Assistant Vice President, Information Technology Audit

Hong Kong Exchanges and Clearing Limited

Hong Kong

On-site

HKD 900,000 - 1,500,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Hong Kong Exchanges and Clearing Limited (HKEX) invites an experienced IT Audit professional to lead and deliver IT audits with a strong focus on cybersecurity risk.

As Assistant Vice President of IT Audit, you will manage risk-based scoping, supervise staff, communicate findings to stakeholders, and drive innovative audit techniques to strengthen the Group's control environment.

Qualifications

  • At least 8 years of experience in internal or external audit, risk management or cybersecurity.
  • University graduate in Accounting, Finance, Business Administration or Technology, etc.
  • Possess professional qualifications such as CPA, CIA, CISA, CISM, CISSP, CEH, CCSP / CCAK, CSX-P or equivalent.
  • Strong understanding of NIST Cybersecurity Framework, ISO 27001 and CIS controls.
  • Solid grasp of IT & cybersecurity risks, application controls, and relevant software and systems.
  • Demonstrated ability to work independently, multi-task and stay organized.

Responsibilities

  • Independently manage and lead IT audits with emphasis on cybersecurity from scoping to reporting.
  • Apply cybersecurity expertise to assess risks and controls, supervise staff, and communicate issues to stakeholders.
  • Develop risk-based testing strategies to evaluate design and operating effectiveness of key controls.
  • Independently articulate control gaps, cyber threats and risk exposures to stakeholders.
  • Engage in ad-hoc audit activities and contribute to continuous improvement of audit methodology.

Skills

Cybersecurity expertise
Risk-based auditing
Team leadership
Stakeholder management
Data analytics
Strong communication

Education

University degree in relevant disciplines

Tools

Cybersecurity software
Operating systems
Databases
Cloud technologies
Networking technologies

Job description

Company Introduction

We’re home to Asia's most dynamic and vibrant capital markets. Connecting capital, ideas, inspiration and innovation for deeper, more diverse and liquid global capital markets; providing greater choice and opportunity for our customers, each and every day. HKEX is a purpose-driven company. Our commitment to the long-term development of our business and our markets is articulated in our purpose: "To Connect, Promote and Progress our Markets and the Communities they support for the prosperity of all."

Job Summary

Group Internal Audit (GIA) supports the HKEX Group in achieving its business objectives, safeguarding its assets and reputation, and raising its control culture awareness through the provision of objective, independent and insightful assurance to the Board and senior management. GIA reports directly to the HKEX Audit Committee and administratively to the Group Chief Executive Officer. The Assistant Vice President of IT Audit reports to the Head of IT Audit and serves as the Manager-in-Charge for leading and delivering IT audits, with a strong focus on cybersecurity risks, in accordance with the annual audit plan. The role requires deep cybersecurity expertise and also supports departmental initiatives.

Job Duties

Key responsibilities include:

  • Independently manage and lead IT audits, with particular emphasis on cybersecurity, from risk-based scoping and fieldwork through to reporting, in accordance with GIA’s audit methodology.
  • Apply cybersecurity expertise to assess key risks and controls, supervise team members, and ensure issues are effectively identified and communicated to stakeholders.
  • Critically assess IT and cybersecurity processes and develop risk-based testing strategies to evaluate the design and operating effectiveness of key controls.
  • Independently articulate control gaps, cyber threats and risk exposures to stakeholders.
  • Leverage innovation/ automation audit techniques to increase effectiveness and efficiency of the audit program.
  • Independently conduct continuous risk monitoring and assessments of the cybersecurity & IT operations to identify emerging / high-risk areas for coverage.
  • Manage stakeholder relationships and proactively provide risk and control advice with an aim to improve the Group’s control environment.
  • Challenge and influence management to implement effective controls.
  • Develop sound knowledge of the Group’s strategy, products, risk management processes and operating platforms.
  • Consider broader enterprise risks and HKEX’s strategic objectives.
  • Stay current of the industry development, cybersecurity and IT trends.
  • Conduct research on industry and risk topics to increase effectiveness of audit coverage and GIA’s ability to add value to the Group and help deepen the GIA team’s cybersecurity knowledge.
  • Engage in ad-hoc audit activities such as review of key firmwide change initiatives, investigations and handling of whistle-blowing cases.
  • Perform quality control on audit deliverables and provide coaching to junior team members.
  • Validate remediation of audit issues in an effective and timely manner.
  • Participate and contribute to departmental initiatives such as continuous improvement of GIA’s audit methodology.
  • Support the preparation of materials for senior management, Audit Committee and regulators.
Job Requirements
  • At least 8 years of experience in internal or external audit, risk management, compliance, cybersecurity, preferably with professional firms or financial institutions. Other relevant expertise will also be considered.
  • A university graduate of relevant disciplines (e.g. Accounting, Finance, Business Administration, Technology, etc.)
  • Possess at least one relevant professional qualification such as CPA, CIA, CISA, CISM, CISSP, CEH, CCSP / CCAK, CSX-P or other security related qualifications.
  • Strong understanding of industry cybersecurity standards such as National Institute of Standards and Technology (NIST) Cybersecurity Framework, ISO 27001, CIS, etc.
  • Strong understanding of the underlying IT & cybersecurity risks, application controls, assessment practices and various IT security software, operating systems, databases, cloud, networking technologies and emerging technology risks.
  • Team-oriented with a strong sense of ownership and individual accountability.
  • Independent and motivated with the ability to multi-task and remain organized.
  • Demonstrate agility and the ability to operate in a fast-changing environment.
  • Strong communication and relationship management skills.
  • Experience in leveraging data and technology an advantage.

HKEX is committed as an Equal Opportunity Employer. Diversity is one of our core values and we look to support, respect diverse perspectives, abilities, culture and experiences within our workplace.

Location: HKEX - Exchange Square Shift: Standard - 40 Hours (Hong Kong SAR) Scheduled Weekly Hours: 40 Worker Type: Permanent

Hong Kong Exchanges and Clearing Limited (HKEX) is a publicly-traded company (HKEX Stock Code:388) and one of the world’s leading global exchange groups, offering a range of equity, derivative, commodity, fixed income and other financial markets, products and services, including the London Metals Exchange. As a superconnector and gateway between East and West, HKEX facilitates the two-way flow of capital, ideas and dialogue between China and the rest of world, through its pioneering Connect schemes, increasingly diversified product ecosystem and its deep, liquid and international markets. HKEX is a purpose-led organisation which, across its business and through the work of HKEX Foundation, seeks to connect, promote and progress its markets and the communities it supports for the prosperity of all. Discover the latest career opportunities and programmes at HKEX.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Associate, Information Technology Audit
Associate, Information Technology Audit

Hong Kong Exchanges and Clearing Limited • Hong Kong

On-site
HKD 600,000 - 900,000
Assistant Vice President, Information Technology Audit
Assistant Vice President, Information Technology Audit

Hong Kong Exchanges and Clearing Limited (HKEX) • Hong Kong

On-site
HKD 900,000 - 1,500,000
Associate, Information Technology Audit
Associate, Information Technology Audit

Hong Kong Exchanges and Clearing Limited (HKEX) • Hong Kong

On-site
HKD 500,000 - 800,000
Associate, Information Technology Audit
Associate, Information Technology Audit

Hong Kong Exchanges & Clearing Ltd • Hong Kong

On-site
HKD 600,000 - 900,000
Assistant Vice President (AVP), Information Security Governance
Assistant Vice President (AVP), Information Security Governance

Hong Kong Exchanges and Clearing Limited • Tseung Kwan O

On-site
HKD 900,000 - 1,300,000
AVP, IT Audit & Cybersecurity Leader
AVP, IT Audit & Cybersecurity Leader

Hong Kong Exchanges and Clearing Limited (HKEX) • Hong Kong

On-site
HKD 900,000 - 1,500,000
Vice President - IT Risk & Control
Vice President - IT Risk & Control

Hong Kong Exchanges and Clearing Limited • Hong Kong

On-site
HKD 900,000 - 1,400,000
IT Audit Associate: Risk-Based Assurance & Controls
IT Audit Associate: Risk-Based Assurance & Controls

Hong Kong Exchanges and Clearing Limited • Hong Kong

On-site
HKD 600,000 - 900,000
VP, IT Audit (Corporate Banking/Cyber Security/Technology Risk)
VP, IT Audit (Corporate Banking/Cyber Security/Technology Risk)

Randstad Hong Kong Limited • Hong Kong

On-site
HKD 900,000 - 1,300,000
IT Audit Associate: Risk, Controls & Compliance
IT Audit Associate: Risk, Controls & Compliance

Hong Kong Exchanges and Clearing Limited (HKEX) • Hong Kong

On-site
HKD 500,000 - 800,000