For Information Security:
-Formulate and revise the Company's information security policies, rules and technical standards, coach and supervise the Company's relevant teams to implement information security policies, rules and technical standards;
-Completed the Group's and the Company's security emergency response;
-Daily security education and training;
For Risk Compliance
-Compliance review of all internal & external function, such as ensuring that processes meet the ISO27001 MAS TRM policy standards and work with the Compliance Manager to manage risk.
-Advise on, and escalate, higher risk relationships and reputation risks arising from clients.
-Provide full support on all risk and compliance matter, including periodic report and submission to risk & compliance committee.
-Designing and implementing an overall risk management policies and processes for the organization
-Performing a risk assessment: Analyzing current risks and identifying potential risks that are affecting the company
-Explaining the external risk posed by corporate governance to stakeholders
-Creating business continuity plans to limit risks
-Conducting policy and compliance audits, which will include liaising with internal and external auditors
-Take prompt remedial actions to track and address audit findings.
-Identify, escalate, and perform root cause analysis on operational risks, addressing delays and risks proactively.
-Building risk awareness amongst staff by providing support and training within the company
Requirements:
-Familiar with information security technology system planning, mainly involving system security, network security, operation and maintenance security, data security, vulnerability management, big data analysis, etc.; familiar with major information security and security attack and defense technologies; understand the security control technology and implementation plan of the financial industry business system;
-Familiar with the theories and methods of information security assessment, the planning and construction of the security management and compliance certification system, involving national laws and regulations, industry regulatory requirements, grade protection assessment, internal and external compliance reinforcement and security audit technology, with rich practical experience;
-Having a certificate such as CISSP, CISA, CISM is preferred