- Location
- Hong Kong
- Type
- Full-time
- Department
- Finance
- Seniority
- VP
- Source
- Workday
Description
Mandatory Reference Checking Scheme (“MRC”) for Hong Kong
The Mandatory Reference Checking Scheme is a framework to facilitate Authorized Institutions (“AIs”) to bilaterally obtain reference information during their recruitment process for certain positions, such that misconduct information in an individual’s previous employments can be provided to AIs to inform their employment decisions.
For information related to MRC Scheme, “Frequently Asked Questions for In Scope Individuals” is published by HKAB/Industry Guidelines (https://www.hkab.org.hk/en/home) or further information will be available upon request, if it is applicable to the position(s) applied.
Country of Location:
China Hong KongJob Responsibilities:
The job holder acts as a second of defence (“2LoD”) and is responsible for providing oversight and challenges of technology risk management, cybersecurity risk management, and control effectiveness of first line of defence (“1LoD”). The job holder is also required to respond spontaneously to evolving business, environment, threats, and regulatory requirements.
- Assist to design, maintain and implement the technology risk management framework and ensure key industry standards such as ISO27001, NIST 800, and PCI-DSS are incorporated into the framework.
- Responsible for operational risk identification, response, monitoring, reporting and execution of operational risk framework by reviewing the adequacy of the implemented controls.
- Ensure 1LoD implementing appropriate controls to address identified technology risk, and provide oversights and challenges of 1LoD’s risk assessment and risk-taking activities.
- Provide risk stewardship with appropriate risk management advice to technology and business stakeholders.
- Support technology risk management activities including internal and external audits, new products proposals, project reviews, and regulatory returns and examinations such as C-RAF maturity assessment, iCAST exercise, TM-E-1 and TMG-1 ICA.
- Assist team head to implement the control assurance strategy, methodology, related policies, guidelines and tools in line with regulatory requirements and industrial best practices.
- Conduct assurance reviews on banking operations and IT risks and controls, including understanding relevant control designs, review scoping, control testing, and communication of findings with reviewee teams.
- Perform deep-dive reviews or investigation into OR incidents to identify the root cause(s), provide recommendations to address the control weakness and evaluate the effectiveness of the corrective and preventive actions applied.
- Assist team head in defining and reviewing Risk Appetite and Key Risk Indicators to measure and monitor technology and cybersecurity risk exposure.
- Ensure timely and accurate submission of regular MIS on control assurance related issues to senior management of the Bank.
- Participate in Committees and Meeting as member when required to provide oversights and challenges.
- Prepare the bank-wide awareness or education program to promote the technology and cybersecurity risk cultures in the Bank.
Requirements:
- Degree holder preferably in Information Technology, Information Systems, Risk Management, Computer Science, or other relevant discipline.
- 5 - 8 years of working experience in operational risk management, technology risk management, or information and cybersecurity risk management.
- Prior experience in performing assurance reviews and IT audits is preferrable.
- Knowledge of relevant regulatory requirements relating to Operational Risk Management in banking industry.
- Certified in CISSP, CISA, CISM, CRISC or other recognized certificate is a must.
- Self-motivated, independent and able to communicate effectively at all levels.
- Good command of written and spoken English and Chinese (including Putonghua).