FLU Risk Manager
The FLU Risk Manager is responsible for executing the risk management processes and manages the risks within its department, including but not limited to conducting risk assessments, testing the controls, identifying and reporting risks and issues, monitoring the department's adherence to risk management policies and procedures, performing tasks required under the data privacy program, coordinating within the department to complete user recertification, and reporting any information security or data privacy incidents.
Responsibilities include :
- Implementing or coordinating with relevant FLU teams on the implementation of the RGF and risk management policies and procedures within FLU and enforcing relevant controls.
- Creating and maintaining FLU procedures pertaining to the FLU Risk Managers' responsibilities.
- Providing inputs / feedback to IRM risk management policies and procedures.
- Monitoring FLU adherence to IRM standards and requirements.
- Proposing addition, modification, and removal of KRIs and thresholds during annual review and off-cycle adjustment, and facilitating the approval process.
- Monitoring, maintaining, and reporting KRIs owned by FLU according to the governance requirements in the KRI Procedure.
- Identifying and escalating KRI warning line and limit breaches according to the KRI Procedure.
- Producing FLU risk reporting for applicable risk areas and reporting to Senior Management, IRM, and risk committees as appropriate.
- Identifying existing and emerging risks potentially impacting the FLUs if any.
- Identifying incidents and issues and reporting to respective IRM.
- Remediating issues or monitoring issue remediation according to the action plan, validating issue closure documentation for FLU-owned business-identified issues.
- Conducting risk assessments pertaining to the respective risk areas.
- Maintaining a control inventory, process mapping, and other documentation as applicable.
- Developing a control testing plan.
- Conducting control testing, reporting results, monitoring control issue remediation as applicable, and validating issue closure documentation.
- Attending risk management related training.
- Identifying risk management training needs for FLUs.
- Reviewing the application security requirements and conducting security control testing on processes, systems, and applications as applicable.
- Assisting ORD in conducting security monitoring investigation as needed.
- Coordinating risk management related requests from internal / external audit, Head Office, and regulators within FLU.
- Monitoring the departmental third-party risk management, business continuity planning / testing, and record retention.
- Actively participating in the monthly FLU Compliance Testing meetings.
- Participating in the BSA / AML / OFAC risk assessment, including monthly data verification, and demonstrating an adequate understanding of the RAE system.
- Contributing to the annual Fraud risk assessment, such as ensuring timely completion of the questionnaire with high quality, and reviewing and providing feedback on the reports.
- Contributing to the annual Consumer and Regulatory compliance risk assessment, such as ensuring timely completion of the questionnaire with high quality, and reviewing and providing feedback on the reports.
- Acting as the department's regulatory change coordinator, providing timely responses to the LCD as requested.
- Acting as a liaison between CISO and FLU department to perform required assigned projects under Data Privacy Program on a timely basis. Supporting Data Privacy program deliverables includes but not limited to identifying projects or applications initiated or owned by the department and performing necessary privacy impact assessment.
- Identifying data sharing cross-border and following cross-border data sharing requirements to get required review and approval.
- Identifying and reporting to CISO on a timely basis any incidents related to data privacy breach or data security breach.
- Coordinating between FLU and CISO to timely perform and complete user recertification.
Other departmental responsibilities include :
Assisting the Department Management with day-to-day administration of EO including preparation of workforce analysis and business impact analysis, drafting departmental strategic plan, work reports, and others.Conducting quality assurance evaluation and testing to departmental processes, assisting with workflow process review and revision.Monitoring the implementation of departmental ABAC compliance and expense management.Participating in special projects and other duties as assigned.Qualifications :
Bachelor's degree in Business Administration, Finance, or Economics required; Master's degree preferred.Minimum 5 years of Banking or Administration experience required.Minimum 5 years of Risk Management, Compliance, and Internal Control experience.Demonstrate knowledge in risk management processes and principles, regulatory, and compliance.Demonstrate knowledge in Purchasing Management, Asset Management, Expense Management, Facility Management, Reputation Risk Management, Donation and Sponsorship management, Branding and Marketing, and Executive Support, etc.Bilingual ability in English and Mandarin required.Pay Range : USD $65,000.00 - USD $150,000.00 / Yr.