- Location
- Hong Kong
- Type
- Full-time
- Department
- Security
- Seniority
- VP
- Source
- Workday
Description
Mandatory Reference Checking Scheme (“MRC”) for Hong Kong
The Mandatory Reference Checking Scheme is a framework to facilitate Authorized Institutions (“AIs”) to bilaterally obtain reference information during their recruitment process for certain positions, such that misconduct information in an individual’s previous employments can be provided to AIs to inform their employment decisions.
For information related to MRC Scheme, “Frequently Asked Questions for In Scope Individuals” is published by HKAB/Industry Guidelines (https://www.hkab.org.hk/en/home) or further information will be available upon request, if it is applicable to the position(s) applied.
Country of Location:
China Hong KongJob Responsibilities:
Governance
• Assist to strengthen the 1st line of defense to improve oversight of cyber/technology risk and support the rapid Fintech development and transformation initiatives.
• Maintain and uphold the risk governance and management framework
• Assist to develop and maintain Information Security Policy and Cyber Security Strategy, associated standard and guidance pertaining to regulatory requirement and industry standard.
• Organize and facilitate the remediation actions to align with HKMA’s C-RAF 2.0 and iCAST requirement, including but not limited to conducting maturity assessment; adoption of intelligence sharing platform; and professional development.
• Ensure IT practices and controls are adequately developed to address information leakage risk.
• Assist to organize bank-wide awareness education program and necessary trainings to promote the security cultures of the Bank.
• Coordinate and respond to audit issues in relation to Cybersecurity to satisfy the compliance requirement.
• Assist the KRI reporting and review indicator when requested, support to provide materials for committee meetings.
Risk
• Perform risk assessment to ensure oversight of cyber/technology risk across domains of IT infra and security expertise
• Evaluate technology deviation and liaise with ITG teams of implementation process
• Liaise external 3rd party to conduct independent assessment.
Compliance
• Perform gap analysis on regulatory requirement including HKMA and MAS TRM associated guidance
• Provide input for inspections and examinations by the regulators, internal and external audits; handle information request and follow up IT related recommendations.
• Ad-hoc task or project assigned by management related to IT Security Governance.
Requirements: