- Performing risk assessments of the Digital Bank's Information Technology environment and assisting in developing the annual audit plan
- Performing IT audits of relevant regulatory requirements (e.g. HKMA SPM TM-E-1, TM-E-2, TM-G-1, TM-G-2, SA-2)
- Deploying AI techniques in to analyze data to improve audit efficiency and effectiveness, ultimately be a source for analytics that business units adopt to provide business insights or for continuous auditing
- Planning and executing IT infrastructure and application audits and working closely with the general auditors on integrated audits
- Assessing risk, exposure and controls regarding new systems / processes or changes to the current environment and performing pre-implementation reviews where appropriate
- Identifying emerging IT risks, drafting and reporting audit findings promptly to line management and senior management, and suggesting practical and innovative solutions
- Following up audit recommendations post-audit, assessing residual risk, validating remedial work performed and documenting and closing issues
- Performing and documenting aspects of Internal Audit's continuous monitoring program for IT, in order to identify changes to risk assessments, audit plan
- Identifying emerging IT risks and control themes to be included in management and Audit Committee presentations
Key Requirements:
- University graduates or above in related disciplines, e.g. Engineering, Accounting, Business, Computer Sciences, etc.
- At least 3 years of relevant experience in IT audit, IT controls, IT implementation/consulting
- Professional IT audit qualifications, e.g. CISA, CISSP or CISM, are added advantages.
- Good understanding of the banking industry and possess strong technical knowledge.
- Sound knowledge of cyber-security related regulatory requirements and best practices.
- Good understanding of cloud infrastructure, experience in auditing cloud platforms would be an advantage.
- Good interpersonal skills with the ability to present complex and sensitive issues to senior management, and influence change.
- Willing to learn and apply AI techniques in performing IT audit jobs to enhance audit efficiency, effectiveness and insights
- Able to work independently and proactively, demonstrating a strong sense of ownership and commitment to delivery quality audits on time.
- Confidence to deliver tough messages and engage in difficult conversations.
- Excellent verbal and written communication skills in English and Chinese.
Mandatory Reference Checking Scheme
Mandatory Reference Checking Scheme (MRC Scheme) may be applicable for certain relevant positions. It is a standardised reference-checking arrangement that is designed to support the integrity of "authorized institutions" regulated by the Hong Kong Monetary Authority (HKMA). Pursuant to the MRC scheme, our Bank will conduct a mandatory reference check by requesting information from each relevant former and current employer of applicants. For more details about the MRC Scheme, please visit the website of the Hong Kong Association of Banks: https://www.hkab.org.hk/en/page/5/mandatory-reference-checking-scheme-phase-2
Applicants who are not invited for an interview within the 8 weeks after submission of application may assume their applications unsuccessful. We may review applications received for suitability for other posts within the Company. All personal data provided will be treated in strict confidence and used strictly for recruitment-related purposes only. We shall retain the personal data of unsuccessful applicants for a period of 24 months upon receipt of such application.