Job Responsibilities
Regulatory Intelligence & Advisory
- Monitor technology regulatory and legislative developments across China financial regulators and government agencies, including CSRC, NFRA, PBOC, SAFE, CAC, CBA, and Exchange centers.
- Support the China franchise Compliance team on technology regulatory and compliance matters.
- Support lines of business through new initiative and new product assessments.
- Build and maintain working relationships with lines of business, legal, data offices, and broader CCOR teams to enable cross-functional and cross-entity collaboration.
Risk Assessment & Independent Challenge
- Independently assess 1LOD technology risk management, controls, and governance through reviews and other activities against applicable laws, rules, and regulatory requirements for supported China entities.
Technology Incident Oversight
- Provide 2LOD guidance on technology incidents, including advice on reportability to China regulators (CSRC, NFRA, PBOC, SAFE).
- Maintain working knowledge of incident thresholds, regulatory definitions, and escalation protocols within the Chinese regulatory environment.
Innovation, Automation & Operational Scaling
- Use technology tools and AI-enabled automation to scale oversight and support continuous monitoring within the APAC CCOR Technology & Cyber function.
- Apply AI to support risk judgment and contribute to a more data-informed risk capability across the team.
Required Qualifications, Capabilities, and Skills
Education & Experience
- Bachelor's degree in Computer Science, Computer Engineering, Information Security, Business Information Systems, or a related field; or equivalent professional experience.
- Minimum 10 years of experience in Technology Risk, Cybersecurity, Compliance, IT Audit, and/or Operational Risk within financial services.
- Working knowledge of China-specific technology regulations, including CSRC, NFRA, PBOC, and SAFE IT requirements.
Technology & AI Fluency
- Ability to understand complex technical systems, the business processes they support, and the associated risks and controls.
- Familiarity with AI, large language models (LLMs), agentic AI, cloud computing, cybersecurity frameworks, and enterprise architectures.
- Familiarity with emerging regulatory requirements governing AI and algorithmic systems in financial services.
Data, Analytics & Emerging Risk
- Apply quantitative and qualitative analysis to identify trends, anomalies, and risk signals across complex datasets.
- Experience moving from sample-based review toward thematic analysis and continuous monitoring.
- Use automation and AI-assisted tools to scale oversight across the risk function.
Regulatory & Business Acumen
- Translate regulatory developments from CSRC, NFRA, PBOC, and SAFE into practical compliance implications.
- Strong organizational, project management, and stakeholder management skills, with a track record of delivering results with professionalism and integrity.
Behavioral Attributes
- Able to work across technology, business, legal, compliance, and ORM functions, adapting communication style to each audience.
- Focused on outcomes, not procedural compliance alone.
- Committed to continuous learning as technology and the risk landscape evolve.
- Track record of building effective relationships in complex, matrixed organizations.
Certifications (Beneficial)
- Relevant certifications include CISSP, CISA, CISM, CRISC, CCSP, or CGEIT.
- Cloud practitioner credentials (AWS, Azure, or equivalent) are also valued.
Language Requirements
- Bilingual fluency in English and Chinese (spoken and written) is required.