Principal Responsibilities
The Technology team sits under the Chief Information Officer who reports to the Country Chief Operating Officer. This job is part of the CIO's team providing oversight of the risk and control environment across Technology and the Singapore market. The job is particularly critical with the increased regulatory focus on Technology and Cybersecurity (TCS) risks, as well as technology and operational resiliency, as evidenced by the heightened regulatory expectations in recent months.
This job acts as a First Line of Defence and ensures the Bank operates within its risk appetite by providing specialist risk and control knowledge and insights, promoting risk and control monitoring and decision-making.
Key responsibilities of this role include:
- Non-financial Risk management –ensure that the Risk Framework is appropriately used for decision making; encourage best practices that ensure all procedures are well documented and regulatory policies are up to date and encourage evaluation of the design effectiveness of the Risk Framework to ensure the promotion of continuous improvement
- Review and Challenge – support Risk and control (R&C) challenge activity, scenario testing and deep dive assurance activities as required; and take an active role in 1LOD and 2LOD TCS related meetings, committees and forums offering constructive and informed input and challenge.
- Timely Escalation - alert and escalate TCS issues and incidents, any significant changes to the TCS risk environment, deteriorating risk exposures, new vulnerabilities or evidence of the crystallisation of emerging risks to senior management in a timely manner.
- Control Advisory – first point of contact to provide TCS related advice and support to the TCS teams and support the ongoing development of the TCS risk and control environment; support the TCS teams through audits, assurance reviews etc. and ensure the outcomes are appropriate with the risks clearly identified
- Governance - support the Singapore CIO HSBC to ensure effective TCS risk oversight and governance, working closely with the TCS risk stewards in 2LOD
- Regulatory Support – support the TCS teams in their interactions with Regulators e.g. inspections, surveys, consultation papers, responses etc. and review and challenge all responses and submissions to the Regulators
- Change Execution – support the TCS teams to manage internally or externally driven changes impacting TCS risks, working with stakeholders across the Bank where required and driving the change until closure/completion
Qualifications
The role holder will have knowledge, skills and experience in the following areas:
- Deep and proven SME knowledge within cyber and/or technology and/or data and operational resilience, with proven experience of working in a Technology related risk function with strong knowledge of applying the relevant risk and controls measures.
- In depth knowledge and experience of implementing non-financial risk frameworks and managing non-financial risks consistently and effectively in line with the agreed risk appetite, preferably in a large financial organization
- Ability to present complex Technology concepts, solutions etc. clearly to non-technical stakeholders in a credible manner and demonstrate a strong awareness of the business dependency on Technology and Cyber
- Ability to methodically analyse complex sets of data and requirements and provide an accountable SME opinion or challenge, and provide direction to 1LOD and Business stakeholders to ensure they fulfil the requirements to manage Resilience Risk within appetite.
- Ability to effectively manage a complex and varied set of stakeholders, and confident to work across cultures
- Outstanding interpersonal skills, coupled with the ability to succeed within a matrix management structure and build and maintain regional and global team relationships and a proven ability to communicate effectively and confidently at all levels across the Group
- Build and maintain relevant cross-organisation and industry relationships to keep up to date on the external TCS risk landscape and provide a benchmarking view of HSBC Singapore against peer activity
- Ability to authentically engage with team, colleagues and business partners to deliver at pace
- Strong knowledge of the external environment – regulatory, political, competitors etc.
- High level of personal drive and motivation to ensure delivery of a broad range of outputs simultaneously across HSBC
- Proven experience of positive, challenging interactions with senior stakeholders that results in successful delivery
- Excellent relationship management, collaboration and influencing skills
- Practical experience of major business transformation activities is preferred but not essential
- Strong understanding of HSBC structures, processes and objectives across the Group (if recruiting internally)
- Strong knowledge of Technology in other organisations – functionally, operationally and financially
- Extensive experience in banking/ financial services, preferably in a global organization
- Educated to graduate degree level in technology, cyber or risk related field or associated relevant business experience
- Excellent verbal and writing skills, able to articulate complex issues concisely and in simple language to support the problem analysis, assessment etc.