Assistant Vice President / Vice President, Technology Risk Management | 人才服务办公室
5 天前发布
职位描述
Fubon Bank, an identity that reflects the commitment of providing customers with Value Banking Service - "Get More than You Expect" , is also a leading distributor of investment solutions and services, supported by a broad range of products, a talented and dynamic team.
In line with our business expansion, we are inviting committed professionals to join our team. If you have the passion and belief that you can grow with our business, and contribute to our success, capitalize on this career opportunity.
Responsibilities:
- Provide technology risk management support including security risk assessment, security exceptions handling and technology risk reporting matters
- Review and monitor the rulesets and alerts of the Bank’s Data Loss Protection (DLP) systems for Web Upload, Printing, Portable Storage and E-mail Filtering
- Provide advices to the development and implementation of the Bank’s policies, guidelines and procedures related to IT security controls
- Provide IT security advisory services to ITG and business/operational units on security standards, architecture of new products, applications and systems, and implementing security controls in existing systems and applications
- Collect cyber threat intelligence from various information sources, review and assess the information collected and request ITG to take appropriate actions
- Overall coordination of annual cyber security drill including the drill planning, execution and reporting.
- Conduct onsite security risk assessments on outsourcing vendors
- Conduct IT compliance risk assessments which involves identifying, analyzing, describing and estimating the IT compliance and technology risks affecting the Bank and report timely on any exceptions to the department head
- Review and monitor key risk indicators and control self-assessments of ITRM to ensure the effectiveness of these tools in identifying and escalating IT internal control issues in a timely manner
- Assess potential fake websites detected and advise appropriate actions and report the case to appropriate authorities
- Promote and enforce regulators’ and the Bank’s policies and guidelines related to IT security through conducting training and information sharing sessions in the Bank
Requirements:
- University degree in Computer Science, Information Systems or other technology-related disciplines
- Possess recognized certificates of Enhanced Competency Framework for Banking Practitioners (e.g. CISA, CISSP, CISA, CRISC, CGEIT, CCSP)
- At least 3 years working experience in the banking industry
- At least 5 years working experience in technology risk management and information security
- Knowledgeable in IT security technologies, including authentication mechanism and cryptography
- Understanding of the HKMA’s and other regulatory requirements
Please send your application DIRECTLY to Fubon Bank (Hong Kong) Limited, Human Resources Management Group via email: [email redacted, apply via company website] with full resume quoting the above reference no.
For other vacancies, please visit our website: www.fubonbank.com.hk
*All personal data provided by job applicants will be used for recruitment purposes only in accordance with the Bank’s Personal Data Information Collection Statement, a copy of which is available on our website: http://www.fubonbank.com.hk/web/html/sh_careers_e.html
其他细节
- 职位空缺来源
- CTgoodjobs
- 参考编号
- 3152212-01#0416
- 发布日期
- 14 May 2025
- 关键词
- Insurance plan,Medical plan,Banking / Finance - Risk Management,Banking / Finance - Technology,Information Technology - IT Auditing / Quality Assurance / Testing,Information Technology - Security Specialist / Risk Management,Banking,Central,Senior management level,Master's degree,Degree,Architecture,Certified Cloud Security Professional (CCSP),Certified Information Systems Auditor (CISA),Certified Information Systems Security Professional (CISSP),Certified in Risk and Information Systems Control (CRISC),Compliance,Computer Science,Coordination,Data Loss Prevention (DLP),Estimation,IT Security,Information Security,Internal Control,New Product,Outsourcing,Planning,Policies,Printing,Regulatory,Risk Assessment,Risk Management,Risk Management Manager,Security,Vendors,Cyber Security Drill,Data Loss Protection (DLP) systems,ITRM