Assistant General Manager, IT Risk Control

5 days ago


Hong Kong Island, Hong Kong SAR China China CITIC Bank International Limited Full time

Lead and provide expertise to efficiently manage cyber and technology risks arising from our use of internal developed technology and 3rd party solutions. Establish/Revise and provide inputs to the design of the cyber and technology risk control framework. Drive the implementation of the cyber and technology risk control framework within 1st Line of Defense (e.g. NIST, ISO 27001). Drive initiatives to identify, measure, monitor and report on new and existing risk matters. Assist EDGM, Head of IT Risk Control & Governance in providing a focal point of managing cyber risk including the design of effective controls and the systematic monitoring of risks. Be a change agent and internal advisory by making risk management relevant to everyone in a clear and succinct manner as we seek to further embed control culture. Be open to change over time as we adapt to the every-changing control and regulatory landscape. Advise on and challenge control matters as needed from a 1.5 line of defense perspective. Follow through remediation on Cyber related incidents and risk matters; guide the containment and eradication phase of the incident when occurred. Collaborate with internal teams, establish incident response plan and communicate effectively amongst BU/SU stakeholders and IT management. Risk exception and acceptance must be well governed, timely validated and properly escalated. Be flexible and show resolution ideas in navigating complex regulatory challenges and deliverables. Establish and enforce Cybersecurity best practices e.g. NIST, SAN, IS , CSA. Perform regular risk assurance review on periodic basis to support 1LOD risk control objective. Make recommendation to ITG management on how to improve ITG overall control environment. Enforce control requirements to established Policies & Standards and provide advisory to internal teams on design controls (a shift left mindset) and be able to articulate the risk associated with ineffective IT system design and operations. Supervise junior member of the IT Risk Control & Governance team to ensure the above objectives are met. Requirements: Degree in Information Technology, Computer Science, or Engineering. 8-10 years' experience in Cybersecurity field including Security Operations, Security Architect, Risk Management, Data Security, Incident Response team etc. Experience in forming and leading Risk Management and/or Governance framework. Experience in Business Continuity/Disaster Recovery Management or Incident Management would be an advantage. Good experience in formulating IT processes and procedures. Cybersecurity experience is a definite advantage. Operational Risk Management experience is a definite advantage. Certified Information System Security Professional (CISSP) is a definite advantage. Certified Information Security Manager (CISM) is a definite advantage. Certified Information Systems Auditor (CISA) is a definite advantage. Certified Information Privacy Professional (CIPP) is an advantage. ITIL certification is an advantage. COBIT certified is an advantage. Personal data collected will be used for recruitment related purposes only. Applicants not invited for interview within 6 weeks may consider their applications unsuccessful. However, applicants may be considered for other suitable positions within the Group for a period of not more than 2 years. Personal data will be destroyed at any time after 3 months. China CITIC Bank International is committed to being an equal opportunities employer and intends to provide a work environment free of unlawful discrimination or harassment. All employment decisions will be made in a non-discriminatory manner. #J-18808-Ljbffr



  • Hong Kong Island, Hong Kong SAR China Manager, Operational and Technology Risk Full time

    Manager, Operational and Technology Risk Why Mox Everything at Mox – from our products, features, to rewards – is designed based on customer research, tailor made for your needs. We care about what customers care about, especially in data security and privacy. Data ethics is core to everyone here at Mox. Who are we looking for? The Mox Operational,...


  • Hong Kong Island, Hong Kong SAR China Manager, Operational and Technology Risk Full time

    A leading digital bank in Hong Kong is on the lookout for a Manager of Operational and Technology Risk. This role demands expertise in risk management, particularly operational and technology risks. The candidate will develop frameworks and collaborate with various stakeholders to ensure compliance with regulatory standards, oversee the risk-taking...


  • Hong Kong Island, Hong Kong SAR China China CITIC Bank International Limited Full time

    Assistant General Manager, Operational Risk Management Add expected salary to your profile for insights Key Responsibilities Responsible for the 2nd line of defense in operational risk related matters under 3 lines of defense model. Plan and lead operational risk projects, leveraging people, technology, data, business processes, and controls to address the...


  • Hong Kong Island, Hong Kong SAR China Dah Sing Bank Full time

    2 days ago Be among the first 25 applicants To support the risk management system and proper functioning of interest rate risk, liquidity risk, market risk reporting and stress testing Responsibilities Support the risk analysis/limit monitoring as well as regulatory reporting related to risk management (such as interest rate risk management, etc.); Monitor,...

  • Lead, FCC Control

    5 days ago


    Hong Kong Island, Hong Kong SAR China Lead, FCC Control Full time

    Why Mox Everything at Mox – from our products, features, to rewards – is designed based on customer research, tailor made for your needs. We care about what customers care about, especially in data security and privacy. Data ethics is core to everyone here at Mox. Mox rewards you with an array of banking and lifestyle benefits. Who says banking can’t...


  • Hong Kong Island, Hong Kong SAR China Classy Wheeler Limited Full time

    Client Description Our client, a listed general insurance company which covers Hong Kong and Macau area. To cope with business expansion, they are now urgently seeking an experienced Risk Management Manager to join their team Job Description Setting the vision and strategy for the enterprise risk management & function working in conjunction with all other...


  • Hong Kong Island, Hong Kong SAR China China CITIC Bank International Limited Full time

    A leading financial institution in Hong Kong seeks an Assistant General Manager for Operational Risk Management. This role involves overseeing the 2nd line of defense in operational risk matters, planning and leading projects, and developing risk policies. Candidates must have a Bachelor's degree in a related field and at least 12 years of experience in...


  • Hong Kong Island, Hong Kong SAR China HSBC Full time

    The Business Risk Manager reports to the Head of Business risk, Trust and Fiduciary Services (TFS). The primary function is to partner with the business, providing support to achieve growth aspirations whilst retaining the appropriate risk management discipline to achieve strategic goals. Business Risk Managers work closely with Risk Owners, Control Owners...


  • Hong Kong Island, Hong Kong SAR China The Career Works Full time

    Our client, a commercial bank, is looking to hire Manager – IT Risk & Governance. Responsibilities Support the implementation of a comprehensive Third Party Risk Management Framework within the IT function Conduct third party risk assessment for IT managed third parties Assist AGM of Control Assurance & Governance team in managing the lifecycle of control...

  • Assistant VP

    5 days ago


    Hong Kong, Hong Kong SAR China Citi Full time

    At Citi, we get to connect millions of people across hundreds of cities and countries every day. And we've been doing it for more than 200 years. We do this through our unparalleled global network. We provide a broad range of financial services and products to our clients - whether they be consumers, corporations, governments or institutions - to help them...