about the company.
Our client is a highly prestigious, top-tier commercial banking group with a prominent international network and a deeply established presence in Hong Kong. Renowned for their extensive corporate banking platform and global trade finance networks, they offer a secure and capital-backed operating environment. They provide employees with structured executive career progression, high cross-regional visibility, and a stable work culture.
about the team.
The Regional IT Audit team is a high-visibility control function reporting directly to the Regional Head of Audit and the global executive board. You will lead an experienced team of technology risk, cybersecurity, and data audit specialists operating in a fast-paced and intellectually stimulating environment. The team culture highly values technical mastery, collaborative problem-solving, and continuous professional development.
about the job.
- Lead and execute complex, risk-based IT audit engagements across corporate banking applications, network infrastructure, cybersecurity frameworks, and data centers.
- Evaluate the adequacy and operational effectiveness of IT general controls (ITGC), application controls, and business continuity management systems.
- Ensure all information technology and cyber resilience frameworks strictly align with HKMA Supervisory Policy Manuals (e.g., TM-E-1, OR-2) and statutory regulations.
- Formulate high-quality, concise, and impactful IT audit reports for executive management, outlining key technology risks and practical remediation strategies.
- Partner with the Chief Information Officer (CIO), Chief Information Security Officer (CISO), and technology heads to provide strategic pre-implementation advice on major core banking upgrades.
- Mentor and manage a dedicated team of IT auditors, fostering continuous learning and driving the adoption of automated data analytics audit tools.
skills & experience required.
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related discipline.
- CISA, CISSP, CISM, or equivalent professional information technology security/audit qualification is preferred.
- Minimum 8 years of experience in IT audit, technology risk, or cybersecurity assurance within a global bank, corporate bank, or Big 4 financial services practice.
- Deep technical expertise in cloud security architecture, infrastructure networks, devops, and HKMA regulatory technology frameworks.
- Exceptional communication and stakeholder management skills, with a proven track record of facilitating complex technical risk discussions with executive business leaders.
- Fluency in English and Chinese is mandatory to effectively collaborate across regional business units and stakeholders.
If you are interested in this role, please click 'Apply Now' or send your CV directly to Marco.li@randstad.com.hk.
...