Experienced IT Risk and Cybersecurity Executive with 20+ years in banking industry, including 8 years in leadership role. Skilled in managing cyber and tech risks, reinforcing IT governance, and ensuring regulatory compliance. Acts as a strategic bridge between IT, risk, and audit teams, driving risk mitigation and cybersecurity enhancements. Proven track record in developing policies, implementing security controls, and leading IT initiatives aligned with business and regulatory needs.
Overview
21
21
years of professional experience
1
1
Certification
Work History
Vice President, Head of Project & Governance
Sumitomo Mitsui Banking Corporation
08.2022 - Current
Manage cyber & technology risks, ensuring compliance with Head Office policies, regulatory requirements (e.g. HKMA, JFSA, APRA) and industry standards (e.g. CoBIT, NIST CSF, etc)
Act as the 1.5 Line assurance function, acting as an independent risk partner to IT by providing oversight, challenge, and support across risk identification assessment, control design and remediation
Conduct risk assessments, vulnerability analyses, and security evaluations, recommending appropriate countermeasures to safeguard systems and data
Develop, implement, and enforce IT, Information Security and cybersecurity policies, standards, and procedures to enhance compliance & operational resilience
Deploy industry best practices, risk controls, and security frameworks to protect against cyber threats, operational disruptions, and data breaches
Lead and execute IT projects, ensuring alignment with business objectives, regulatory mandates, and risk management best practices to enhance security posture and operational efficiency.
Via Persolkelly Australia
Vice President, Head of IT Services Management
Sumitomo Mitsui Banking Corporation
01.2018 - 08.2022
Develop and execute ITSM strategy aligned with organizational goals
Drive ITSM best practices and continuous improvement
Oversee core ITSM functions, including incident, problem, change, release, and configuration management.
Conduct risk assessments, enforce compliance audits, and implement corrective actions.
Establish and maintain IT governance frameworks, ensuring processes are standardized, documented, and consistently followed across the organization.
Vice President
Sumitomo Mitsui Banking Corporation
01.2017 - 01.2018
Specially appointed to assist Head of IT to establish cybersecurity function in office required by HKMA
Perform HKMA C-RAF assessments ensure compliance to regulatory requirements
Assistant Vice President
Sumitomo Mitsui Banking Corporation
01.2015 - 01.2017
Implement branch-wise ICT projects
Perform security and compliance assessments on every system project
Ensure IT governance and enforce IT policies and procedures
Associate / Senior Associate
Sumitomo Mitsui Banking Corporation
01.2012 - 01.2015
Supervise IT Services Team
Assist system projects implementation
Assistant / Officer
Sumitomo Mitsui Banking Corporation
01.2007 - 01.2012
Conduct Tier 1 and 2 technical support to internal business units
Perform daily system health check on IT infrastructure and trading systems
Perform system administrations including system upgrade and patching
Associate Technical Consultant
Standard Chartered Bank
01.2006 - 01.2007
Perform daily operational tasks
System & network administration
Via JardineOne Solution HK
Service Engineer
HK Trade Development Council
01.2005 - 01.2006
Perform Daily operational tasks & 2nd tier Desktop support
Via T&S Quantum Ltd.
Education
Master of Science - Information Systems Management
City University of Hong Kong
01.2013
Bachelor of Arts (HONS) - Computing
Hong Kong Polytechnic University
01.2009
Skills
Cybersecurity management
Risk assessment and mitigation
Cybersecurity governance
Technology risk management
Coaching & Mentoring
Leadership
Experience with ITIL methodologies
Experience with NIST CSF assessments
COBIT
Team leadership
IT governance
Certification
Associate Certified Chief Information Security Officer (CCISO)
Certified Information System Auditor (CISA)
Certified Information Security Manager (CISM)
Control Objectives for Information and related Technology 5 (COBIT 5) Foundation
IT Infrastructure Library (ITIL) v3 Foundation
London Chamber of Commerce and Industry (LCCI) 1st & 2nd level bookkeeping
Publications
LAM S. T. et al., “Education in IT Security: A Case Study in Banking Industry”, GSTF Journal on Computing, December 2013, Volume 3 Number 3, ISSN:2010-2283, Hong Kong
Timeline
Vice President, Head of Project & Governance
Sumitomo Mitsui Banking Corporation
08.2022 - Current
Vice President, Head of IT Services Management
Sumitomo Mitsui Banking Corporation
01.2018 - 08.2022
Vice President
Sumitomo Mitsui Banking Corporation
01.2017 - 01.2018
Assistant Vice President
Sumitomo Mitsui Banking Corporation
01.2015 - 01.2017
Associate / Senior Associate
Sumitomo Mitsui Banking Corporation
01.2012 - 01.2015
Assistant / Officer
Sumitomo Mitsui Banking Corporation
01.2007 - 01.2012
Associate Technical Consultant
Standard Chartered Bank
01.2006 - 01.2007
Service Engineer
HK Trade Development Council
01.2005 - 01.2006
Bachelor of Arts (HONS) - Computing
Hong Kong Polytechnic University
Master of Science - Information Systems Management
Vice President, Regulatory Officer, Team Lead at Sumitomo Mitsui Banking Corporation (SMBC)Vice President, Regulatory Officer, Team Lead at Sumitomo Mitsui Banking Corporation (SMBC)
Global Head, Managing Director & Vice President, TD Securities Governance & Controls at TD Bank GroupGlobal Head, Managing Director & Vice President, TD Securities Governance & Controls at TD Bank Group