Summary
Overview
Work History
Education
Skills
Certification
Publications
Timeline
Generic

Leslie Lam

Summary

Experienced IT Risk and Cybersecurity Executive with 20+ years in banking industry, including 8 years in leadership role. Skilled in managing cyber and tech risks, reinforcing IT governance, and ensuring regulatory compliance. Acts as a strategic bridge between IT, risk, and audit teams, driving risk mitigation and cybersecurity enhancements. Proven track record in developing policies, implementing security controls, and leading IT initiatives aligned with business and regulatory needs.

Overview

21
21
years of professional experience
1
1
Certification

Work History

Vice President, Head of Project & Governance

Sumitomo Mitsui Banking Corporation
08.2022 - Current
  • Manage cyber & technology risks, ensuring compliance with Head Office policies, regulatory requirements (e.g. HKMA, JFSA, APRA) and industry standards (e.g. CoBIT, NIST CSF, etc)
  • Act as the 1.5 Line assurance function, acting as an independent risk partner to IT by providing oversight, challenge, and support across risk identification assessment, control design and remediation
  • Conduct risk assessments, vulnerability analyses, and security evaluations, recommending appropriate countermeasures to safeguard systems and data
  • Develop, implement, and enforce IT, Information Security and cybersecurity policies, standards, and procedures to enhance compliance & operational resilience
  • Deploy industry best practices, risk controls, and security frameworks to protect against cyber threats, operational disruptions, and data breaches
  • Lead and execute IT projects, ensuring alignment with business objectives, regulatory mandates, and risk management best practices to enhance security posture and operational efficiency.
  • Via Persolkelly Australia

Vice President, Head of IT Services Management

Sumitomo Mitsui Banking Corporation
01.2018 - 08.2022
  • Develop and execute ITSM strategy aligned with organizational goals
  • Drive ITSM best practices and continuous improvement
  • Oversee core ITSM functions, including incident, problem, change, release, and configuration management.
  • Conduct risk assessments, enforce compliance audits, and implement corrective actions.
  • Establish and maintain IT governance frameworks, ensuring processes are standardized, documented, and consistently followed across the organization.

Vice President

Sumitomo Mitsui Banking Corporation
01.2017 - 01.2018
  • Specially appointed to assist Head of IT to establish cybersecurity function in office required by HKMA
  • Perform HKMA C-RAF assessments ensure compliance to regulatory requirements

Assistant Vice President

Sumitomo Mitsui Banking Corporation
01.2015 - 01.2017
  • Implement branch-wise ICT projects
  • Perform security and compliance assessments on every system project
  • Ensure IT governance and enforce IT policies and procedures

Associate / Senior Associate

Sumitomo Mitsui Banking Corporation
01.2012 - 01.2015
  • Supervise IT Services Team
  • Assist system projects implementation

Assistant / Officer

Sumitomo Mitsui Banking Corporation
01.2007 - 01.2012
  • Conduct Tier 1 and 2 technical support to internal business units
  • Perform daily system health check on IT infrastructure and trading systems
  • Perform system administrations including system upgrade and patching

Associate Technical Consultant

Standard Chartered Bank
01.2006 - 01.2007
  • Perform daily operational tasks
  • System & network administration
  • Via JardineOne Solution HK

Service Engineer

HK Trade Development Council
01.2005 - 01.2006
  • Perform Daily operational tasks & 2nd tier Desktop support
  • Via T&S Quantum Ltd.

Education

Master of Science - Information Systems Management

City University of Hong Kong
01.2013

Bachelor of Arts (HONS) - Computing

Hong Kong Polytechnic University
01.2009

Skills

  • Cybersecurity management
  • Risk assessment and mitigation
  • Cybersecurity governance
  • Technology risk management
  • Coaching & Mentoring
  • Leadership
  • Experience with ITIL methodologies
  • Experience with NIST CSF assessments
  • COBIT
  • Team leadership
  • IT governance

Certification

  • Associate Certified Chief Information Security Officer (CCISO)
  • Certified Information System Auditor (CISA)
  • Certified Information Security Manager (CISM)
  • Control Objectives for Information and related Technology 5 (COBIT 5) Foundation
  • IT Infrastructure Library (ITIL) v3 Foundation
  • London Chamber of Commerce and Industry (LCCI) 1st & 2nd level bookkeeping

Publications

LAM S. T. et al., “Education in IT Security: A Case Study in Banking Industry”, GSTF Journal on Computing, December 2013, Volume 3 Number 3, ISSN:2010-2283, Hong Kong

Timeline

Vice President, Head of Project & Governance

Sumitomo Mitsui Banking Corporation
08.2022 - Current

Vice President, Head of IT Services Management

Sumitomo Mitsui Banking Corporation
01.2018 - 08.2022

Vice President

Sumitomo Mitsui Banking Corporation
01.2017 - 01.2018

Assistant Vice President

Sumitomo Mitsui Banking Corporation
01.2015 - 01.2017

Associate / Senior Associate

Sumitomo Mitsui Banking Corporation
01.2012 - 01.2015

Assistant / Officer

Sumitomo Mitsui Banking Corporation
01.2007 - 01.2012

Associate Technical Consultant

Standard Chartered Bank
01.2006 - 01.2007

Service Engineer

HK Trade Development Council
01.2005 - 01.2006

Bachelor of Arts (HONS) - Computing

Hong Kong Polytechnic University

Master of Science - Information Systems Management

City University of Hong Kong
Leslie Lam