Summary
Overview
Work History
Education
Certification
Timeline
Generic
LILY CHOW

LILY CHOW

Senior Consultant
Hong Kong

Summary

Lily is currently working as a senior consultant in Ernst & Young Advisory Service Limited. She has more than 3 years experiences, specializing in performing technical compliance assessments for financial institutions based on regulations by various regulators, mainly the HKMA, HKAB and SFC.

Overview

4
4
years of professional experience
10
10
years of post-secondary education
3
3
Certifications
3
3
Languages

Work History

Senior Consultant - Technology Consulting

Ernst & Young Advisory Services Limited
02.2024 - Current
  • Performed compliance review in accordance to the HKMA’s Cyber Resilience Assessment Framework (C-RAF) (inherent risk profile and maturity assessment) for scaled bank in Hong Kong.
  • Performed independent cybersecurity assessment for a Chinese-based credit reference agency in accordance with the ISO/IEC 27002:2022 and ISO/IEC 27701:2019 standard.
  • Performed Independent Assessment on technology projects for multiple banks in accordance with the Hong Kong Monetary Authority (“HKMA”) Supervisory Policy Manual and other related circulars / guidelines. The assessment scope includes TM-E-1, TM-G-1, TM-G-2, SA-2, RAF, Anti-DDoS protection, Customer Data Protection and Cloud computing or AI’s related IT infrastructure and technology risk management controls.
  • Performed annual compliance review for digital asset financial services group in accordance with the Securities and Futures Commission ("SFC") requirement on virtual asset trading platforms (“VATP”) for license renewal purpose
  • Provided regulatory supervision support for the monetary authority of Macau (“AMCM”), involving system risk assessment and regulatory review for top 5 Chinese banks, Macau-based banks and international banks with operations in Macau.

Analyst - Risk Advisory

Deloitte Touche Tohmatsu
09.2022 - 02.2024
  • Engaged in IT control audit and risk evaluation for systems to examine areas such as user access management, access security, change control management, backup and recovery.
  • Performed testing on automated controls reviews using a risk-based approach.
  • Performed independent assessment of compliance with Hong Kong Deposit Protection Board (HKDPB) guideline for leading local financial institution and evaluate potential system risks resulting from variance to HKDPB guidelines.
  • Performed ISEA 3402 review for internal leading investment bank and leading real estate investment company.
  • Conducted post-audit result discussion with clients regarding findings identified and provide suggestions on improvements with reference to industry's best practice.

FCAS internship

Bank of China (Hong Kong)
07.2021 - 12.2021
  • Engaged in penetration testing performed by external auditors.
  • Conducted Internal cyber threats identification and log monitoring.
  • Performed observation of management meeting to understand the bank's development path.
  • Attended regular training by HKMA related to technology risk management.

Education

Bachelor of Business Administration - information systems, operations management

The Hong Kong University of Science and Technology
01.2018 - 01.2022

Secondary Education - Economics, Business, Accounting and Financial studies (BAFS), History

Diocesan Girls' School
01.2012 - 01.2018

Certification

Certified Information Systems Auditor (CISA) - Exam passed

Timeline

Certified ISO27001 Information Security Associate

12-2024

Senior Consultant - Technology Consulting

Ernst & Young Advisory Services Limited
02.2024 - Current

Certified Information Systems Auditor (CISA) - Exam passed

11-2022

Certificate of Cloud Security Knowledge V4 (CCSKv4), Cloud Security Alliance (CSA)

11-2022

Analyst - Risk Advisory

Deloitte Touche Tohmatsu
09.2022 - 02.2024

FCAS internship

Bank of China (Hong Kong)
07.2021 - 12.2021

Bachelor of Business Administration - information systems, operations management

The Hong Kong University of Science and Technology
01.2018 - 01.2022

Secondary Education - Economics, Business, Accounting and Financial studies (BAFS), History

Diocesan Girls' School
01.2012 - 01.2018
LILY CHOWSenior Consultant