 hours/year of InfoSec professional training.
- Stay current with emerging security and regulatory trends to provide forward-looking guidance.
- Create and maintain clear documentation for regulatory, audit, and internal governance purposes.
- Maintain a commitment to continuous learning and professional development.
Qualifications
- Regulatory Awareness: Familiarity with Taiwan financial services regulatory requirements — specifically FSC and SITCA information security obligations; working knowledge of Taiwan's Personal Data Protection Act (PDPA) and broader APAC financial sector security standards a plus.
- Frameworks & Governance: Working knowledge of industry-standard on the GRC principles, including risk assessment methodologies, policy development, and control monitoring.
This role offers close partnership with the business and exposure to nearly every area of the firm across technology, information security, and operations. Success requires a strong understanding of how information security enables business outcomes and supports the products and services that deliver value to clients.
Experience
- 3+ years of related IT experience, preferably within the financial services industry; exceptional candidates from other industries will also be considered.
- Demonstrated strong verbal and written communication skills in a professional corporate setting.
- Strong executive presence and a high-energy, proactive approach.
- Strong experience working with Taiwan regulatory requirements.
- Relevant experience in GRC, information security, or related function.
- Ability to work effectively in a collaborative team environment.
- Detail-oriented with strong organizational skills.
- Practical working experience in the SecOps function.
Qualifications and skills needed
- Bachelor's degree in Information Technology, Business Administration, Risk Management, or a related field.
- Basic understanding of GRC concepts and frameworks.
- Strong analytical and problem-solving skills.
- Project management and business analyst skills.
- Excellent written and verbal communication skills.
- Ability to work collaboratively in a team environment.
- Detail-oriented with strong organizational skills.
- Proficiency in Microsoft Office Suite (Word, Excel, PowerPoint).
- Excellent interpersonal and communication skills with strong English business and technical writing ability.
- Functional verbal and written communication skills in Chinese (Cantonese and/or Mandarin).
- Experienced in delivering technical/security training to diverse audiences.
Preferred Qualifications:
- Relevant internship or work experience in a GRC or related role.
- Familiarity with GRC tools and software.
Neuberger is an equal opportunity employer. The Firm and its affiliates do not discriminate in employment because of race, creed, national origin, religion, age, color, sex, marital status, sexual orientation, gender identity, disability, citizenship status or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact [email protected].
Learn about the Applicant Privacy Notice.