Governance and Compliance Analyst recruitment
This is an excellent opportunity to work at the forefront for IT Risk and Audit based projects for a top global multinational company in Hong Kong.
Responsibilities of the role:
- Identification of existing TS SOX, AYIC and security process testing for all in-scope
- Annual planning for SOX testing, BCM (adequacy and effectiveness) across Asia Technology Services globally that satisfies the ongoing requirements of key internal and external stakeholders.
- Resourcing and planning for the support of SOX testing allowing for peaks in workload.
- Detailed, documented results of SOX testing to a standard that can be relied on by external auditors as complete, accurate and independent.
- Annual planning for quarterly testing of Operational Security Process Standard controls across Technology Services globally
- Detailed documenting of results in Security Process testing to a standard that can be relied on as complete, accurate and independent by internal and external stakeholders for the purposes of security process SOX testing.
- Successful implementation of the SOX and Security Process testing plans with all key milestones being met.
- Responsible for stakeholder engagement methodology.
- Responsible for continuous improvement plan linked to agreed objectives.
- Attendance at regular management meetings and function related meetings/forums.
- Conducting performance metrics, reporting dashboards and other regular/ad-hoc Management Information for TS Risk Security Leadership and other internal/external stakeholders.
- Risk reports for Asia Risk Board, Risk Dashboard, RCC, TS ExCO, BSRC, and CEC
Requirement of the role:
- A minimum of 4 years relevant experience in Information Technology with at least 2 years above specialized in IT security and risk control area.
- Previous experience working with a virtual, geographically dispersed team, including issue resolution, negotiation, forecasting and planning.
- Knowledge of Sarbannes Oxley 404 requirements, IT Audit or Control Testing techniques
- Awareness of CoBiT and PCI DSS, management framework used within Technology Services.
- Technical competence in any of the infrastructure platforms, e.g. Data Centre Operations, Network Services (Voice / Data), Messaging, Desktop technology, Distributed Servers (UNIX and Windows), MidRange, etc.
- Capability in MS Office (Word, Powerpoint, Excel)
- Knowledge of Pivot table in MS Excel
- Capability in MS Project, Visio, Sharepoint
- PRINCE2 Foundation a plus but not essential
- CISA (Certified Information Security Auditor) a plus but not essential
- CISM (Certified Information Security Manager) a plus but not essential
- CISSP (Certified Information Systems Security Professional) a plus but not essential
If you are interested in this opportunity, please forward your resume in word format to kchui@ikasinternational.com and include “Governance and Compliance Analyst” in the subject line.
January 9, 2012
• Tags: Governance and Compliance Analyst recruitment, Information Services careers in the Hong Kong SAR • Posted in: Financial