Senior Manager, Dpo and Data Risk

3 days ago


Singapore HSBC Full time

-Job description**Some careers grow faster than others.**

If you’re looking for a career that will give you plenty of opportunities to develop, join HSBC and your future will be rich with potential. Whether you want a career that could take you to the top, or simply take you in an exciting new direction, HSBC offers opportunities, support and rewards that will take you further.

Global Risk is a thriving and expert risk management function supporting HSBC globally with all aspects of risk management. The team actively manages a varied and dynamic range of risk types, including security, fraud, information security, contingency, geopolitical, operational, credit, pension, insurance, market and reputation risks. All parts of the Global Risk team use their skills, insight and integrity to handle established threats and those they see emerging, acting to protect and enable HSBC to deliver sustainable growth.

We are currently seeking a high calibre professional to join our team as a **Senior Manager, DPO and Data Risk.**

**Principal Responsibilities**

Global Enterprise Risk Management (ERM) is a sub function of Group Risk and Compliance. The ERM function will support the integration of our Group Framework and Appetite Management, and have broad oversight of the Risk Taxonomy. While the core risks of the bank remain consistent compared to a few years ago, the way in which they manifest, the speed to crystallisation and the connection points between them have become increasingly complex. It is therefore essential that we are equipped with the knowledge to navigate the dynamic and interconnected risk landscape of today. The objective of enterprise risk management is to develop a holistic, portfolio view of the most significant risks to the achievement of the Group’s most important objectives.

Data Privacy Officers (DPOs) are responsible for ensuring HSBC meets its obligations under data protection and privacy laws within their particular jurisdiction. They provide expert advice, guidance and direction and support the necessary standards and controls to enable the Bank, including its employees and relevant third parties, to manage privacy risks and comply with obligations under data protection laws in relation to the processing of personal data. To establish a culture of privacy within HSBC, the DPO will need to work collaboratively with key senior stakeholders across the business and will be accountable for keeping executives appraised of privacy risks and issues

Data Risk (part of Resilience Risk) Specialists provide expert advice and stewardship covering the full data risk lens to ensure high quality advice, expertise and guidance. Data Risk Specialists operate on an entity-wide basis and must work closely with the ERM Business and Functions aligned roles to support them by providing technical advice and guidance for their consumption and use in delivering their respective relationship management remits.

The Senior Manager, DPO and Data Risk, is responsible for supporting and delivering the above responsibilities, with more detail provided below.

DPO
- Informing and advising the business and its employees of their data privacy and protection compliance obligations
- Providing expert guidance, oversight and challenge on all aspects of data protection and privacy risk strategy and compliance focusing efforts on areas that present higher data privacy risks
- Monitoring compliance with data privacy provisions and with HSBC Group policies relating to the protection of personal data, including the assignment of responsibilities, staff education and awareness training, and ensuring remediation of any related audit findings
- Reviewing and advising on Data Protection Impact Assessments (DPIAs) and monitoring performance of mitigations, where necessary
- Cooperating with the regulatory authority
- Advising on, and providing the business with support, to ensure the necessary safeguards and controls are in place to ensure compliance with requirements for international data transfers by identifying all circumstances in which personal data is transferred outside of the relevant jurisdiction

Data Risk
- Provide technical data risk advice and support to the Singapore ERM Business & Functions coverage team to ensure they understand and are aware of the control environment and assessment of risk within the country commensurate with the scale and nature of operations
- Support the ERM Business & Functions coverage team to explain in non-technical terms the impact of issues or events, and top and emerging risks that may require changes (for example, to controls, resources or business operations) to remain within respective Risk Appetite. Support the ERM Business & Functions coverage team to ensure Risk and Control Owners have a clear understanding of the effectiveness of the current control environment
- Monitor the local external environment to get early sight of emerging data risks and provide detailed guidance on contro



  • Singapore RevUp Consulting Full time

    As Risk Management & Data Protection Lead, you will develop and implement risk management and data protection strategies to safeguard the organisation and ensure regulatory compliance. You will collaborate with stakeholders, manage business continuity plans, and act as the Data Protection Officer (DPO) to maintain operational resilience. **Key...

  • Legal Counsel

    2 weeks ago


    Singapore Marina Bay Sands Full time

    LOVE WHAT YOU DO? THERE IS A PLACE FOR YOU HERE! Be part of our diverse and inclusive team. Job Responsibilities Regular Assists the DPO and Deputy DPO with the following work: - Executing an annual work plan to ensure compliance with the Personal Data Protection Act (“PDPA”) under the guidance of the Deputy General Counsel.- Reviewing and executing...


  • Singapore NTUC Health Full time

    COMPANY DESCRIPTION **NTUC Health Co-operative Limited (NTUC Health)** is an NTUC social enterprise that provides a comprehensive and integrated suite of quality and affordable health and eldercare services to meet the growing needs of families and their dependents. Building on close to three decades of experience and expertise, NTUC Health is among the...


  • Singapore The Edge Partnership Full time

    **Responsibilities**: - Designing and implementing an overall risk management process for the organization - Serve as Data Protection Officer (DPO) for the organization and put in data governance framework in the organization - Regularly reviewing internal risk policy and ensuring compliance with new legislation - Building risk awareness amongst staff by...


  • Singapore Citi Full time

    **Responsibilities**: Designing, developing, delivering and maintaining best-in-class Compliance, programs, policies and practices for ICRM. Providing oversight and guidance over the assessment of complex issues, structuring potential solutions and driving effective resolution with other stakeholders. Identifying and assessing Citi’s key compliance risks....


  • Singapore beBeeCybersecurity Full time $96,000 - $144,000

    Cyber Risk and Data Governance ExpertMinistry of Law, Singapore is seeking a Cyber Risk and Data Governance Lead to spearhead development of risk management strategies, security guidelines, and gap analyses to bolster cybersecurity and data protection across regulated entities.Key Responsibilities:Formulate risk management strategies, frameworks, policies,...


  • Singapore REVUP CONSULTING PTE. LTD. Full time

    **The Role** - Develop and enforce risk management policies, ensuring alignment with organizational goals and industry standards. Establish and maintain risk monitoring systems to identify and mitigate risks effectively. - Create and implement comprehensive risk policies and Personal Data Protection Act (PDPA) governance measures. Enhance risk awareness...


  • Singapore Huang He Consultancy Pte Ltd Full time

    The responsibilities of a DPO include, but are not limited to: - Ensuring compliance with PDPA when developing and implementing policies and processes for handling personal data; - Fostering a data protection culture among employees and communicating personal data protection policies to stakeholders; - Managing personal data protection-related queries and...


  • Singapore Ministry of Law Full time

    Overview Cyber Risk and Data Governance Lead, Information Technology Division at Ministry of Law, Singapore. The role leads initiatives in cyber risk and data governance to support regulatory divisions. What You Will Be Working On You will collaborate with management teams, project teams, MinLaw's partners and vendors in the following areas: Lead...


  • Singapore Citi Full time

    Whether you’re at the start of your career or looking to discover your next adventure, your story begins here. At **Citi**, you’ll have the opportunity to expand your skills and make a difference at one of the world’s most global banks. We’re fully committed to supporting your growth and development from the start with extensive on-the-job training...