IT Risk Manager / Analyst recruitment
- Ideal for candidates well versed in IT Risk and Security
- Excellent career opportunity
- 5-day work
Job Responsibilities:
- Delivery of Risk Awareness and Training program for organization's global infrastructure division and potentially expand the program to other business when required.
- Delivery of the Audit Execution Support model. This model should support any internal / external audit and regulatory inspection / questionnaire activities related to global infrastructure division.
- Delivery of the annual control and risk assessment program.
- Identification, assessment and, where appropriate, escalation of emerging/upstream risks and security issues working with Lead IT Risk Manager to gather, analyse and understand intelligence about future change.
- Support for the continuous improvement of the Risk Security framework across Technology Services, identifying the need for adaptation of controls to meet changes in the risk profile and/or risk appetite and optimising the balance between controls and risk.
- Input into the development of the response to new internal and external requirements/policy/regulations, supporting the implementation across Technology Services.
- To ensure all operational activity is completed within the prescribed governance structure and that statutory/ governance exercises are completed robustly.
- Support for delivery of technology development of security infrastructure to achieve global / Group technology strategic goals – this may involve delegated oversight of programmes of delivery and effective management of resources to deliver all technology development in line with budget and timescales.
Job Requirements:
- Degree in any IT disciplines
- Holder of CISA, CISM or CISSP
- At least 5 years experience in IT with 2 years experience in IT Security and risk control area
- Previous experience working with a virtual, geographically dispersed team, including issue resolution, negotiation, forecasting and planning
- Experience financial services industry
- Good knowledge in SOX 404 requirements, IT Audit or Control Testing techniques
- Awarenewss of Cobit and PCI DSS, maangement framework used within Technology Services
- Technical competence in any of the infrastructure platforms, e.g. Data Centre Operations, Network Services (Voice / Data), Messaging, Desktop technology, Distributed Servers (UNIX and Windows), MidRange, etc.
April 1, 2011
• Tags: Analyst recruitment, Information Technology careers in the Hong Kong SAR, IT Risk Manager • Posted in: Financial