Technology Risk Manager

3 weeks ago


Hong Kong, Hong Kong SAR China The Bank of East Asia Full time

 

Position Summary

Responsible for the 2nd line of defense in technology risk related matters under 3 tiers of risk defensive model, to monitor and review the established control mechanisms and resources for execution in Head Office, China, overseas branches and significant subsidiaries in accordance with the Enterprise Risk Management (“ERM”) and Cybersecurity Fortification Initiative (“CFI”) frameworks. 


Responsibilities

  • Ensure that the technology risk management framework, policies and control procedures are adequately implemented
  • Regularly review the relevant policy and manual for users and IT staff
  • Ensure cyber risk management function is properly performed, e.g. cyber risk identification and assessment, protection and detection for cyber incident, review and report of significant discrepancies from cyber-related risk assessment 
  • Review and provide advice on products and system design, control procedures and risk indicators from technology risk perspectives
  • Provide advice for root cause analysis and remediation for incidents and issues identified
  • Maintain and monitor the risk profile on a regular basis
  • Review the risk control for third parties and cybersecurity
  • Review the risk controls for system resilience and recovery in support of operational resilience
  • Undertake the oversight of the Bank’s all branches and subsidiaries in the Group
  • Review project documents to ensure SDLC is being followed
  • Ensure regular trainings are provided to staff members and ensure continuing training and skill development for cyber security staff are in place
  • Comply with all applicable regulations, rules, codes, guidelines and standards set by regulators and the Bank, and carry out duties with high integrity


Requirements

  • University graduate, preferably major in Computer Science related subjects or equivalent
  • Possess certification in CISSP/CISA as required by Enhanced Competence Framework (“ECF”) issued by the HKMA
  • Ideally 8-12 years’ work experience in information security, technology risk, or IT audit
  • Sound knowledge in regulatory requirements related to information security in banking sector
  • Sound knowledge in cryptographic techniques, firewall/network, DLP, APT, DDoS, IAM (identity and access management), vulnerability management, Cloud, etc.
  • Familiar to regulatory requirements such as HKMA(TM-E-1, TM-G-1, TM-G-2, SA-2), MAS, PCI-DSS, SWIFT-CSCF etc.
  • Good communication skills and risk awareness
  • Strong analytical mindset; knowledge on artificial intelligence, data governance and controls is advantageous
  • Good command of both spoken and written English and Chinese, fluent in Putonghua is preferable. 



  • Hong Kong, Hong Kong SAR China China Construction Bank (Asia) Corporation Limited Full time

    Job Descriptions Manage Technology Risk Management processes to identify emerging or existing technology-related risks, measure impact, likelihood and direction of technology-related risks. Establish and review technology risk management policy, mechanism and tools of the Bank with reference to Head Office and regulatory requirements. Monitor first line of...

  • Vice President, Operational

    Found in: Talent HK C2 - 2 weeks ago


    Hong Kong, Hong Kong SAR China United Overseas Bank Full time

    Vice President, Operational & Technology Risk Management Posting Date: 13-May-2023 Location: Hong Kong (City Area), Hong Kong Company: UOB Hong Kong About UOB United Overseas Bank Limited (UOB) is a leading bank in Asia with a global network of more than 500 branches and offices in 19 countries and territories in Asia Pacific, Europe and...


  • Hong Kong, Hong Kong SAR China Bank Of China (Hong Kong) Limited Full time

    Responsibilities: Identify the existing and potential risk in IT operation, report the risk to supervisor and related parties in time, formulate the rectification plan and follow up. Implement effective detection and control measures to strengthen the production operation safety and effectiveness of IT Department Responsible for the communication and...

  • Global Technology Product Head, Risk

    Found in: Talent HK C2 - 2 weeks ago


    Hong Kong, Hong Kong SAR China Prudential plc Full time

    Prudential’s purpose is to be partners for every life and protectors for every future. Our purpose encourages everything we do by creating a culture in which diversity is celebrated and inclusion assured, for our people, customers, and partners. We provide a platform for our people to do their best work and make an impact to the business, and we support...

  • Risk Manager

    Found in: Talent HK C2 - 2 weeks ago


    Hong Kong, Hong Kong SAR China The Bank of East Asia Full time

    Responsibilities This is a role under the team of Risk Analytics & Governance Department. Maintain the risk data warehouse of the bank on user’s perspective. Organize and execute BAU Change Request Life cycle of the risk data warehouse. Handle data assessment requests, production issues and adhoc tasks raised from upstream systems and downstream...


  • Hong Kong, Hong Kong SAR China KPMG China Full time

    KPMG China provides multidisciplinary services from audit and tax to advisory, with a strong focus on serving our clients' needs and their industries. Not only do we have an overriding commitment to provide the highest quality services for our clients, but we also strive to become a responsible corporate citizen that has a positive impact on our environment...

  • Assistant, Technology Risk

    Found in: Talent HK C2 - 3 weeks ago


    Hong Kong, Hong Kong SAR China The Bank of East Asia Full time

    Responsibilities This is a role under the Technology Risk Management Section in the Risk Management Department Performtechnology risk profile and KRIs maintenance work Collect KRI data from Head Office, China Office, overseas branches and subsidiaries Assist in preparing risk monitoring reports Perform any ad hoc assistant tasks when necessary depdning...

  • Senior Consultant

    Found in: Talent HK C2 - 2 weeks ago


    Hong Kong, Hong Kong SAR China Sia Partners Full time

    Job description Due to our exceptional growth in Asia, we are looking for a Senior Consultant experienced in Technology Risk and Operational Resilience to join our team in Hong Kong. As a Senior Consultant, you will help to build our expertise and guarantee the quality of delivery to ensure market-leading practices for our Hong Kong office, taking...

  • Consultant Technology Risk Control And Governance

    Found in: Talent HK C2 - 2 weeks ago


    Hong Kong, Hong Kong SAR China Nityo Infotech Full time

    Consultant Technology Risk Control and Governance Experience Required 3 - 4 Years Industry Type IT Employment Type Permanent Location Hong Kong


  • Hong Kong, Hong Kong SAR China Hong Kong Exchanges and Clearing Limited Full time

    Company Introduction: We're home to Asia's most dynamic and vibrant capital markets. Connecting capital, ideas, inspiration and innovation for deeper, more diverse and liquid global capital markets; providing greater choice and opportunity for our customers, each and every day. HKEX is a purpose-driven company. Our commitment to the long-term development...

  • Tech Risk Manager

    Found in: Talent HK C2 - 2 weeks ago


    Hong Kong, Hong Kong SAR China IO TECH SOLUTIONS LIMITED Full time

    Duties & Responsibilities:Build strong relationship with other teams in technology, business and various corporate functions including second line Risk team to drive  improvement on technology risk,  governance processes and remediation programsRegulating group and business entity levels technology risks policies and standardsIdentify and manage...

  • VP, Technology Risk

    3 weeks ago


    Hong Kong, Hong Kong SAR China WilsonHCG Hong Kong Full time

    Responsibilities: Plan and execute periodic in-house and external red-team exercises, and oversee the implementation of rectification measures. Evaluate existing cyber defenses against MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) Framework. Plan and perform security tests regarding trading and clearing-related environment, systems,...

  • Risk Officer

    Found in: Talent HK C2 - 2 weeks ago


    Hong Kong, Hong Kong SAR China The Bank of East Asia Full time

    Responsibilities This role will be under the team of Risk Tech & Digitalization within the Risk Analytics & Governance Department. Participate in the development projects of Banking Return System on user’s perspective and liaise with Financial Control, IT and external vendors Gather data mapping requirements and translate into functional specifications...

  • Manager, Security Risk Management

    Found in: Talent HK C2 - 1 week ago


    Hong Kong, Hong Kong SAR China AXA Group Full time

    AXA Hong Kong (AXA HK) Security Team acts as a partner with AXA Hong Kong and Macau business to keep AXA and our customers data safe and ensure ongoing operational resilience. AXA HK Security Team develops and implements the security strategy, in line with Group and local direction and relevant legal and regulatory requirements; and provides governance and...

  • Consultant/Senior Consultant, Cyber Security

    Found in: Talent HK C2 - 6 days ago


    Hong Kong, Hong Kong SAR China KPMG China Full time

    KPMG China provides multidisciplinary services from audit and tax to advisory, with a strong focus on serving our clients' needs and their industries. Not only do we have an overriding commitment to provide the highest quality services for our clients, but we also strive to become a responsible corporate citizen that has a positive impact on our environment...

  • Technology and BCP Lead, Insurance company

    Found in: beBee jobs HK - 3 weeks ago


    Hong Kong, Central and Western District, Hong Kong SAR China Randstad Hong Kong Full time

    about the company.Market leading insurance companyabout the job.Develop and lead the IT security governance framework and risk portfolioConduct gap analyses on regulatory requirements and drive programs to address gapsLead and coordinate cybersecurity and compliance assessmentsDefine and monitor key risk indicators (KRIs) related to IT and technology risks,...

  • Tech Risk

    Found in: Talent HK C2 - 3 weeks ago


    Hong Kong, Hong Kong SAR China JPMorgan Chase & Co. Full time

    Join our team to play a pivotal role in mitigating tech risks and upholding operational excellence, driving innovation in risk management.  As a Tech Risk & Controls Manager in Cybersecurity & Tech Controls, you will be responsible for identifying, and mitigating compliance and operational risks in line with the firm's standards. You will also provide...

  • Risk Manager

    3 weeks ago


    Hong Kong, Hong Kong SAR China Bank Of China (Hong Kong) Limited Full time

    Job duties: Participate in the implementation/upgrading and testing of the treasury systems Perform product due diligence and provide quantitative support to the new treasury products Participate in improving market risk models and monitoring the related model risk Prepare market risk reports for senior management Requirements: Degree holder (Major in...

  • Financial Technology Intern

    Found in: Talent HK C2 - 3 weeks ago


    Hong Kong, Hong Kong SAR China TradingScreen Full time

    Financial Technology Intern at TS Imagine Hong Kong About the job   TS Imagine is looking for a Financial Services Intern/ Financial Data Intern to join our team!  You will work and collaborate with some of the world’s most elite financial institutions utilizing leading-edge technologies and innovation to solve complex business challenges in...

  • Technology Innovation Manager

    Found in: Talent HK C2 - 2 weeks ago


    Hong Kong, Hong Kong SAR China Sirius Partners Full time

    Strategy and Transformation: Identify and evaluate emerging technologies, trends, and industry developments. Plan, execute, and manage technology innovation projects, including resource allocation, budget management, and timeline supervision. Ensure projects are delivered on time, within budget, and meet quality standards Implementation: Oversee execution of...