锦鲤求职

汇丰控股

Associate IT Security Manager

锦鲤会替你打开官网网申、按简历自动填表提交,你只需要在关键步骤确认。

岗位描述

Ensure the businesses are compliant to multiple regulatory obligations, namely, HKMA C-RAF, Critical Infrastructures (Computer Systems) Ordinance and HK IA GL20, by conducting detailed assessments with external assessors and global SMEs, while maintaining proper, timely and cross-entity communications with various stakeholders. Act as the liaison between Cyber Security team and all Business/Functions in the group, to which provide expertise, consultancy, and support as the Subject Matter Expert of Cyber Security to identify risk and controls required on cyber security Lead projects to produce deliverable with high quality/standards under strict timelines . Solicit with senior business stakeholders and 2nd line of defence for input and steer for all regulatory inquiries and circulars. Uplift the assessment process with automation and optimization. Monitor outstanding issues, track regulatory commitments and be responsible for remediation closure with support from Global SMEs and local leadership. Keep abreast of the latest cyber security threat landscape, evaluate the potential impact to the bank. Communicate with regulators when needed and manage their expectations. Bachelor's degree in computer science or a related discipline. Proven experience in IT security and risk management; candidates with less experience may be considered for an Associate role. Solid experience in cybersecurity controls, and IT risk management frameworks. Strong knowledge of banking and insurance regulations and guidelines related to cybersecurity and technology risk management, including Fintech. Strong self-motivation, with good leadership, communication, interpersonal and analytical skills. Great sense of ownership and a customer-centric mindset. Excellent command of both spoken and written English and Chinese; Cantonese is an advantage. Professional qualifications such as CISM, CISA, CISSP and CEH are preferred. Experienced in performing security risk assessment and audits based on industry standards. Familiar with ISO 27001 Information Security Management Systems (ISMS). Experience with project management.

运维/技术支持方向的申请准备

先核对岗位要求与自己的经历,再准备档案、投递和面试。

阅读求职步骤与示例 →