The Role
Performs IT security audits, risk and compliance assessments, remediation tracking, technology risk analysis, policy development, and security advisory activities for IT systems and projects. Partners with audit, risk management, security, and business teams; prepares management reports and security communications; ensures regulatory and security requirements are embedded into processes. Conducts security awareness training and advises on cybersecurity controls, governance, and regulatory compliance.
Summary Generated by Built In
- Work
extensively with Internal / External Audit and Risk Management on IT audit,
risk and compliance assessment
- Engage
with all levels of IT staffs to gather information for audit and assessment
- Tracked
the remediation status of audit and assessment observation and recommendation and
prepare management reports
- Work
with Group IT Security and Information Risk Management to perform risk
assessment
- Involve
in new systems and projects under development as an independent advisor to IT teams
and business to ensure security requirements are embedded into BAU processes and
IT projects
- Develop
and regularly review policies and procedures regarding IT Security
- Perform
risk assessment and trend analysis to ensure that IT risks are identified,
measured,
- recorded
and reported, monitored, and re-mediated timely and within the Company’s risk appetite
- Prepare
materials communicating IT security messages and supporting management reporting
on security and technology performance
- Promote
IT security awareness and conduct regular training for staff
Requirements
- Degree
in Computer Studies, or related disciplines
- Relevant
professional qualifications (e.g. CISA, CISM, and CISSP)
- At
least 3 years of relevant working experience, preferably in banking / insurance
industry
- Strong
control mindset on cyber and technology risk matters
- Able
to articulate IT risk in relation to the business
- Ability
to identify and assess complex IT risks and controls
- Capable
of providing effective challenge and advice while maintaining strong,
respectful relationships with various parties
- Familiar
with relevant regulatory requirements on technology risk management and cybersecurity
relating to Bermuda Monetary Authority (BMA), Insurance Authority (IA), Securities
and Futures Commission (SFC) and Monetary Authority of Macao (AMCM)
- Candidate
who has IT Audit or IT Governance, Risk, and Compliance (GRC) experience will be
an advantage
- Committed,
proactive, assertive and positive with a can-do attitude
- Strong
team player to collaborate with a diverse team
- Thrive
in a fast-paced environment
- Fluent
in both spoken and written English and Chinese
- Candidate
with less experience will be considered as Analyst
Skills Required
- Degree in Computer Studies or a related discipline
- Relevant professional qualification such as CISA, CISM, or CISSP
- At least 3 years of relevant work experience
- Experience in banking or insurance
- Strong understanding of cybersecurity and technology risk controls
- Ability to articulate IT risk in relation to business needs
- Ability to identify and assess complex IT risks and controls
- Ability to provide effective challenge and advice while maintaining professional relationships
- Familiarity with technology risk management and cybersecurity regulations from BMA, IA, SFC, and AMCM
- IT Audit or IT Governance, Risk, and Compliance experience
- Fluency in spoken and written English and Chinese
- Committed, proactive, assertive, positive, and collaborative work approach
- Ability to thrive in a fast-paced environment
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Teki'Spire Limited is an executive search and recruitment firm specializing in Technology, Data & Digital roles, covering functions such as Digital, Big Data, Business Intelligence, Application Development, and Project Management.






