Technology Risk Management Manager (Quản lý Quản trị rủi ro Công nghệ thông tin)

Manager
CompanyPHKL Prudential Hong Kong
LocationThành phố Hồ Chí Minh
Category-
SeniorityManager
Workplace-
Posted2026-09-24
Viaworkday

Description

Prudential’s purpose is to be partners for every life and protectors for every future. Our purpose encourages everything we do by creating a culture in which diversity is celebrated and inclusion assured, for our people, customers, and partners. We provide a platform for our people to do their best work and make an impact to the business, and we support our people’s career ambitions. We pledge to make Prudential a place where you can Connect, Grow, and Succeed.

Job Purpose / Mục tiêu vị trí

This role is to:

Vị trí này giúp:

  • Provide assurance and oversight on information and technology risks that might pose a threat to the business. Đảm bảo và giám sát các rủi ro thông tin và công nghệ có thể gây ra mối đe dọa cho doanh nghiệp.
  • Provide Local Business Units (LBU) management with objective analysis, detailed observations and recommendations relating to key information and technology risk areas to mitigate the spectrum of risks relating to the achievement of the LBU’s business operations. Cung cấp cho ban quản lý công ty những phân tích khách quan, quan sát chi tiết và đề xuất liên quan đến các lĩnh vực rủi ro công nghệ và thông tin trọng yếu để giảm thiểu các rủi ro liên quan đến việc đạt được các hoạt động kinh doanh của LBU.
  • Provide oversight and assurance within the LBU that processes, tools, and technologies are operating effectively to mitigate risks to information and technology assets. Giám sát và đảm bảo trong công ty rằng các quy trình, công cụ và công nghệ đang hoạt động hiệu quả để giảm thiểu rủi ro đối với thông tin và tài sản công nghệ.
  • Monitor and review the effectiveness of implementation of information technology, security and data protection standards, policies, and procedures within the LBU to ensure compliance with regulatory, Group, and LBU specific policy requirements. Theo dõi và đánh giá hiệu quả của việc triển khai các tiêu chuẩn, chính sách và thủ tục về công nghệ thông tin, bảo mật và bảo vệ dữ liệu trong công ty để đảm bảo tuân thủ các yêu cầu chính sách cụ thể của cơ quan chức năng, của Tập đoàn và của công ty.
  • Support LBU operational functions as required to manage risks to information and technology assets appropriately. Hỗ trợ các chức năng vận hành của công ty theo yêu cầu để quản lý rủi ro đối với tài sản công nghệ và thông tin một cách phù hợp
  • Provide independent, objective assurance that information and technology risks are being managed to ensure they are within the risk appetite approved by the Board. Đảm bảo tính độc lập, khách quan rằng các rủi ro thông tin và công nghệ đang được quản lý để đảm bảo những rủi ro này nằm trong khẩu vị rủi ro đã được Hội đồng quản trị phê duyệt.
  • Work closely with the Group Technology Risk Management team to roll out and ensure the effective implementation of information and technology risk frameworks, policies, processes, and other initiatives. Phối hợp chặt chẽ với nhóm Quản lý Rủi ro Công nghệ của Tập đoàn để triển khai và đảm bảo triển khai hiệu quả các khuôn khổ, chính sách, quy trình và các sáng kiến khác về rủi ro công nghệ và thông tin

##

Job Responsibilities / Phạm vi công việc

Thực hiện các hoạt động quản trị/ kiểm tra kiểm soát / tư vấn cho doanh nghiệp:

  • Perform oversight of information technology incidents including security and privacy incidents. Ensure proper escalation of incidents as per LBU incident management process and group Cyber Security Incident Respond Plan. Review the recovery, remedial, and preventive actions taken by 1st Line is effective in managing IT incidents. Giám sát sự cố CNTT bao gồm sự có bảo mật và quyền riêng tư. Đảm bảo báo cáo sự cố đúng theo quy trình quản lý sự cố cấp Công ty và cấp Tập đoàn CSIRP. Kiểm tra lại các hành động khôi phục, khắc phục và phòng ngừa do tuyến phòng ngự số 1 thực hiện có hiệu quả trong việc quản lý các sự cố.
  • Review the effectiveness and completeness of the Risk and Control Self-Assessment (RCSA). Ensuring that risks are properly articulated, controls are effective in ensuring risk are adequately managed. Performs control testing for key Technology and Privacy related risk as part of RCSA. Xem xét tính hiệu quả và tính đầy đủ của quy trình RCSA (Quy trình tự đánh giá rủi ro và kiểm soát). Đảm bảo rằng rủi ro được xác định rõ rang, các biện pháp kiểm soát có hiệu quả trong việc đảm bảo rủi ro được quản lý đầy đủ. Thực hiện kiểm tra kiểm soát đối với rủi ro chính liên quan đến Công nghệ và Quyền riêng tư như một phần của RCSA.
  • Review accuracy/ completeness of reporting, ensuring Technology risks are properly identified and articulated. Prepare and submit Technology Risk update to LBU risk committee/ relevant forum. Collect data for Key Risk Indicators (KRI) reporting. Xem xét tính chính xác/ đầy đủ của báo cáo, đảm bảo các rủi ro về CNTT được xác định và trình bày rõ ràng. Chuẩn bị và gửi bản cập nhật rủi ro CNTT cho ủy ban rủi ro LBU/ diễn đàn có liên quan. Thu thập dữ liệu cho báo cáo KRI.
  • Review Business Information Security Governance (BISG) metrics trend and review the effectiveness of actions/ controls implemented by 1st line. Escalate overdue issues and gaps to senior management/ and Risk Committee where appropriate. Xem xét xu hướng các chỉ số quản trị BISG và đánh giá hiệu quả của các hành động/ kiểm soát được thực hiện bởi tuyến đầu tiên. Báo cáo các vấn đề và lỗ hổng quá hạn cho quản lý cấp cao/ và Ủy ban quản lý rủi ro khi thích hợp.
  • Review the completeness and effectiveness of the training and awareness session conducted by 1st line. Enhance TRM in 1st line by conducting training/coaching. Xem xét tính đầy đủ và hiệu quả của buổi đào tạo và nâng cao nhận thức do tuyến 1 thực hiện. Tăng cường TRM ở tuyến đầu tiên bằng cách tiến hành đào tạo/huấn luyện.
  • Pre-audit review of effectiveness of controls (ideally should be on on-going basis). Review completeness of Issue Self-identified and Being Actioned by Management (ISBAM). Đánh giá trước về tính hiệu quả của các biện pháp kiểm soát (lý tưởng nhất là nên thực hiện liên tục). Đánh giá tính đầy đủ của ISBAM.
  • Conduct frequent deep dive review on the completeness and adequacy of documentation, controls, ensuring that risk is properly articulated, and controls are in place e.g., Risk and Materiality Assessment, Critical System Assessment, Cloud Risk Assessment, Could Consultation Presentation, Internet Insurance Attestation, etc. Tiến hành đánh giá sâu thường xuyên về tính đầy đủ và thỏa đáng của tài liệu, các biện pháp kiểm soát, đảm bảo rằng rủi ro được trình bày rõ rang và các biện pháp kiểm soát được áp dụng, ví dụ: Đánh giá rủi ro và tính trọng yếu, Đánh giá hệ thống trọng yếu, Đánh giá rủi ro Cloud, Trình bày tư vấn Cloud, Chứng nhận bảo hiểm Intetnet, v.v
  • Review and ensure access (e.g., Cloud Storage, SFTP, RMD) are properly reviewed and approval is valid with proper business justification. Xem xét và đảm bảo quyền truy cập (ví dụ: Lưu trữ đám mây, SFTP, RMD) được xem xét đúng cách và phê duyệt hợp lệ với lý do kinh doanh phù hợp.
  • Review the completeness and adequacy of the review performed by 1st line for Privacy Impact Analysis and SIT. Xem xét tính đầy đủ và thỏa đáng của đánh giá do tuyến đầu tiên thực hiện đối với PIA và SIT.
  • Review the completeness and adequacy of the review performed by 1st line for TISQ. Xem xét tính đầy đủ và thỏa đáng của đánh giá được thực hiện bởi dòng đầu tiên cho TISQ.
  • For DLP rules, review and ensure access is properly reviewed and approval is valid with proper business justification. Review DLP rules and effectiveness of DLP controls. Đối với các quy tắc DLP, xem xét và đảm bảo quyền truy cập được xem xét đúng cách và phê duyệt hợp lệ với lý do kinh doanh phù hợp. Xem xét các quy tắc DLP và hiệu quả của các biện pháp kiểm soát DLP.
  • Provide SME support to identify technology risks from the early stages of digitalization projects /process in the Company. Tư vấn, hỗ trợ nhận diện sớm các rủi ro CNTT liên quan đến các dự án / quy trình số hóa trong công ty.

Othe