Vice President, Information Security and Digital Risk Management

OCBC

Hong Kong

On-site

HKD 900,000 - 1,300,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Competitive base salary
Holistic benefits package
Learning and development opportunities

Job summary

OCBC Bank seeks a senior information security and technology risk professional to reinforce governance under ISDRM. The role reports to the Head of ISDRM and supports risk oversight across technology, data and cyber domains.

The candidate will drive risk framework enhancements, lead risk reporting to Board, and provide independent challenge on new tech and fintech initiatives. Strong communication with tech and business stakeholders is essential.

Qualifications

  • University degree in technology, computer science, information security, business, risk management, or related discipline.
  • Professional certifications such as CISM, CISSP, CISA under ECF on cybersecurity for second line of defence.

Responsibilities

  • Support the implementation and enhancement of the Bank’s risk management framework for technology, information and cyber risk.
  • Formulate and update risk management policies and guidelines aligned with Group standards and regulatory expectations.
  • Act as secretariat for ISDRM risk management committee and represent ISDRM in governance meetings.
  • Prepare risk reports and metrics to Board and senior management with clear insights into risk posture.
  • Provide independent advice on risk domains for new products and strategic digital initiatives.
  • Lead or participate in reviews related to emerging risks and regulatory requirements.
  • Monitor first-line risk management activities and ensure key controls are implemented.
  • Coordinate risk awareness, training and testing programs across the Bank.
  • Drive information risk mitigations and remote access controls.

Skills

Risk management
Information security
Stakeholder management
Communication

Education

University degree in Technology/CS/Info Security/Business/Risk Management

Tools

CISM
CISSP
CISA

Job description

Job Summary

This position reports into and supports the Head of Information Security and Digital Risk Management (ISDRM). As part of the second line under the Three Lines Model, ISDRM is responsible for establishing, maintaining and enhancing governance and oversight of the Bank’s technology, information, and cyber risk domains.

What You Will Be Doing
  • Support the implementation and continuous enhancement of the Bank’s technology, information and cyber risk management framework, in collaboration with relevant stakeholders including Group counterparts, technology teams, business and support units, and other risk management functions.
  • Formulate, review and update risk management framework, policies and guidelines, ensuring alignment with applicable Group standards, supervisory expectations, and industry best practices.
  • Act as secretariat for ISDRM-related risk management committee and working groups, and represent ISDRM at relevant Group and local risk governance meetings and forums as required.
  • Prepare and deliver regular risk reports, analyses and metrics (e.g. KRIs) to the Board and senior management, providing clear insights into the Bank’s overall risk posture.
  • Provide independent advice, support and effective challenge on technology, information and cyber risk domains associated with new products, major technology or Fintech initiatives, strategic digital transformation projects and third‑party arrangements (e.g. cloud computing).
  • Lead or participate in thematic reviews and compliance assessments related to emerging risks (e.g. AI‑enabled attacks) and regulatory requirements (e.g. facilitation of CRAF Maturity Assessment & iCAST).
  • Monitor and perform independent review of specific aspects of first‑line risk management activities, including risk assessment and acceptance, incident response, change management processes, and the implementation of key controls or remediation actions.
  • Collaborate with Group counterparts to plan and deliver risk awareness, training and testing programmes to enhance staff awareness and vigilance across the Bank.
  • Drive and oversee the implementation of Bank-wide information risk mitigation initiatives, including enhancements to data loss prevention controls, application remote access controls, and the detection and management of system access misuse.
  • Coordinate and facilitate internal and external audits, regulatory examinations and ongoing regulatory communications relating to technology, information and cyber risk domains.
Who Are We Looking For
  • A university degree in Technology, Computer Science, Information Security, Business, Risk Management, or a related discipline.
  • Relevant professional certifications such as CISM, CISSP, CISA under the Enhanced Competency Framework (ECF) on Cybersecurity for a second line of defence role required.
  • A minimum of 7 years of relevant experience in information security, cyber/technology risk management or technology audit, gained within the financial services industry (FSI) or professional services firms serving FSI clients.
  • Strong risk management mindset with a solid understanding of IT environments, evolving threat landscapes, and technology/information/cyber security controls, including relevant industry standards (e.g. ISO/IEC27001) and regulatory guidelines (e.g. HKMA’s SPM TM‑G‑1, C‑RAF).
  • Good communication, presentation and stakeholder management skills, with the ability to engage effectively with both technical and non‑technical stakeholders at various levels and articulate complex risk issues clearly and confidently.
  • Proven ability to provide constructive challenge and influence risk‑informed decision‑making through practical, balanced, and commercially sound recommendations.
  • Demonstrates sound judgement, with the ability to prioritise issues, assess materiality, and escalation risk issues appropriately.
  • Self‑motivated, well‑organised and able to work independently while contributing effectively in a collaborative team environment.
  • Good command of both spoken and written English and Chinese.
  • Experience in conducting risk assessments, threat modelling or audits will be an advantage.
What We Offer

Competitive base salary. A suite of holistic, flexible benefits to suit every lifestyle. Community initiatives. Industry‑leading learning and professional development opportunities. Your wellbeing, growth and aspirations are every bit as cared for as the needs of our customers.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Technology Risk Manager (Information Security Control Division)
Technology Risk Manager (Information Security Control Division)

Bank of China (Hong Kong) • Hong Kong

On-site
HKD 450,000 - 650,000
Medical insurance
Life insurance
Allowances
(Senior) echnology Risk Manager (Cyber Security Control Division)
(Senior) echnology Risk Manager (Cyber Security Control Division)

Bank of China (Hong Kong) • Hong Kong

On-site
HKD 500,000 - 800,000
Medical insurance
Life insurance
Various allowances
(Senior) Technology Risk Manager (Cyber Security Control Division)
(Senior) Technology Risk Manager (Cyber Security Control Division)

Bank of China (Hong Kong) Limited • Hong Kong

On-site
HKD 420,000 - 750,000
(Senior) Technology Risk Manager (Cyber Security Control Division)
(Senior) Technology Risk Manager (Cyber Security Control Division)

Hong Kong Job Consulting • Hong Kong

On-site
HKD 700,000 - 1,000,000
Technology Risk Manager (Information Security Control Division)
Technology Risk Manager (Information Security Control Division)

Bank of China (Hong Kong) Limited • Hong Kong

On-site
HKD 700,000 - 1,000,000
SVP/ VP, Cybersecurity & Governance
SVP/ VP, Cybersecurity & Governance

Michael Page International (HK) Ltd • Hong Kong

On-site
HKD 800,000 - 1,200,000
Collaborative work environment
Exposure to cutting-edge technology
Cybersecurity Manager (Technical Controls, Infrastructure Security) (Bank)
Cybersecurity Manager (Technical Controls, Infrastructure Security) (Bank)

Classy Wheeler Limited • Hong Kong

On-site
HKD 800,000 - 1,200,000
(Senior) Technology Risk Manager (2nd line of defense)
(Senior) Technology Risk Manager (2nd line of defense)

Bank Of China (Hong Kong) Limited • Hong Kong

On-site
HKD 800,000 - 1,200,000
Technology Risk & Compliance
Technology Risk & Compliance

Moore Stephens Hong Kong • Hong Kong

On-site
HKD 520,000 - 860,000
Competitive compensation
Non-Financial Risk Manager - CTIS - Executive Director
Non-Financial Risk Manager - CTIS - Executive Director

Morgan Stanley • Hong Kong

On-site
HKD 1,500,000 - 2,000,000