Chief Information Security Office-Strategy, Programs & GRC AVP

Bank of China Limited, New York Branch

  • New York, New York
  • 4 days ago
  • $65,000–$150,000 Per Year
  • Full-time
Want to know if you’re a fit?
Upload your resume and let our AI show you.

Skills

  • Administrative Skillsunmatched
  • Auditingunmatched
  • Banking Regulationsunmatched
  • Banking Servicesunmatched
  • Best Practicesunmatched
  • Budgetingunmatched
  • Business Bankingunmatched
  • Business Processesunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Campaignsunmatched
  • Computer Scienceunmatched
  • Corporate Bankingunmatched
  • Cross-Functionalunmatched
  • Federal Laws and Regulationsunmatched
  • Financeunmatched
  • Financial Servicesunmatched
  • ISO (International Organization for Standardization)unmatched
  • IT Requirementsunmatched
  • Identify Issuesunmatched
  • Identity Data Managementunmatched
  • Industry Standardsunmatched
  • Information Technology & Information Systemsunmatched
  • Information Technology/Systems Auditunmatched
  • Information/Data Security (InfoSec)unmatched
  • Interpersonal Skillsunmatched
  • LCD (Liquid Crystal Display)unmatched
  • Maintain Complianceunmatched
  • Management of Information Systems/Technology (MIS)unmatched
  • Mathematicsunmatched
  • Metricsunmatched
  • Organizational Skillsunmatched
  • Phishingunmatched
  • Presentation/Verbal Skillsunmatched
  • Privacy Regulationsunmatched
  • Problem Solving Skillsunmatched
  • Project Developmentunmatched
  • Project Evaluationunmatched
  • Project Planningunmatched
  • Project Trackingunmatched
  • Project/Program Coordinationunmatched
  • Project/Program Managementunmatched
  • Regulationsunmatched
  • Regulatory Complianceunmatched
  • Reporting Dashboardsunmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Risk Managementunmatched
  • Root Cause Analysisunmatched
  • Strategic Planningunmatched
  • Systems Engineeringunmatched
  • Taxonomiesunmatched
  • Team Playerunmatched
  • Testingunmatched
  • Trading/Stockbrokingunmatched
  • Training Programunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • Writing Skillsunmatched

Description

Introduction:

Established in 1912, Bank of China is one of the largest banks in the world, with over $3 trillion in assets and a footprint that spans more than 60 countries and regions. Our long-term outlook, institutional weight and global breadth provide our clients with a stable and reliable financial partner, whether in Corporate or Personal Banking or our Trade Services, Commodities, Financial Institutions and Global Markets lines of business.

Overview:

This incumbent will provide Strategy, Programs, Governance, Risk and Compliance functions as required to fulfill BOCNY information security program requirements. This incumbent will provide Strategy Coordination, CISO Projects Management, Training & Culture, Metrics & Reporting, Governance, Risk Assessments, Compliance, Data Privacy and Identity functions as detailed below.

Responsibilities:

Strategy

  • Coordinate Information Security strategy in alignment with the BOCNY branch strategy.
  • Maintain strategic initiatives tracking and associated KRIs to track progress and execution of the objectives.
  • Conduct quarterly strategy reviews with the CISO team to ensure alignment and momentum continue. Adjust strategy as necessary.
  • Provide end-to-end project management function for all CISO led projects. 

Programs

  • Manage all CISO programs, including but not limited to: Information Security Program, Data Privacy Program, and Training & Culture Program including Security Training, Phishing Campaigns, and Tabletop Exercises.

Governance

  • Establish and maintain Information Security policies and procedures.
  • Ensure CISO roles and responsibilities are clearly delineated and documented to ensure efficiency, create synergies and ensure TISR is being properly managed across first and second lines.
  • Periodically refresh and update TISR controls guidance in relevant policies and supporting procedures with detailed implementation guidance.
  • Develop, monitor, and track CISO policy adherence measures and metrics.
  • Provide all administrative functions for the Information Security Committee and all its sub-committees. 

Risk

  • Establish and enhance a TISR framework that consists of the appropriate components to effectively manage TISR.
  • Conduct risk assessments of TISR for Projects, Third-Party, New Activities and Applications.
  • Develop and execute an TISR annual work plan of risk identification, assessment, and control evaluation and testing activities.
  • Review and contribute to the development and maintenance of the taxonomy for Risk, Process and Controls for TISR domains.
  • Catalog and oversee remediation of TISR issues include those arising from Audit and Regulatory exams, ITRM deep dives, root cause analyses and control testing.
  • Track observed control gaps and root causes and annually refresh CISO policy and procedures to reflect new and enhanced controls. 

Compliance

  • Prepare and submit Audit Requests for evidence.
  • Anticipate audit requests and prepare comprehensive approach to for CISO policy and standards and associated implementation.
  • Prepare response evidence for IT/IS related regulatory exams.
  • Recommend changes to policy, process or procedures to align with OCC and other federal guidelines and regulations.
  • Evaluate and provide evidence of compliance for BOCNY Branch.
  • Liaison with LCD/RAO/IAD to ensure collaboration and partnership so that CISO can meet regulatory IT/IS requirements. 

Data Privacy

  • Develop and implement strategies to ensure compliance with relevant privacy laws and regulations.
  • Stay up-to-date with changes in data privacy legislation and industry best practices.
  • Assist in the development and maintenance of privacy policies, standards and procedures.
  • Provide oversight and monitoring of privacy risk assessments by the FLUs.
  • Ensure all relevant processes reflect privacy requirements and comply with laws and regulations.
  • Plan and implement privacy training programs and communications.
  • Identify and assess privacy risks within the organization. 

Metrics & Reporting

  • Manage all metrics and reporting for CISO, including: Operational, Executive & Board, Budget & Headcount, Dashboards.

Identity & Access Management

  • Establish and periodically update policies, procedures, and guidelines related to access recertification, incorporating industry best practices.
  • Manage the end-to-end process of user access reviews, including planning, execution, tracking, and resolution of identified issues.
  • Conduct periodic User Recertification & Access Reviews throughout all BOC applications to ensure consistency and accuracy.
  • Collaborate with cross-functional teams, including IT, OSD, and business units, to align access governance with broader organizational goals.
  • Conduct periodic assessments of user access governance processes, identifying opportunities for improvement and implementing necessary enhancements.
Qualifications:
  • Bachelor’s Degree in Business, Risk, Data, Computer Science, Management Information Systems, Engineering, Mathematics, or related field
  • Minimum 5 years of work experience in Risk Management, Audit, IT/IS Operations, or other relevant functions
  • Minimum 3 years of experience in developing and executing IT/IS Risk programs, projects, and policies
  • Minimum 1 year of experience working with US Banking Regulations, financial industry standards, and industry standard IT/IS Risk Frameworks
  • Strong program, frameworks, project management development, implementation, and maintenance skills
  • Strong writing skills, especially in the context of governing documents, such as policies and standards
  • Strong verbal and interpersonal skills when working with a diverse group of stakeholders that can include senior management, business staff, and technical staff
  • Creative problem-solving skills
  • Strong organizational understanding and ability to navigate complex organizations
  • Results oriented and metrics driven
  • Understanding of financial services business and related processes and IT/IS risks and how to mitigate with well-designed, commercially sound controls
  • Operational and IT/IS risk assessment and management skills in first, second, and/or third line capacity
  • Sound and practical IT/IS risk management and program knowledge
  • Financial / banking industry, business line, and product knowledge
  • Familiarity with IT/IS Risk Management regulations, standards, and frameworks including NIST, ISO27002, FFIEC Guidelines, etc.
  • Risk identification and assessments of different types that are commensurate with the size and complexity of the financial institution
  • IT/IS risk management and audit principles and industry standard practices
  • CISSP/CRISC/ or IT related certifications preferred
Pay Range

Actual salary is commensurate with candidate’s relevant years of experience, skillset, education and other qualifications.

: USD $65,000.00 - USD $150,000.00 /Yr.

Numbers & Facts

LocationNew York, New York
Job TypeFull-time
Salary$65,000–$150,000 Per Year

Similar Jobs

See more jobs