
Digital Program Specialist - IT Risk and Program Management
Asian Infrastructure Investment Bank
- Beijing
- Permanent
- Full-time
- Conduct IT security and risk due diligence on vendors and third parties during the related corporate procurement stages.
- Collaborate with corporate procurement, legal, compliance, and IT teams to ensure vendors' security risks and embargo and sanction risks are assessed.
- Lead the Third-Party Security Assessments (TPSA) program to evaluate, mitigate, and monitor security risks associated with IT vendors and suppliers, also including outsourcing supplier, cloud service providers, open-source technologies, and product security.
- Coordinate IT outsourcing management activities, including outsourcing planning, risk assessment, performance monitoring, and compliance oversight, to ensure alignment with the Bank's outsourcing management requirements.
- Support the Team Lead of IT Risk and Resilience & Cyber Security to oversee IT security governance, compliance, and risk mitigation programs.
- Coordinate with various IT and business teams to support security initiatives, ensuring alignment with Bank requirements and industry best practices.
- Track, analyze, and report on the effectiveness of IT security programs by using key metrics and data insights, ensuring compliance with security requirements and supporting continuous improvement.
- Support internal and external IT audits, ICFR control testing, risk control assessment, etc.
- Manage vendors, which includes procurement, contracting, and performance management, among others.
- Bachelor's degree in computer science, information security, data science, risk management, or a related discipline. Master's degree would be a plus.
- 5-8 years of relevant working experience in IT risk and program management and relevant fields, preferably with financial institutions.
- Hands-on experience conducting due diligence and third-party security risk assessments.
- Strong knowledge of IT outsourcing risk, cloud risk, open-source risk, embargo, and sanction risk.
- Familiarity with cloud security principles and cloud-native security solutions on Azure and AWS.
- Strong understanding of information security and privacy standards, frameworks, and compliance requirements, including ISO 27001, NIST CSF, NIST SP800, SOC 2, and GDPR.
- Certifications such as CISSP, CISM, CRISC, PMP, and ISO 27001 Auditor would be an advantage.
- Strong business acumen and the ability to balance technical security needs with business priorities.
- Ability to work effectively in a multicultural organization.
- Excellent written and oral English language skills.
- Strong data analysis, reporting, writing, and communication skills, with the ability to interpret complex data and prepare clear, actionable reports and insights for executive-level stakeholders.
- Excellent project management skills and attention to detail, with the ability to lead the team to manage multiple workstreams.