Chief Information Security Office-Strategy, Programs & GRC AVP at Bank of China Limited, New York Branch | New York, United States | Rezi

Chief Information Security Office-Strategy, Programs & GRC AVP at Bank of China Limited, New York Branch

Chief Information Security Office-Strategy, Programs & GRC AVP

Bank of China Limited, New York Branch · New York, United States

1 weeks ago

Chief Information Security Office-Strategy, Programs & GRC AVP

Bank of China Limited, New York Branch · New York, United States

10 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

This incumbent will provide Strategy, Programs, Governance, Risk and Compliance functions as required to fulfill BOCNY information security program requirements. This incumbent will provide Strategy Coordination, CISO Projects Management, Training & Culture, Metrics & Reporting, Governance, Risk Assessments, Compliance, Data Privacy and Identity functions.

Responsibilities

  • Coordinate Information Security strategy in alignment with the BOCNY branch strategy.
  • Maintain strategic initiatives tracking and associated KRIs to track progress and execution of the objectives.
  • Conduct quarterly strategy reviews with the CISO team to ensure alignment and momentum continue.
  • Provide end-to-end project management function for all CISO led projects.
  • Manage all CISO programs, including Information Security Program, Data Privacy Program, and Training & Culture Program.
  • Establish and maintain Information Security policies and procedures.
  • Ensure CISO roles and responsibilities are clearly delineated and documented.
  • Periodically refresh and update TISR controls guidance in relevant policies and supporting procedures.
  • Develop, monitor, and track CISO policy adherence measures and metrics.
  • Provide all administrative functions for the Information Security Committee and all its sub-committees.
  • Establish and enhance a TISR framework that consists of the appropriate components to effectively manage TISR.
  • Conduct risk assessments of TISR for Projects, Third-Party, New Activities and Applications.
  • Develop and execute an TISR annual work plan of risk identification, assessment, and control evaluation and testing activities.
  • Review and contribute to the development and maintenance of the taxonomy for Risk, Process and Controls for TISR domains.
  • Catalog and oversee remediation of TISR issues.
  • Track observed control gaps and root causes and annually refresh CISO policy and procedures.
  • Prepare and submit Audit Requests for evidence.
  • Anticipate audit requests and prepare comprehensive approach for CISO policy and standards.
  • Prepare response evidence for IT/IS related regulatory exams.
  • Recommend changes to policy, process or procedures to align with OCC and other federal guidelines and regulations.
  • Evaluate and provide evidence of compliance for BOCNY Branch.
  • Liaison with LCD/RAO/IAD to ensure collaboration and partnership.
  • Develop and implement strategies to ensure compliance with relevant privacy laws and regulations.
  • Stay up-to-date with changes in data privacy legislation and industry best practices.
  • Assist in the development and maintenance of privacy policies, standards and procedures.
  • Provide oversight and monitoring of privacy risk assessments by the FLUs.
  • Ensure all relevant processes reflect privacy requirements and comply with laws and regulations.
  • Plan and implement privacy training programs and communications.
  • Identify and assess privacy risks within the organization.
  • Manage all metrics and reporting for CISO, including Operational, Executive & Board, Budget & Headcount, Dashboards.
  • Establish and periodically update policies, procedures, and guidelines related to access recertification.
  • Manage the end-to-end process of user access reviews.
  • Conduct periodic User Recertification & Access Reviews throughout all BOC applications.
  • Collaborate with cross-functional teams to align access governance with broader organizational goals.
  • Conduct periodic assessments of user access governance processes, identifying opportunities for improvement.

Requirements

  • Bachelor’s Degree in Business, Risk, Data, Computer Science, Management Information Systems, Engineering, Mathematics, or related field
  • Minimum 5 years of work experience in Risk Management, Audit, IT/IS Operations, or other relevant functions
  • Minimum 3 years of experience in developing and executing IT/IS Risk programs, projects, and policies
  • Minimum 1 year of experience working with US Banking Regulations, financial industry standards, and industry standard IT/IS Risk Frameworks
  • Strong program, frameworks, project management development, implementation, and maintenance skills
  • Strong writing skills, especially in the context of governing documents, such as policies and standards
  • Strong verbal and interpersonal skills when working with a diverse group of stakeholders
  • Creative problem-solving skills
  • Strong organizational understanding and ability to navigate complex organizations
  • Results oriented and metrics driven
  • Understanding of financial services business and related processes and IT/IS risks and how to mitigate with well-designed, commercially sound controls
  • Operational and IT/IS risk assessment and management skills in first, second, and/or third line capacity
  • Sound and practical IT/IS risk management and program knowledge
  • Financial / banking industry, business line, and product knowledge
  • Familiarity with IT/IS Risk Management regulations, standards, and frameworks including NIST, ISO27002, FFIEC Guidelines, etc.
  • Risk identification and assessments of different types that are commensurate with the size and complexity of the financial institution
  • IT/IS risk management and audit principles and industry standard practices

Skills

  • Information Security
  • Project Management
  • Data Privacy
  • Risk Assessment
  • Compliance
  • Metrics & Reporting
  • Identity & Access Management
  • NIST
  • ISO27002
  • FFIEC Guidelines

Location

  • New York

Work Type

  • Full-time

Experience Level

  • Minimum 5 years of work experience
  • Minimum 3 years of experience
  • Minimum 1 year of experience

Education Level

  • Bachelor’s Degree

Salary/Compensations

  • USD $65,000.00 - USD $150,000.00 /Yr.

Benefits

  • CISSP/CRISC/ or IT related certifications preferred

About the Company

  • Established in 1912, Bank of China is one of the largest banks in the world, with over $3 trillion in assets and a footprint that spans more than 60 countries and regions.
  • Our long-term outlook, institutional weight and global breadth provide our clients with a stable and reliable financial partner, whether in Corporate or Personal Banking or our Trade Services, Commodities, Financial Institutions and Global Markets lines of business.