IT Risk and Control Specialist recruitment

 Description:

The IT Risk Control Specialist is responsible for defining and executing risk and control initiatives and processes covering a broad range of related topics such as IT Security compliance programmes as well as operational risk and legal/ regulatory programmes for DB China. Further, the IT Risk Control Specialist is responsible for the identification and in-depth analysis of risk clusters and definition of potential strategic resolution, targeting the optimal point of risk-cost-ratio.
Where appropriate, the IT Risk Control Specialist will manage or oversee remediation programmes and be responsible for the quality of execution and outcomes. IT Risk Control Specialists also liaise with the regional teams, such as GT Risk Management and GT IT Security, Group Audit and other central functions as part of the normal execution of work activities.

Tasks / Responsibilities:

• IT Security and Risk Management

1. Execute risk and control programmes in line with the defined risk appetite and approach
2. Identifies environment (operational or application) modifications that should be made in order to improve security
3. Facilitate and advise the line organisation (i.e. managers) on the execution of risk programmes and outcomes
4. Perform and track completion of quality assurance assessments in preparation for upcoming audits and/or execution of legal/ regulatory or Group programmes, e.g., CBRC and PBOC
5. Perform independent reviews to identify, highlight and document risk issues. Follow-up on action items through closure of issues, e.g., self-assessments, independent risk assessment reviews (dbRACE)
6. Proactively manage internal and external audit processes. Verify factual correctness of issues, advise and assess individual management action plans for quality, prior to submission.
7. Contribute and provide feedback to IT risk and control-related policies/standards as a subject matter expert. Track progress of completion of these initiatives.
8. Select and develop most appropriate risk management strategy to minimize business disruption and address business needs
9. Identify and communicate trends regarding risk and risk management
10. Responsible for accurate reporting from a range of source tools and systems on a regular and ad-hoc basis

• Regulatory

1. Oversee and execute regulatory engagement processes including inspections/examinations, inquiries and meeting requests. Perform regulatory response preparation (includes quality checks)
2. Log regulatory actions and track for timely closure
3. Communicate all activities timely to local and regional management, and ensure approval processes are executed for
4. Execute processes to identify and evaluate new and changed regulations. Engage Technology units as needed to address new and changed regulations.
5. Perform review of local regulatory requirements and evaluate for consistencies in global capabilities.
6. Prepare and deliver engagement plans, reports and key metrics for regional and global management reporting.
7. Act as the local SME and central point of contact for all Technology regulatory matters.
8. Manage, prepare and track all IT regulatory reports, survey, queries and compliance requirements. Prepare local heat map.
9. Evaluate GT initiatives for applicability to regulatory compliance
10. Perform independent reviews to identify, highlight and document risk issues on IT regulatory guidelines and requirements.
11. Develop and maintain linkage between internal and external activities (Leverage internal audit management ledgers)

Skills / Qualifications

The candidate should have at minimum 5 years combined experience in Financial Services, IT Application Development or Infrastructure Support, Information Security, Computer Audit, Compliance and/or Risk Management Technology.

• Good relationship, communication, and negotiation skills
• Good project management skills and ability to deliver timely results
• Comfortable interacting with management and discussing critical issues
• Proven initiative; self starter; highly motivated; can work independently
• Good knowledge of local IT regulatory requirements
• Broad knowledge of Information Security and the management of IT risks
• Working knowledge of application and infrastructure technology
• CISSP/CISA or similar is preferred but not mandatory
• Literate in both English and Chinese (spoken and written)
 

Don't  miss the opportunity. Apply Online now!