Point your AI agent at freehire and let it find you a job.

Get the CLI →

cncbinternational

NewBe an early applicant

Assistant Vice President, IT Security Governance

Posted Updated
Discussion

Mandatory Reference Checking Scheme (“MRC”) for Hong Kong

The Mandatory Reference Checking Scheme is a framework to facilitate Authorized Institutions (“AIs”) to bilaterally obtain reference information during their recruitment process for certain positions, such that misconduct information in an individual’s previous employments can be provided to AIs to inform their employment decisions.

For information related to MRC Scheme, “Frequently Asked Questions for In Scope Individuals” is published by HKAB/Industry Guidelines () or further information will be available upon request, if it is applicable to the position(s) applied.

Country of Location:

China Hong Kong

Job Responsibilities:

Governance
• Assist to strengthen the 1st line of defense to improve oversight of cyber/technology risk and support the rapid Fintech development and transformation initiatives.
• Maintain and uphold the risk governance and management framework
• Assist to develop and maintain Information Security Policy and Cyber Security Strategy, associated standard and guidance pertaining to regulatory requirement and industry standard.
• Organize and facilitate the remediation actions to align with HKMA’s C-RAF 2.0 and iCAST requirement, including but not limited to conducting maturity assessment; adoption of intelligence sharing platform; and professional development.
• Ensure IT practices and controls are adequately developed to address information leakage risk.
• Assist to organize bank-wide awareness education program and necessary trainings to promote the security cultures of the Bank.
• Coordinate and respond to audit issues in relation to Cybersecurity to satisfy the compliance requirement.
• Assist the KRI reporting and review indicator when requested, support to provide materials for committee meetings.
Risk
• Perform risk assessment to ensure oversight of cyber/technology risk across domains of IT infra and security expertise
• Evaluate technology deviation and liaise with ITG teams of implementation process
• Liaise external 3rd party to conduct independent assessment.
Compliance
• Perform gap analysis on regulatory requirement including HKMA and MAS TRM associated guidance
• Provide input for inspections and examinations by the regulators, internal and external audits; handle information request and follow up IT related recommendations.
• Ad-hoc task or project assigned by management related to IT Security Governance.

Requirements:

Skills

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available