Assistant Manager to SM, Technology Risk
Il y a 22 heures
Brussels, Brussels-Capital, Belgique
Industrial and Commercial Bank of China
Temps plein
Gratuit avec email ou Google
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Gratuit avec email ou Google
Industrial and Commercial Bank of China (Asia) Limited (“ICBC (Asia)”) is the flagship of overseas business of Industrial and Commercial Bank of China Limited (“ICBC”) – currently the largest commercial bank in China, and it is one of the domestic systemically important banks (D-SIBs) in Hong Kong. Currently, ICBC (Asia) has 52 retail outlets (including 27 “Elite Club” Wealth Management Centres) in Hong Kong. It is engaged in commercial banking, investment banking and other financial services, including those of securities, insurance and funds, with a focus on commercial and retail banking as well as global market business. Chinese Mercantile Bank and ICBC Asset Management (Global) Company Limited, two wholly-owned subsidiaries of ICBC (Asia), specialize in Renminbi services in mainland China and ICBC’s global asset management business respectively.
Job Responsibilities
Perform the technology risk management process which identifies, measures, monitors and controls technology-related risks of existing/new systems, processes and initiatives
Ensure awareness of, and compliance with, the Bank's IT control policies, and to provide report with recommendations, if any, after investigation of any technology-related incidents
Implement risk issue management procedures for assuring the required policies and guidelines are enforced in daily operation
Recommend and implement remedial actions and control measures
Plan and work with the technology team and any concerning parties on technology related initiatives
Perform review and/or security assessment on the related initiatives
Job Requirements
University graduate with major in Computer Science, IT or related disciplines, with professional qualification such as CISSP, CISM, CISA, CREST CPSA / CRT, CEH is preferred
At least 5 to 7 years of relevant work experience in IT / Cybersecurity Security, e-Banking security, BCP/DR and/or relevant risk control area
Solid experience in handling technical information / cybersecurity security issues and good understanding of business processes and related regulations including HKMA TM-G-1, TM-G-2, SA-2, C-RAF, STDB, SFC, PDPO, etc.
Proven experience in writing policies, procedures and reports is a must
Familiar with infrastructure platforms, e.g. Data Centre Operations, Network Services (Voice / Data / Routing & Switching, security), Messaging, Desktop technology, Distributed Servers (UNIX and Windows), Mainframe etc.
Knowledge / experience on ISO27001 is an advantage
Strong sense of responsibility and ability to work under pressure
Work independently with good communication and interpersonal skills
Conversant with MS Word, Excel & Chinese character input
Good command of written & spoken English and Chinese including Putonghua
Holder of ECF on Cybersecurity is preferable
岗位:高级主任至经理,科技风险
工作职责:
履行科技风险管理,负责对现有/新系统、流程和项目中有关科技风险进行识别、衡量、监控和控制。
熟悉银行的信息科技管控政策并确保合规,能调查科技相关事件并撰写整改报告。
开展日常风险隐患排查和督导,持续确保银行政策和指引有效执行。
及时提出科技风险管控提升措施意见或建议。
协助制定科技风险管理工作规划,具有良好的团队协作精神。
能独立承担信息科技风险审查和网络安全评估。
任职要求:
大学本科毕业,主修计算机科学、信息技术或相关学科;持有 CISSP、CISM、CISA、CREST CPSA / CRT、CEH 等专业资格者优先。
具备至少5至7年IT/网络安全、电子银行安全、业务连续性计划/灾难恢复 或相关风险控制领域的实际工作经验。
在处理技术信息/网络安全问题方面有扎实经验,并深入理解业务流程及相关法规,包括香港金融管理局的 TM-G-1、TM-G-2、SA-2、C-RAF、STDB,以及证券及期货事务监察委员会 (SFC)、个人资料(隐私)条例 (PDPO) 等。
必须具备撰写政策、程序和报告的实操经验。
熟悉主流技术架构或基础设施,例如:数据中心运营、网络服务(语音/数据/路由与交换、安全)、消息系统、桌面技术、分布式服务器(UNIX 和 Windows)、大型主机等。
具备ISO27001知识/经验者优先。
较强的工作责任心和抗压能力。
能够独立工作,具备良好的沟通及人际交往技巧。
熟练使用 MS Word、Excel 及中文输入法。
良好的中英文书写及口语能力(包括普通话)。
持有ECF(數碼安全)資格優先
Interested parties, please click "Apply Now" for application.
Personal data collected will be used for recruitment purpose only.