Technology Audit and Advisory - Manager / Senior Manager
About the job
About Protiviti
Protiviti is a global consulting firm that helps leaders face the future with confidence. We deliver deep expertise and objective insights across technology, cybersecurity, digital transformation, risk management, compliance, governance, internal audit, and business performance improvement. Our 11,000+ professionals operate across 90+ offices worldwide, serving over 80% of the Fortune 100 and nearly 80% of Fortune 500 companies. Protiviti Inc. is a wholly owned subsidiary of Robert Half (NYSE: RHI).
Why Join Protiviti?
- Work on diverse and meaningful IT audit and technology risk engagements.
- Gain exposure to leading financial institutions and multinational organisations.
- Broaden your expertise across IT governance, ITGCs, cloud, data privacy, risk management and operational resilience.
- Collaborate with experienced professionals and subject-matter specialists across Protiviti's global network.
- Use innovative tools, data analytics and technology-enabled approaches to deliver greater client value.
- Develop your leadership capabilities and advance your career in a collaborative, supportive and entrepreneurial environment.
About Services
Organisations face growing technology risks, regulatory expectations and operational costs. However, technology risk and its potential business impact are not always fully considered in business decision-making. Our Technology Audit and Advisory services help clients understand their technology risk exposure and enhance the effectiveness of their controls. As a Technology Risk Specialist, you will guide clients in managing technology risks, addressing regulatory requirements and enhancing technology governance, controls and resilience.
We are now seeking Manager / Senior Manager to join the team. The individual will help the Managing Director to manage the team, engagements and client relationships.
Major responsibilities:
- Lead and manage IT audit, IT SOX, technology risk, data privacy assessment and regulatory compliance review for banks, securities firms, insurers, asset managers and multinational organisations.
- Develop the design and operating effectiveness of technology controls and evaluate clients' control environments against regulatory requirements, industry standards and leading practices.
- Conduct technology governance, cybersecurity and regulatory compliance reviews with reference to applicable Hong Kong regulatory requirements, including those issued by the HKMA, SFC and Insurance Authority, as well as recognised frameworks such as COBIT, NIST, ISO 27001 and/or ITIL.
- Identify control gaps, root causes and areas for improvement, and develop practical, risk-based recommendations that are proportionate to the client's business and regulatory environment.
- Prepare clear and concise reports, presentations and other client deliverables, and communicate audit findings and recommendations to senior management and relevant stakeholders.
- Manage engagements throughout the project lifecycle, including project scoping, work planning, resource allocation, budgeting, progress monitoring, quality assurance and delivery risk management.
- Build trusted relationships with clients, manage stakeholder expectations and support senior team members in maintaining strong relationships with the clients.
- Support business development activities, including identifying client needs, preparing proposals and offerings, participating in client pitches and contributing to go-to-market initiatives.
- Supervise, coach and develop junior team members.
- Develop internal networks and maintain excellent relationships with colleagues across Protiviti in Hong Kong and across APAC
Required Experience & Qualifications
- Bachelor's degree in Information Systems, Information Technology, Finance, Business Management or related discipline
- Minimum 7 years plus of relevant experience in IT audit, technology risk, IT controls or cybersecurity, preferably within financial services and/or professional services.
- Experience leading IT audit and technology risk engagements and managing client stakeholders
- Strong knowledge of IT governance, ITGCs, application controls, system and network security, cloud risk, data protection, outsourcing, third party risk and business continuity
- Strong knowledge of HKMA, SFC, and IA requirements relating to technology and cybersecurity risk, and familiarity with industry frameworks such as COBIT, NIST, ISO 27001, and/or ITIL.
- Experience or knowledge in AI governance, AI risk management, and related audit reviews would be an advantage.
- Professional certifications, i.e. CISA, CISSP, CISM, CIA, CRISC, ISO 27001 lead auditor and / or other related certifications would be an advantage
- Excellent written and spoken English and Cantonese. Fluency in Mandarin is an advantage
We offer attractive remuneration package to the right candidate. Interested parties shall email their resume and expected salary to [email protected]. All information received will be kept in strict confidence and only for employment-related purpose.
By clicking 'apply', you give your express consent that Robert Half may use your personal information to process your job application and to contact you from time to time for future employment opportunities. For further information on how Robert Half processes your personal information and how to access and correct your information, please read the Robert Half privacy notice: https://www.roberthalf.com/hk/en/privacy. Please do not submit any sensitive personal data to us in your resume (such as government ID numbers, ethnicity, gender, religion, marital status or trade union membership) as we do not collect your sensitive personal data at this time.