岗位描述
Provide independent and objective assessment to the Board and senior management on the adequacy and effectiveness of the Group’s internal control, risk management and governance frameworks, with a particular focus on information technology, cybersecurity, data and emerging technology risks across the Group's operations in Hong Kong, Macau and Mainland China.
Key Responsibilities
• Lead and execute the Group's IT audit strategy covering cybersecurity, digital banking, cloud computing, AI, data governance, technology risk and operational resilience.
• Manage IT audits, special reviews and investigations, ensuring high-quality delivery in line with professional standards.
• Assess the effectiveness of governance, risk management and internal controls across technology and information security domains.
• Provide independent assurance and actionable insights to senior management and Board Committees.
• Evaluate controls over technology outsourcing, third-party service providers, cloud environments and cross-border technology operations.
• Promote data analytics, automation and AI-enabled auditing techniques to enhance audit effectiveness.
• Monitor emerging technology risks, cybersecurity threats and regulatory developments.
• Lead, coach and develop a high-performing audit team while driving continuous improvement initiatives.
Requirements
• Degree in Information Technology, Computer Science, Information Systems or related discipline.
• Minimum 12 years of experience in IT Audit, Technology Risk, Information Security, Cybersecurity or related functions, with proven leadership experience.
• Professional certifications such as CISA, CISSP, CISM, CRISC, CIA, CPA, CGEIT, CDPSE, CCSP or equivalent.
• Strong knowledge of cybersecurity, cloud computing, digital banking, AI governance, data governance, operational resilience and technology risk management.
• Solid understanding of regulatory requirements and technology risk frameworks within the banking or regulated financial services industry.
• Experience engaging with senior executives, Board Committees and regulators on complex technology and risk topics.
• Strong analytical, stakeholder management, communication and people management skills.
• Experience with data analytics, automation and AI-enabled audit methodologies is highly desirable.