Apply Edge Start your job search

VP/ ED, Technology Risk Management

Gravitas Recruitment Group (Global) Ltd · New Territories, Hong Kong SAR

Apply & track with Apply Edge
Role SummaryWe are seeking an experienced Technology Risk professional to join the Second Line of Defense (2LOD) Risk Management function. The successful candidate will be responsible for independently overseeing the firm's cybersecurity, information security, technology risk, and IT governance framework. This role will provide challenge, oversight, and assurance to the First Line of Defense while ensuring compliance with regulatory expectations and industry best practices.The position will play a key role in strengthening the organization's technology risk management capabilities, driving information security initiatives, and enhancing the overall cyber resilience of the firm.Key ResponsibilitiesAct as the Second Line of Defense (2LOD) for technology, cybersecurity, and information security risk oversight across the organization.Develop, maintain, and enhance the Technology Risk Management Framework, policies, standards, and governance processes.Independently assess, challenge, and monitor technology and cyber risks arising from infrastructure, applications, cloud platforms, and third-party providers.Oversee the effectiveness of cybersecurity and information security controls, ensuring risks are identified, assessed, and mitigated appropriately.Review security incidents, cyber threats, vulnerabilities, and remediation plans, providing independent challenge and escalation where necessary.Lead technology risk assessments for new products, systems, strategic initiatives, and outsourcing arrangements.Monitor key risk indicators (KRIs), risk appetite metrics, and technology risk exposures, reporting findings to senior management and risk committees.Coordinate regulatory examinations, internal and external audits, and ensure timely remediation of technology and information security findings.Provide subject matter expertise on technology risk, cybersecurity, IT governance, operational resilience, and regulatory requirements.Partner with Technology, Information Security, Compliance, Internal Audit, and business stakeholders to strengthen the firm's overall cyber resilience and risk culture.RequirementsBachelor's degree in Computer Science, Information Security, Information Systems, Technology Risk, Cybersecurity, or a related discipline.Minimum 8 years of experience in Information Security, Cybersecurity, Technology Risk, IT Risk, or IT Governance.Experience within banking, securities, asset management, insurance, fintech, or other regulated financial institutions is highly preferred.Strong understanding of cyber risk management frameworks and security control environments.Experience interacting with regulators, auditors, and senior management committees.Strong written and verbal communication skills in Mandarin.Interested parties please "apply" or send your resume to w.chung@gravitasgroup.com