Hong Kong Exchanges Logo

Hong Kong Exchanges

Senior Process Risk and Control Analyst

Posted 2 Days Ago
Be an Early Applicant
London, Greater London, England
Senior level
London, Greater London, England
Senior level
The Senior Process Risk and Control Analyst provides Technology Governance Risk and Compliance services to ensure compliance and risk reduction initiatives across HKEX, LME, and LME Clear. Responsibilities include controls analysis, risk management activities, support for audits, and awareness briefings.
The summary above was generated by AI

Senior Process Risk and Control Analyst

Shift Pattern:

Standard 40 Hour Week (United Kingdom)

Scheduled Weekly Hours:

40

Corporate Grade:

D - Assistant Vice President

Reporting Line:

(UK Division) Information Technology

Location:

UK-London

Worker Type:

Permanent

The London Metal Exchange (LME) is the world centre for industrial metals trading. In 2023, 149 million lots were traded, equating to $15 trillion notional and 3.5 billion tonnes, with a market open interest high of 1.8 million lots.

The metals community uses the LME, an HKEX Group company, as a venue to transfer or take on price risk, as a physical market of last resort and as the provider of transparent global reference prices.

Overall Purpose of Role:

The role provides Technology Governance Risk and Compliance specialist services to HKEX, LME and LME Clear. Working closely with peers across the technology function and stakeholders within the wider Organization.

The role is to drive compliance and risk reduction initiatives across the Firm using all the Governance Risk and Compliance tool sets available. This will help ensure the service delivered is consistent with the inherent security threat and risk profile of a global exchange designated as critical national infrastructure.

Responsibilities:

  • Maintain and mature the 1LoD technology Risk and Controls processes.
  • Perform controls analysis and testing and provide best practice recommendations.
  • Drive risk management activities including analysis, identification and oversight.
  • Support and produce MI for committees/ stakeholders.
  • Lead internal and external audits and support regulatory initiatives. 
  • Support TPRM Assurance activities
  • Deliver continuous enhancement to support GRC maturity initiatives.
  • Manage Exceptions against policies and standards.
  • Create and deliver InfoSec Assurance awareness briefings.
  • Support the team in line with the Process Risk and Control service catalogue.

Qualifications Required:

  • University degree in Information/Cyber Security or related field/equivalent compliance experience

Preferred Knowledge and Experience:

  • Any professional security qualifications such as CISM, CRISC or CISSP are desirable
  • Experience of working in regulated markets or financial services
  • Knowledge of Information Security Domains /and frameworks such as NIST. CIS
  • Preferred background in 1st LoD Line Risk & Control roles or IT/Cyber Architecture
  • Strong analytical thinker capable of generating and presenting IT technology risks & Controls to non-technical audiences.
  • Experience/knowledge of the following: -
    • Risk Management/Audit Oversight.
    • Presenting/Reporting to a senior level.
    • Experience of assessing control gaps and documenting associated remediation plans   
    • TPRM Assessments/ Activities
    • Creating awareness / assurance briefings   

Skills Required

  • Stakeholder management across multiple business functions working with all lines of defence teams.
  • Proficient written, verbal and presentation skills.
  • Understanding of security related KPIs & KRIs, metrics and reporting.
  • Proactive and balance multiple projects to deliver timely effective solutions.
  • Able to rapidly understand the business operating environment of the Group.
  • Apply existing GRC knowledge to drive compliance across the business and improve service delivery.

The LME is committed to creating a diverse environment and is proud to be an equal opportunity employer. In recruiting for our teams, we welcome the unique contributions that you can bring in terms of education, ethnicity, race, sex, gender identity, expression & reassignment, nation of origin, age, languages spoken, colour, religion, disability, sexual orientation and beliefs. In doing so, we want every LME employee to feel our commitment to showing respect for all and encouraging open collaboration and communication.

Top Skills

Cyber Security
Information Security

Similar Jobs

9 Hours Ago
4 Locations
Senior level
Senior level
Cloud • Information Technology • Security • Software • Cybersecurity
As a Senior Windows Software Engineer on the Zero Trust team, you will develop high-performance networking code for the Zero Trust desktop client. You will work on Windows internals, be involved in low-level driver development, write clean and testable code, and collaborate closely with product managers to implement features that meet security and performance standards.
Top Skills: CC++PythonRust
15 Hours Ago
Hybrid
Leeds, West Yorkshire, England, GBR
Senior level
Senior level
Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
The IT Risk and Compliance Lead will manage IT risks, ensure compliance with standards and regulations such as SOX and PCI/DSS, and foster a risk-aware culture. Responsibilities include risk portfolio management, stakeholder communication, audit planning, and collaboration with risk teams.
Yesterday
Hybrid
London, Greater London, England, GBR
Entry level
Entry level
Fintech • Mobile • Payments • Software • Financial Services
The Full Stack Security Engineer will focus on enhancing security practices within Wise by designing and building infrastructure, automating security features, and collaborating with product and platform engineers for effective data protection. The role requires adaptability and communication skills, with an emphasis on security awareness and best coding practices.
Top Skills: JavaJavaScriptTypescript

What you need to know about the London Tech Scene

London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account