Job responsibilities
- Act as the project manager to responsible for data, privacy and project management in CAO Office
- Support to define and execute on global and local data and privacy strategy and responsible for data governance and privacy protection
- Conducted business & technical analysis related to Data Risk and Privacy Metrics
- Formalize data sourcing, reporting implementation and onshore system integration processes need to be documented (gap analysis vs JPM if processes already exist)
- Maintain procedural documents related to data and privacy governance framework, including data use, data quality, data protection, retention & destruction, DPIA, privacy incident investigation
- Participate in cross border data triage working group to facilitate cross border data sharing requests
- Support CAO Office projects related work as requested
Required qualifications, capabilities, and skills
- Bachelor’s Degree in Computer Science, Cybersecurity, Data Science, or related disciplines
- 7+ years of experience or equivalent expertise in technology risk management, information security, or a related field, with a focus on managing risk identification, assessment, and mitigation.
- Hands-on practical experience delivering enterprise level cybersecurity solutions and controls
- Advanced knowledge of cybersecurity architecture, applications, data security, risk assessment & reporting, control evaluation, design, and governance, with a proven record of implementing effective risk mitigation strategies
- Ability to tackle design and functionality problems independently with little to no oversight
- Familiarity with risk management frameworks, industry standards, and financial industry regulatory requirements
- Demonstrated ability to influence executive-level strategic decision-making and translating technology insights into business strategies for senior executives
Preferred qualifications, capabilities, and skills
- In-depth knowledge of the financial services industry and their IT systems
- CISM, CRISC, CISSP, or similar industry-recognized risk and risk certifications are preferred