Bank of China (Hong Kong)

Technology Risk Manager (Information Security Control Division)

Bank of China (Hong Kong)  •  Hong Kong, HK (Onsite)  •  4 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Roles and Responsibilities & Specific Requirements (Application Security):

  • Assist in reviewing IT initiatives and provide advisory from technology risk perspectives
  • Assist to establish and review policies, guidelines, procedures in application security area
  • Provide advisory and practical guidance to support technology risk and information security assessments, include vulnerability scanning, penetration test etc.
  • Conduct regular assessment on application security
  • Familiar with security testing tools e.g. Fortify, AppScan and Open Source Scanning tools, technologies on DevSecOps and industry good practice OWASP is preferable

Roles and Responsibilities & Specific Requirements (System Security):

  • Research and evaluate latest trend & technologies on information security and fintech area, such as FinTech, Artificial Intelligence, Big Data, Cloud Computing etc.
  • Conduct regular assessment on OS platform security & middleware software security
  • Plan and conduct security assessment in area of physical security (e.g.: data center security)
  • Assist to establish and review policies, guidelines, procedures in system security、physical security and fintech technology security area
  • Familiar with system platform operation and system architecture design is preferable

Roles and Responsibilities & Specific Requirements (Third-Party Security):

  • Drive security assessments of third-party vendor focusing on compliance with regulations, company policies, and internal controls.
  • Oversee information security risk management processes for onboarding and off-boarding of third-party vendor relationships.
  • Communicate to business units and cross-functional teams regarding third-party vendor risk issues and/or control gaps, and recommends remediation initiatives.
  • Provide awareness by conducting training on third-party vendor risk management framework.
  • Contribute to internal practice development initiatives and technology risk knowledge base
  • Stay informed about latest developments in third-party vendor risk management field.

Roles and Responsibilities & Specific Requirements (Information Security):

  • Assist senior manager to formulate and manage information security policies, standards and procedures.
  • Plan and conduct information security assessment and IT risk evaluation in area covering IT general controls, information asset management, access controls and endpoint security review, etc.
  • Plan and carry out various information security assurance activities, such as computer accounts re-certification.
  • Review the initiation of security configuration changes, such as access rules, data leakage prevention policies.
  • Co-operates with system administrators to deploy various information security controls or tools, and take lead to conduct appropriate remedial action on security incidents.
  • Act as a subject matter expert to assist business units and cross-functional teams in identifying and mitigating information security risks and/or control gaps, and recommends remediation initiatives.

General Job Requirements:

  • Degree holder in Computer Science or other degree majoring in Information Systems, or related discipline.
  • Over 4 years of experience in IT security, technology risk, risk management, compliance or IT audit function, gained from other sizable financial institutions
  • Holding at least one recognized professional qualification under HKMA enhanced competency framework such as CISA, CISSP, CRISC is preferable.
  • Familiar with HKMA TMG-1, TM-E-1, PCI-DSS, ISO 2700-series or other security risk management framework is an advantage
  • Good command of written and spoken English with Mandarin is preferable and
  • Good communication and interpersonal skills;
  • Flexibility in traveling.
  • Candidate with less experience will be considered as Assistant Manager.
Bank of China (Hong Kong)

About Bank of China (Hong Kong)

Bank of China (Hong Kong) Limited (“BOCHK”) is a leading commercial banking group in Hong Kong with strong market positions in all major businesses. We have the most extensive local branch network and diverse service platforms in Hong Kong, including more than 190 branches, 280 automated banking centres, efficient e-channels of over 1,000 self-service machines, as well as Internet and Mobile Banking services. We offer a comprehensive range of financial, investment and wealth management services to personal, corporate and institutional customers. To implement the overseas development strategy of BOC Group, we strive to drive our regional development by expanding our business in the Southeast Asian region. Our branches and subsidiaries have been extended to Southeast Asian countries such as Thailand, Malaysia, Vietnam, the Philippines, Indonesia, Cambodia, Laos and Brunei, with the provision of professional and high-quality financial services to local customers. We will also expedite our development into a top-class, full- service and internationalised regional bank.

BOCHK is one of the three note-issuing banks and the sole clearing bank for Renminbi (“RMB”) business in Hong Kong. With our strong RMB franchise, we are the first choice of customers in this business.Through the deep collaboration with our parent bank, BOC, we provide a full range of high-quality crossborder services to multinationals, cross-border customers, mainland enterprises going global, central banks and super-sovereign organisations.

BOC Hong Kong (Holdings) Limited, BOCHK’s holding company, is one of the largest listed companies on the main board of the Stock Exchange of Hong Kong, with stock code “2388” and ADR OTC Symbol “BHKLY”.

Industry
Finance & Insurance
Company Size
1,001-5,000 employees
Headquarters
, HK
Year Founded
Unknown
Website
bochk.com
Social Media