
Tech Risk and Controls Lead
- Beijing
- Permanent
- Full-time
- Ensure effective identification, quantification, communication, and management of technology risk, focusing on root cause analysis and resolution recommendations
- Develop and maintain robust relationships, becoming a trusted partner with LOB technologists, assessments teams, and data officers to facilitate cross-functional collaboration and progress toward shared goals
- Execute reporting and governance of controls, policies, issue management, and measurements, offering senior management insights into control effectiveness and inform governance work
- Proactively monitor and evaluate KRIs, KPI, and control effectiveness, identify gaps, and recommend enhancements to strengthen risk posture and regulatory compliance
- Main point of contact with Regulator on Technology/Cyber Risk matter, including managing entity-specific risks including supporting prompt incident response impacting the entity.
- Keep apprised of current and emerging technology risks which could potentially affect the financial institution's risk profile.
- Responsible for bringing to the notice of the Location Board/ Location Operating Committee /IT sub-committee of the board about the cyber security risk the bank is exposed to.
- Coordinate the activities pertaining to China Regulator Reporting procedure for Cyber Incident and coordination with Cyber Security Operation Center.
- Responsible for the timely completion and submission of regulatory required assessment.
- 10+ years of experience or equivalent expertise in technology risk management, information security, or related field, emphasizing risk identification, assessment, and mitigation
- Familiar with China banking industry related regulations, i.e. NFRA, PBOC, SAFE, MLPS..etc
- Familiarity with risk management frameworks, industry standards, and financial industry regulatory requirements
- Proficient knowledge and expertise in data security, risk assessment & reporting, control evaluation, design, and governance, with a proven record of implementing effective risk mitigation strategies
- Demonstrated ability to influence executive-level strategic decision-making and translating technology insights into business strategies for senior executives
- CISM, CRISC, CISSP, or other industry-recognized risk certifications