Back to offers list
We are looking for

Operational Risk Officer - RISK - Data Protection Office APAC

Last update 07.11.2024

Position Purpose

RISK ORM APAC mission is to provide RISK and APAC Management with a front-to-back consolidated view on operational risks of APAC activities to contribute to the reduction of operational risk and to better respond to the Regulator’s expectations. The RISK ORM APAC mandate is to challenge and supervise the Operational Risk management of APAC activities. It belongs to the second line of defence at BNP Paribas, as part of the Risk Function (RISK) and is placed under the responsibility of the APAC Chief Risk Officer.

The APAC Data Protection Correspondent (APAC DPC) is positioned within RISK ORM APAC and provides expertise on personal data protection related topics in accordance with the relevant RACI. The APAC DPC must assist the APAC Data Protection Officer (DPO) in supervising the compliance of projects and with legal and regulatory personal data protection requirements throughout the APAC region as well as the Group’s and APAC personal data protection policies. The DPC is to ensure second level controls by providing the required supervision and assistance to the 1st Line of Defence.

Responsibilities:

Direct Responsibilities

To contribute to relevant personal data protection activities realization

•To guarantee required norms and methods definition and application to a company’s good data protection risks apprehension (follow-up of projects, information systems adaptation, declarations conception and maintenance, subcontractors contracts analysis, follow-up on control plans reporting, etc.) 

•To guarantee advice and assistance to strategical program ongoing. 

To support the implementation of the privacy strategy defined by APAC DPO

•To assist the APAC DPO in the supervision and monitoring of implementation of the Group's Data Protection policies and guidelines, bearing the local regulatory requirements in mind, to ensure consistency

•To define action plans and corrections related, and to ensure application of the same

•To alert APAC DPO when activity is under operational risk (non-appropriateness between needs and resources, etc.), to propose correction solutions and to implement those solutions 

•To contribute to continuous efficiency improvement and to any optimization process. 

To contribute to operational activities achievement 

•To adjudicate or mediate APAC DPO engaging decisions, emergencies and escalated issues 

To contribute to permanent control actions

•To contribute to perform LOD2 controls and challenge LOD1

•To contribute to perform the check and challenge of the RCSA

•To contribute to RISK ID exercise 

•To contribute to OR&C report

To ensure a professional network development

•To participate in local Data Protection Committees when requested by the DPO

•To contribute to Internal Control Committee

•To collaborate with local CROs and RISK teams

Supporting Responsibilities

•To assist the DPO on exchanges with the authorities in charge of the protection of personal data under the responsibility of the DPO 

•To assist the DPO in the supervision and implementation of Privacy by Design principles throughout the lifecycle of all projects, activities, products, services, processes and systems

•To contribute to role development by validating data protection requirements for new activities, new products, services or specific operations, and to carry a technical assistance 

•To receive, process and advise internal and external local solicitations about data protection 

•To receive, process and advise requests from data subjects, subcontractors and partners etc. 

•To itemise existing processes and identify breaches regarding data protection requirements (APAC local regulation & GDPR requirements) 

•To contribute to perform risk assessment on personal data breaches

•To assist the DPO in monitoring documentation, e.g. the RoPA (Register of Processing Activities)

•To contribute to the identification and notification process for data protection violations according to defined procedures and local legal requirements 

•To realize effectiveness for data protection controls and to ensure expected reporting 

•To ensure regular reporting to APAC DPO about the activity 

•To assist the DPO, where required, with local language nuances, law and practices.

•To contribute in the creation and implementation of awareness programs and to the promotion of a culture of protection of personal data within the scope of responsibility.

Technical & Behavioral Competencies:

*Level: 

 Level 1: Deep Level 2: Intermediary Level 3: Basic

Knowledge (Required to exercise the position)

•To know standards and norms about data protection - Level 1

Know-how (Implementation of technics, methods, tools to achieve activities)

Technics

•To know how to assess maturity level of the existing facility about Data Privacy - Level 1

Transverse 

•To have a professional face-to-face or phone discussion in a foreign language - Level 1

•To prioritize - Level 1

•To efficiently manage several topics at the same time - Level 1

•To issue advice / recommendation taking into account every parameters - Level 1

•To have an efficient speaking communication - Level 1

•To conceptualize / to formalize an idea, a process or a project - Level 1

•To have an efficient writing communication - Level 1

Tools

•To work with BNP Paribas tools (e.g. Data Protection Hub, Risk 360) - Level 2 

Behavioural and soft skills:

•To efficiently multi-task with topics and maintain attention to detail / rigor - Level 1

•To issue advice / recommendation considering all parameters - Level 1

•To have efficient communication skills (oral & written) - Level 1

•To conceptualize / formalize an idea, a process or a project - Level 2

•To work as a team / transversally - Level 1

•To identify and analyse risks for the activities that are handled - Level 1

•To assess, issue an opinion - Level 1

•To deploy a strategy and to define an action plan - Level 2

•To animate resources and coordinate their intervention - Level 1

•To show diplomacy to allow a message to be heard - Level 1

•To show conviction, to generate interlocutor’s acceptance - Level 1

•Being able to anticipate and come up with ideas - Level 2

•Creativity and innovation - Level 2

•To show discretion about delicate and/or confidential topics - Level 1

•Ability to manage conflict - Level 2

•To integrate multicultural dimension - Level 1

Special Qualifications (If required)

•Degree holder in legal, business or computer science or IT

•At Least 5 years of relevant experience in IT risk, Cyber security, Data Protection and related regulatory topics

•CIPP Certification or similar privacy certificate would be a plus

•a very good understanding of EU GDPR with IAPP/E certification

•3-5 years relevant working experience in privacy is a minimum

•5-8 years in total working experience

•Previous APAC or cross-territory experience preferred

•Experience in senior level reporting and discussion

About BNP PARIBAS

As the leading European Union bank, and one of the world’s largest financial institutions with an uninterrupted presence in the region since 1860, BNP Paribas offers a wide range of financial services for corporate, institutional and private investors spanning corporate and institutional banking, wealth management, asset management and insurance. 

We passionately embrace diversity and are committed to fostering an inclusive workplace where all employees are valued and encourage applicants of all backgrounds, including diversity of origin, age, gender, sexual orientation, gender identity, religion applicants who may be living with a disability. We have a number of internal employee networks in place to empower our staff to act and challenge the status quo.

•BNP Paribas PRIDE is highly active in favour of the LGBTQIA+ community

•BNP Paribas MixCity which fosters better representation of women at all levels of the organization

•Ability, the mutual aid network for employees with a disability or a disabling or chronic illness

•BNP Paribas CulturAll which celebrates diverse backgrounds

BNP is committed to financing a carbon-neutral economy by 2050. The Group is a founding member of the Net-Zero Banking Alliance and has set up its own Low Carbon Transition Group to support its clients through their energy transitions.

https://careers.apac.bnpparibas/

More information 

BNP Paribas - Diversity & Inclusion Journey

BNP Paribas - The Bank Of Green Changes

Award Obtained

BNPP has won Top employer Europe award in a 10th consecutive year

Interested by our offer? Don't wait any longer!

Discover the different professions within BNP Paribas: Audit, Compliance, Risk and Legal

If it is your ambition to work in a profession that entrusts you with a high degree of responsibility and gives you the chance to contribute to strategic decision-making at BNP Paribas, the following roles might be ideal for you to consider.

Find out more

Why should I apply?

Basically, why would you want to join BNP Paribas over any other company?

BECAUSE YOU'RE THE KIND OF PERSON WHO WANTS...

  • What if we told you that working in our Group isn’t quite what you might think? At BNP Paribas, we do a multitude of different jobs that are constantly evolving to meet the expectations of our clients and society as a whole. Whether through everyday tasks or major projects, doing one of our jobs means making a personal commitment to taking sustainable action.

  • Feeling good about your job means bringing your whole self to work and being who you are. It’s also about having the resources you need to achieve a healthy work-life balance. Both of these are major commitments at BNP Paribas.

  • At BNP Paribas, developing your skills is as important to us as it is to you. And the skills you learn with us will help you through the rest of your working life.

Find out more