The Job :
- Technology and Operational Risk Support the design or enhance the operational risk policies to ensure the Enterprise Risk Management (ERM) framework is embedded in the business activities Update the current risk assessment and control process which includes risk appetite, tolerance and limits, and provide analysis and follow-up on the closure of related management actions and recovery plan Facilitate completion of Risk Control Self-Assessment (RCSA) and Regulatory Requirement Self-Assessment across Technology and Operational Perform new service risk assessments to identify control gaps, execute risk mitigation projects and provide support to stakeholders on matters relating to regulatory, risk and corporate governance Review initiatives in accordance with regulatory bodies’ requirements (such as HKMA SPM, TM-E-1, TM-G-1, SA-2, OR-2, C-RAF, iCAST) Assessing the regulatory change impacting technology, operational and driving related risk mitigation programs with stakeholders Implement and update security policies and procedures to maintain the technology risk level for the business unit To maintain risk register and communicate the identified risks and impacts with stakeholders Follow up independent assessment, internal audit, security penetration test issues in a timely and controlled manner Conduct an independent review of incidents and related information to ensure the prevention, detection, containment and correction Conduct and manage technology risk for 3rd party service providers Co-ordinate Business Continuity Plan
- Others Train and develop team and support needs from other departments related to risk managementPromote and implement the risk analytics and data-driven Provide recommendations to senior executives for any potential problems & risks adhere to existing operation work flow and policies Support needs from other stakeholders related to risk management Ad hoc task as assigned by supervisor
To succeed in this role :
Degree holder in Information Technology or related disciplines; Add-on with professional certifications like CISA / CISM / CISSP / CCSP / CRISC, and similar certifications.Minimum 7 years' of relevant experience, preferably with banking or financial institutions experience, in compliance, technology risk, or IT audit (either 1st line or 2nd line of defense)Knowledge with NIST CSF, ISO 27001, OWASP Top 10Knowledge in Cloud, Mobile App, API Security, PCI-DSSSound knowledge of Information Security, System Resiliency & Availability & Software development practices, Application Security and frameworks preferredGood project management skillStrong knowledge of risk management, controls and processesFamiliar with financial services industry including prepaid card / credit card process, Merchant Services and ecommerce.Keen interest in startup environment, fintech trends and sound knowledge of banking and financial productsStrong leadership, communication and stakeholders management, analytical and problem-solving skillsGreat sense of ownership, self-motivated, work independently as well as being a good team player; Multi-tasked and able to work under tight timelinesProficiency in both English and ChineseAll personal data provided by candidates will be used for recruitment purposes only by HKT Services Limited in accordance with HKT's Privacy Statement, which is available on our website. Unless otherwise instructed in writing, candidates may be considered for other suitable positions within the Group (being, HKT Limited, PCCW Limited and their respective subsidiaries, affiliates and associated companies). Personal data of unsuccessful candidates will normally be destroyed 24 months after rejection of the candidate's application. If you have any questions regarding your personal data held by HKT Services Limited HKT's Privacy Statement, please feel free to contact our Privacy Compliance Officer by writing to or GPO Box 9896, Hong Kong.x 9896, Hong Kong.