This role will focus on Technology Risk Governance, Incident Response Management, Cyber Resilience Assessment Framework (C-RAF), Operational Resilience, and Regulatory Compliance. The successful candidate will play a key role in strengthening the bank's technology risk posture and ensuring compliance with HKMA requirements.
Key Responsibilities
Requirements
What you need to do now
If you're interested in this role, click 'apply now' to forward an up-to-date copy of your CV, or call us now.
Key Responsibilities
- Lead and oversee technology risk management activities across the bank, ensuring alignment with regulatory requirements and industry best practices.
- Manage and coordinate major technology and cybersecurity incidents, including incident assessment, escalation, root cause analysis (RCA), remediation tracking, and post-incident reviews.
- Ensure compliance with HKMA Technology Risk Management (TM-G-1) and Cyber Resilience Assessment Framework (C-RAF) requirements.
- Develop, review, and enhance technology risk policies, procedures, standards, and governance frameworks.
- Coordinate and support C-RAF assessments, cyber resilience reviews, and regulatory examinations.
- Plan and execute bank-wide crisis management exercises, cyberattack simulations, disaster recovery (DR) drills, and operational resilience testing.
- Lead testing and drill activities covering critical infrastructure, critical systems, and business services.
- Conduct technology risk assessments for new initiatives, system changes, cloud adoption, and third-party arrangements.
- Engage with regulators, auditors, senior management, and technology teams on risk-related matters.
- Monitor risk issues, control effectiveness, remediation actions, and emerging technology risks.
Requirements
- Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Risk Management, or related disciplines.
- Professional certifications such as CISA, CRISC, CISSP, CISM, CBCP, CGEIT, or equivalent.
- Minimum 5 years of experience in Technology Risk, Cyber Risk, IT Risk, Operational Resilience, Information Security, or related functions within banking or financial services.
- Strong knowledge of HKMA regulations, including Technology Risk Management and C-RAF requirements.
- Proven experience in technology/cyber incident response management, major incident handling, and crisis management.
- Hands-on experience planning and conducting bank-wide DR drills, cyber simulation exercises, tabletop exercises, and critical infrastructure testing.
- Strong experience developing and maintaining technology risk policies, procedures, and governance frameworks.
- Understanding of operational resilience, business continuity, third-party risk, cloud risk, and cybersecurity governance.
- Excellent stakeholder management and communication skills.
What you need to do now
If you're interested in this role, click 'apply now' to forward an up-to-date copy of your CV, or call us now.
Job ID 1289756
Hays Hong Kong Limited ("Hays Hong Kong") is the one of the leading specialist recruitment companies in Hong Kong in recruiting qualified, professiona...
More Jobs From Hays
Hays
Hong Kong
Hays
Hong Kong
Hays
Hong Kong
Hays
Hong Kong
Boost your career
Find thousands of job opportunities by signing up to eFinancialCareers today.More Jobs Like This
Bank Of China (Hong Kong) Limited
Hong Kong
Bank Of China (Hong Kong) Limited
Hong Kong