Assistant Vice President, Information Technology Audit

Hong Kong Exchanges and Clearing Limited (HKEX)

Hong Kong

On-site

HKD 900,000 - 1,500,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Hong Kong Exchanges and Clearing Limited (HKEX) seeks an experienced IT Audit leader to drive cybersecurity-focused audits within Group Internal Audit. You will oversee planning, fieldwork, reporting, and team coaching, ensuring effective controls and risk mitigation across the IT landscape.

The role requires deep cybersecurity expertise, strong communication, and the ability to influence management while aligning with HKEX strategic objectives.

Qualifications

  • At least 8 years of experience in internal or external audit, risk management, compliance or cybersecurity.
  • University graduate in accounting, finance, business administration or technology.
  • Hold at least one professional qualification such as CPA, CIA, CISA, CISM, CISSP, CEH, CCSP/CCAK or CSX-P.
  • Strong understanding of industry cybersecurity standards (NIST CSF, ISO 27001, CIS).

Responsibilities

  • Independently manage and lead IT audits with emphasis on cybersecurity from scoping to reporting.
  • Develop risk-based testing strategies to evaluate control design and operating effectiveness.
  • Leverage automation audit techniques to increase efficiency.
  • Conduct continuous risk monitoring of cybersecurity and IT operations.
  • Manage stakeholder relationships and provide risk and control advice to improve the control environment.
  • Contribute to knowledge of the group’s strategy, risks, and operating platforms.
  • Stay current on cybersecurity and IT trends and research industry topics.
  • Engage in ad-hoc audit activities and review of change initiatives.

Skills

IT Audit
Cybersecurity
Risk Management
Stakeholder Management
Multi-tasking

Education

University graduate in Accounting/Finance/Business/Technology

Tools

NIST CSF
ISO 27001
CIS

Job description

Company Introduction:

We’re home to Asia's most dynamic and vibrant capital markets. Connecting capital, ideas, inspiration and innovation for deeper, more diverse and liquid global capital markets; providing greater choice and opportunity for our customers, each and every day. HKEX is a purpose-driven company. Our commitment to the long-term development of our business and our markets is articulated in our purpose: "To Connect, Promote and Progress our Markets and the Communities they support for the prosperity of all."

Job Summary:Group Internal Audit (GIA) supports the HKEX Group in achieving its business objectives, safeguarding its assets and reputation, and raising its control culture awareness through the provision of objective, independent and insightful assurance to the Board and senior management. GIA reports directly to the HKEX Audit Committee and administratively to the Group Chief Executive Officer. The Assistant Vice President of IT Audit reports to the Head of IT Audit and serves as the Manager-in-Charge for leading and delivering IT audits, with a strong focus on cybersecurity risks, in accordance with the annual audit plan. The role requires deep cybersecurity expertise and also supports departmental initiatives.

Job Duties:
Job Responsibilities
  • Independently manage and lead IT audits, with particular emphasis on cybersecurity, from risk-based scoping and fieldwork through to reporting, in accordance with GIA’s audit methodology. Apply cybersecurity expertise to assess key risks and controls, supervise team members, and ensure issues are effectively identified and communicated to stakeholders.
  • Critically assess IT and cybersecurity processes and develop risk-based testing strategies to evaluate the design and operating effectiveness of key controls. Independently articulate potential control gaps, cyber threats and risk exposures to stakeholders.
  • Leverage innovation/ automation audit techniques to increase effectiveness and efficiency of the audit program.
  • Independently conduct continuous risk monitoring and assessments of the cybersecurity & IT operations to identify emerging / high-risk areas for coverage.
  • Manage stakeholder relationships and proactively provide risk and control advice with an aim to improve the Group’s control environment. Challenge and influence management to implement effective controls.
  • Develop sound knowledge of the Group’s strategy, products, risk management processes and operating platforms. Consider broader enterprise risks and HKEX’s strategic objectives.
  • Stay current of the industry development, cybersecurity and IT trends. Conduct research on industry and risk topics to increase effectiveness of audit coverage and GIA’s ability to add value to the Group and help deepen the GIA's team cybersecurity knowledge.
  • Engage in ad-hoc audit activities such as review of key firmwide change initiatives, investigations and handling of whistle-blowing cases.
  • Perform quality control on audit deliverables and provide coaching to junior team members.
  • Validate remediation of audit issues in an effective and timely manner.
  • Participate and contribute to departmental initiatives such as continuous improvement of GIA’s audit methodology.
  • Support the preparation of materials for senior management, Audit Committee and regulators.
Job Requirements
  • At least 8 years of experience in internal or external audit, risk management, compliance, cybersecurity, preferably with professional firms or financial institutions. Other relevant expertise will also be considered.
  • A university graduate of relevant disciplines (e.g. Accounting, Finance, Business Administration, Technology, etc.)
  • Possess at least one relevant professional qualification such as CPA, CIA, CISA, CISM, CISSP, CEH, CCSP / CCAK, CSX-P or other security related qualifications.
  • Strong understanding of industry cybersecurity standards such as National Institute of Standards and Technology (NIST) Cybersecurity Framework, ISO 27001, CIS, etc.
  • Strong understanding of the underlying IT & cybersecurity risks, application controls, assessment practices and various IT security software, operating systems, databases, cloud, networking technologies and emerging technology risks.
  • Team-oriented with a strong sense of ownership and individual accountability.
  • Independent and motivated with the ability to multi-task and remain organized.
  • Demonstrate agility and the ability to operate in a fast-changing environment.
  • Strong communication and relationship management skills.
  • Experience in leveraging data and technology an advantage.

HKEX is committed as an Equal Opportunity Employer. Diversity is one of our core values and we look to support, respect diverse perspectives, abilities, culture and experiences within our workplace.

Location:

HKEX - Exchange Square

Shift:

Standard - 40 Hours (Hong Kong SAR)

Scheduled Weekly Hours:

40

Worker Type:

Permanent

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Assistant Vice President, Information Technology Audit
Assistant Vice President, Information Technology Audit

Hong Kong Exchanges and Clearing Limited • Hong Kong

On-site
HKD 900,000 - 1,500,000
Associate, Information Technology Audit
Associate, Information Technology Audit

Hong Kong Exchanges and Clearing Limited (HKEX) • Hong Kong

On-site
HKD 500,000 - 800,000
Associate, Information Technology Audit
Associate, Information Technology Audit

Hong Kong Exchanges & Clearing Ltd • Hong Kong

On-site
HKD 600,000 - 900,000
Associate, Information Technology Audit
Associate, Information Technology Audit

Hong Kong Exchanges and Clearing Limited • Hong Kong

On-site
HKD 600,000 - 900,000
AVP, IT Audit & Cybersecurity Leader
AVP, IT Audit & Cybersecurity Leader

Hong Kong Exchanges and Clearing Limited (HKEX) • Hong Kong

On-site
HKD 900,000 - 1,500,000
Manager - Group Audit and Management Services (IT Audit) - IC
Manager - Group Audit and Management Services (IT Audit) - IC

Classy Wheeler Limited • Hong Kong

On-site
IT Audit Associate: Risk-Based Assurance & Controls
IT Audit Associate: Risk-Based Assurance & Controls

Hong Kong Exchanges and Clearing Limited • Hong Kong

On-site
HKD 600,000 - 900,000
Assistant IT Audit Manager (Job Ref: CW1378ITAA)
Assistant IT Audit Manager (Job Ref: CW1378ITAA)

Classy Wheeler Limited • Hong Kong

On-site
HKD 400,000 - 600,000
VP, IT Audit (Corporate Banking/Cyber Security/Technology Risk)
VP, IT Audit (Corporate Banking/Cyber Security/Technology Risk)

Randstad Hong Kong Limited • Hong Kong

On-site
HKD 900,000 - 1,300,000
Assistant Manager - Internal Audit (IT)
Assistant Manager - Internal Audit (IT)

Aviation Security Company Limited • Hong Kong

On-site
HKD 500,000 - 800,000
Generous fringe benefits