126 Cism jobs in Hong Kong
Information Security Manager
Posted 11 days ago
Job Viewed
Job Description
Join to apply for the Information Security Manager role at Michael Page .
1 day ago Be among the first 25 applicants.
About Our ClientOur client is a well-established organization within the financial services sector. With a large workforce and a solid market presence in Hong Kong, they are committed to maintaining high standards in technology and information security.
Job DescriptionAs a 'Manager, Information Security,' your main responsibilities will include:
- Overseeing the implementation and maintenance of the bank's information security systems.
- Conducting regular audits and risk assessments to ensure adherence to security protocols.
- Developing and implementing information security policies and procedures.
- Training and mentoring staff on information security best practices.
- Conducting cybersecurity assessments, including penetration testing and infrastructure/web application reviews.
- Managing and maintaining security systems such as firewalls, NAC, IPS, and SIEM.
- Leading and coordinating information security projects across departments.
- Managing incident responses and investigations into security breaches.
- Staying updated on the latest trends and developments in information security.
- Reporting on the status of information security to senior management.
A Successful 'Manager, Information Security' Should Have
- A degree in Computer Science, Information Security, or a related field.
- Proven experience in a managerial role within the field of information security.
- Familiarity with information security regulations and standards in the financial services industry.
- Exceptional leadership and communication skills.
- The ability to handle sensitive information with discretion and integrity.
- A competitive salary in the range of HKD 648,000 - HKD 792,000 per annum.
- Standard benefits package.
- The chance to work in a fast-paced, technology-driven environment within the financial services industry.
- Opportunities for career progression and professional development.
- A supportive and collaborative company culture.
We encourage all candidates who believe they can fulfill these responsibilities and possess the necessary qualifications and skills to apply. This is a fantastic opportunity to join a leading financial organization in Hong Kong and make a significant impact in the field of Information Security.
Contact: Alexis Wee
Quote job ref: JN-
Seniority level- Mid-Senior level
- Full-time
- Information Technology and Engineering
- Financial Services, Accounting, and Banking
Information Security Manager
Posted 20 days ago
Job Viewed
Job Description
Join to apply for the Information Security Manager role at Global Payments Inc. .
Develops and leads one or more of the following highly technical and specialized areas within information security: Security Engineering, Security Architecture, Forensics Analysis, Threat Analysis, Threat Hunting and Penetration Testing. Manages the development, deployment and execution of enterprise security controls and defenses. Monitors, analyzes and exploits system vulnerabilities to detect potential threats. Executes containment, mitigation and protection processes to safeguard against real time threats while maintaining critical documentation and evidence. Determines risk and exposure from security breaches and resolves incidents while providing guidance to business decision-makers.
Responsibilities- Tracks and supports the delivery of information security solutions. Manages the tactical activities of installing and configuring security systems, software and applications. Coordinates responses to intrusions and provide remediation guidance and support.
- Coordinates resources on highly complex development projects including approval of design specifications and scope. Provides input to short-term security technology roadmaps regarding applicability of new technologies. Disseminates updates to InfoSec Architectural policies, standards and guidelines to team members.
- Reviews forensic investigations and analysis of reported cyber incidents to evaluate root cause vectors and necessary control measures needed to prevent future occurrence. Implements appropriate countermeasures to recover deleted, hidden or lost user data.
- Coordinates research and analysis of threat actor profiles and associated indicators to detect potential threats. Implements recommended actions and security tools to identify, monitor and mitigate attacks. Coordinates with external security organizations to exchange threat intelligence.
- Coordinates complex threat assessment to evaluate incident impact and risk exposure. Reviews cyber operations intelligence and/or indications and warnings intelligence products (e.g., threat assessments, briefings, intelligence studies, country studies), and draws conclusions on possible implications or applicability. Guides the threat intelligence collection process to enhance analytical capabilities.
- Manages execution of penetration testing activities on core systems. Articulates the outcome of stimulated attacks and underlying security issues or system weaknesses. Recommends and institutes remediation techniques or improvements to protect and maintain security frameworks and controls.
- Supports the evaluation and selection of security applications and systems. Manages the implementation of access control defenses. Provides quality review on the evaluation and documentation of team procedures. Manages development, deployment and support activities for multiple critical security technologies to include problem resolution and management, application maintenance, project requests and system enhancements.
- Not an exhaustive list; other duties as assigned.
- Bachelor's Degree
- Relevant Experience or Degree in: Information Security or Computer Science preferred. Other majors will be considered.
- Typically a minimum of 6 years
- Related professional experience and prefer a minimum of 1-2 years experience in a supervisory position.
- One or more of the following-CISSP, CISA, CISM, PCI-QSA, PA-QSA, PCIP, CRISC, CGEIT, Certified Forensic Computer Examiner (CFCE), Certified Cyber Threat Analyst (CCTA), Certified Computer Examiner (CCE)
- Prior Global Payments, payment or technology industry experience is preferred.
- Master's Degree in a related field of study from an accredited university.
None Identified
Job Details- Seniority level: Mid-Senior level
- Employment type: Full-time
- Job function: Information Technology
- Industries: Financial Services and IT Services and IT Consulting
Information Security Manager
Posted 16 days ago
Job Viewed
Job Description
Join to apply for the Information Security Manager role at Michael Page .
1 day ago Be among the first 25 applicants.
About Our ClientOur client is a well-established organization within the financial services sector. With a large workforce and a solid market presence in Hong Kong, they are committed to maintaining high standards in technology and information security.
Job DescriptionAs a 'Manager, Information Security,' your main responsibilities will include:
- Overseeing the implementation and maintenance of the bank's information security systems.
- Conducting regular audits and risk assessments to ensure adherence to security protocols.
- Developing and implementing information security policies and procedures.
- Training and mentoring staff on information security best practices.
- Conducting cybersecurity assessments, including penetration testing and infrastructure/web application reviews.
- Managing and maintaining security systems such as firewalls, NAC, IPS, and SIEM.
- Leading and coordinating information security projects across departments.
- Managing incident responses and investigations into security breaches.
- Staying updated on the latest trends and developments in information security.
- Reporting on the status of information security to senior management.
A Successful 'Manager, Information Security' Should Have
- A degree in Computer Science, Information Security, or a related field.
- Proven experience in a managerial role within the field of information security.
- Familiarity with information security regulations and standards in the financial services industry.
- Exceptional leadership and communication skills.
- The ability to handle sensitive information with discretion and integrity.
- A competitive salary in the range of HKD 648,000 - HKD 792,000 per annum.
- Standard benefits package.
- The chance to work in a fast-paced, technology-driven environment within the financial services industry.
- Opportunities for career progression and professional development.
- A supportive and collaborative company culture.
We encourage all candidates who believe they can fulfill these responsibilities and possess the necessary qualifications and skills to apply. This is a fantastic opportunity to join a leading financial organization in Hong Kong and make a significant impact in the field of Information Security.
Contact: Alexis Wee
Quote job ref: JN-
Seniority level- Mid-Senior level
- Full-time
- Information Technology and Engineering
- Financial Services, Accounting, and Banking
Information Security Manager
Posted 20 days ago
Job Viewed
Job Description
Join to apply for the Information Security Manager role at Global Payments Inc. .
Develops and leads one or more of the following highly technical and specialized areas within information security: Security Engineering, Security Architecture, Forensics Analysis, Threat Analysis, Threat Hunting and Penetration Testing. Manages the development, deployment and execution of enterprise security controls and defenses. Monitors, analyzes and exploits system vulnerabilities to detect potential threats. Executes containment, mitigation and protection processes to safeguard against real time threats while maintaining critical documentation and evidence. Determines risk and exposure from security breaches and resolves incidents while providing guidance to business decision-makers.
Responsibilities- Tracks and supports the delivery of information security solutions. Manages the tactical activities of installing and configuring security systems, software and applications. Coordinates responses to intrusions and provide remediation guidance and support.
- Coordinates resources on highly complex development projects including approval of design specifications and scope. Provides input to short-term security technology roadmaps regarding applicability of new technologies. Disseminates updates to InfoSec Architectural policies, standards and guidelines to team members.
- Reviews forensic investigations and analysis of reported cyber incidents to evaluate root cause vectors and necessary control measures needed to prevent future occurrence. Implements appropriate countermeasures to recover deleted, hidden or lost user data.
- Coordinates research and analysis of threat actor profiles and associated indicators to detect potential threats. Implements recommended actions and security tools to identify, monitor and mitigate attacks. Coordinates with external security organizations to exchange threat intelligence.
- Coordinates complex threat assessment to evaluate incident impact and risk exposure. Reviews cyber operations intelligence and/or indications and warnings intelligence products (e.g., threat assessments, briefings, intelligence studies, country studies), and draws conclusions on possible implications or applicability. Guides the threat intelligence collection process to enhance analytical capabilities.
- Manages execution of penetration testing activities on core systems. Articulates the outcome of stimulated attacks and underlying security issues or system weaknesses. Recommends and institutes remediation techniques or improvements to protect and maintain security frameworks and controls.
- Supports the evaluation and selection of security applications and systems. Manages the implementation of access control defenses. Provides quality review on the evaluation and documentation of team procedures. Manages development, deployment and support activities for multiple critical security technologies to include problem resolution and management, application maintenance, project requests and system enhancements.
- Not an exhaustive list; other duties as assigned.
- Bachelor's Degree
- Relevant Experience or Degree in: Information Security or Computer Science preferred. Other majors will be considered.
- Typically a minimum of 6 years
- Related professional experience and prefer a minimum of 1-2 years experience in a supervisory position.
- One or more of the following-CISSP, CISA, CISM, PCI-QSA, PA-QSA, PCIP, CRISC, CGEIT, Certified Forensic Computer Examiner (CFCE), Certified Cyber Threat Analyst (CCTA), Certified Computer Examiner (CCE)
- Prior Global Payments, payment or technology industry experience is preferred.
- Master's Degree in a related field of study from an accredited university.
None Identified
Job Details- Seniority level: Mid-Senior level
- Employment type: Full-time
- Job function: Information Technology
- Industries: Financial Services and IT Services and IT Consulting
Insurance - Information Security Manager
Posted 11 days ago
Job Viewed
Job Description
Join to apply for the Insurance - Information Security Manager role at Michael Page
Insurance - Information Security Manager1 day ago Be among the first 25 applicants
Join to apply for the Insurance - Information Security Manager role at Michael Page
About Our Client
The hiring company is a large organization within the insurance industry, known for its strong market presence and commitment to innovation. The company offers a collaborative environment and focuses on delivering high-quality services to its clients in Hong Kong.
- Strategic Impact
- Professional Growth
The hiring company is a large organization within the insurance industry, known for its strong market presence and commitment to innovation. The company offers a collaborative environment and focuses on delivering high-quality services to its clients in Hong Kong.
Job Description
- Deliver expert guidance on security matters related to solution design, business initiatives, and general security inquiries.
- Create and update documentation for security policies and procedures, ensuring consistency with corporate security frameworks and standards.
- Perform risk evaluations on technology implementations and security controls to uncover vulnerabilities and propose mitigation strategies. Maintain a risk log and communicate potential impacts to relevant stakeholders.
- Lead and manage end-to-end security assessments and ISO compliance audits.
- Assist with external audit and regulatory compliance activities, and formulate action plans to address any identified gaps.
- Supervise the handling of security incidents, supporting frontline teams to ensure prompt identification, response, and resolution.
- Regularly assess and refine security policies and operational workflows to strengthen control measures.
- Compile and present security reports to the Chief Security Officer and senior leadership.
- Minimum of 5 years' experience in cybersecurity, risk management, or a related discipline.
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or a similar field.
- Proven success in driving and executing effective security programs and initiatives.
- Strong analytical skills with the ability to navigate complex business environments and work independently.
- Exceptional communication and presentation abilities, capable of translating technical security concepts into business-friendly language.
- Experience in a global or multinational corporate setting is preferred.
- Proficiency in English, both spoken and written.
- Possession of relevant certifications such as CISSP, CISA, OSCP, CEH, ISO 27001, NIST, or equivalent is advantageous.
- Competitive annual salary in the range of HKD 660,000 to HKD 816,000.
- Opportunity to work in a large organization within the insurance industry with a focus on innovation.
- Collaborative company culture that values professional growth and development.
Contact: Nicholas Ng
Quote job ref: JN- Seniority level
- Seniority level Mid-Senior level
- Employment type Full-time
- Job function Information Technology and Engineering
- Industries Insurance, Financial Services, and Capital Markets
Referrals increase your chances of interviewing at Michael Page by 2x
Get notified about new Information Security Manager jobs in Hong Kong, Hong Kong SAR .
Technology Risk Manager (IT Security) – Information Technology Department Manager / Lead / Senior Engineer - IT Security Administration Senior Manager & Team Head – Information Security and Technology Risk ManagementSha Tin District, Hong Kong SAR 1 week ago
IT Security and Operation Specialist (Asst Manager Level) Associate Director, Cloud and Infrastructure Compliance Head of Technology Risk Management, Risk Management Group Senior Manager - Infrastructure - Information Technology Services - Hong Kong ) Senior Technology Risk Manager (Overseas Branch) Senior Manager / Manager, IT Audit - SAP Consultant/ Senior Consultant/ Manager - Data Privacy and Protection (Technical) - Cyber - Hong Kong ) Technology Risk Management – Manager (Overseas Branch) Senior Audit Manager, Technology & ArchitectureKwun Tong District, Hong Kong SAR 2 months ago
Deputy Executive Manager, Business Information Security OfficeSha Tin District, Hong Kong SAR 2 weeks ago
IT Security / Cybersecurity Manager - FS Manager – Application Security & Governance, Information TechnologyKwai Tsing District, Hong Kong SAR 1 week ago
Technology Risk Manager (Information Security Control Division) Information and Technology Manager (Security Management) (Ref: ISD-AL)We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrInsurance - Information Security Manager
Posted 3 days ago
Job Viewed
Job Description
Join to apply for the Insurance - Information Security Manager role at Michael Page
Insurance - Information Security Manager1 day ago Be among the first 25 applicants
Join to apply for the Insurance - Information Security Manager role at Michael Page
About Our Client
The hiring company is a large organization within the insurance industry, known for its strong market presence and commitment to innovation. The company offers a collaborative environment and focuses on delivering high-quality services to its clients in Hong Kong.
- Strategic Impact
- Professional Growth
The hiring company is a large organization within the insurance industry, known for its strong market presence and commitment to innovation. The company offers a collaborative environment and focuses on delivering high-quality services to its clients in Hong Kong.
Job Description
- Deliver expert guidance on security matters related to solution design, business initiatives, and general security inquiries.
- Create and update documentation for security policies and procedures, ensuring consistency with corporate security frameworks and standards.
- Perform risk evaluations on technology implementations and security controls to uncover vulnerabilities and propose mitigation strategies. Maintain a risk log and communicate potential impacts to relevant stakeholders.
- Lead and manage end-to-end security assessments and ISO compliance audits.
- Assist with external audit and regulatory compliance activities, and formulate action plans to address any identified gaps.
- Supervise the handling of security incidents, supporting frontline teams to ensure prompt identification, response, and resolution.
- Regularly assess and refine security policies and operational workflows to strengthen control measures.
- Compile and present security reports to the Chief Security Officer and senior leadership.
- Minimum of 5 years' experience in cybersecurity, risk management, or a related discipline.
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or a similar field.
- Proven success in driving and executing effective security programs and initiatives.
- Strong analytical skills with the ability to navigate complex business environments and work independently.
- Exceptional communication and presentation abilities, capable of translating technical security concepts into business-friendly language.
- Experience in a global or multinational corporate setting is preferred.
- Proficiency in English, both spoken and written.
- Possession of relevant certifications such as CISSP, CISA, OSCP, CEH, ISO 27001, NIST, or equivalent is advantageous.
- Competitive annual salary in the range of HKD 660,000 to HKD 816,000.
- Opportunity to work in a large organization within the insurance industry with a focus on innovation.
- Collaborative company culture that values professional growth and development.
Contact: Nicholas Ng
Quote job ref: JN- Seniority level
- Seniority level Mid-Senior level
- Employment type Full-time
- Job function Information Technology and Engineering
- Industries Insurance, Financial Services, and Capital Markets
Referrals increase your chances of interviewing at Michael Page by 2x
Get notified about new Information Security Manager jobs in Hong Kong, Hong Kong SAR .
Technology Risk Manager (IT Security) – Information Technology Department Manager / Lead / Senior Engineer - IT Security Administration Senior Manager & Team Head – Information Security and Technology Risk ManagementSha Tin District, Hong Kong SAR 1 week ago
IT Security and Operation Specialist (Asst Manager Level) Associate Director, Cloud and Infrastructure Compliance Head of Technology Risk Management, Risk Management Group Senior Manager - Infrastructure - Information Technology Services - Hong Kong ) Senior Technology Risk Manager (Overseas Branch) Senior Manager / Manager, IT Audit - SAP Consultant/ Senior Consultant/ Manager - Data Privacy and Protection (Technical) - Cyber - Hong Kong ) Technology Risk Management – Manager (Overseas Branch) Senior Audit Manager, Technology & ArchitectureKwun Tong District, Hong Kong SAR 2 months ago
Deputy Executive Manager, Business Information Security OfficeSha Tin District, Hong Kong SAR 2 weeks ago
IT Security / Cybersecurity Manager - FS Manager – Application Security & Governance, Information TechnologyKwai Tsing District, Hong Kong SAR 1 week ago
Technology Risk Manager (Information Security Control Division) Information and Technology Manager (Security Management) (Ref: ISD-AL)We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrInformation Security Management Lead
Posted 5 days ago
Job Viewed
Job Description
2 days ago Be among the first 25 applicants
Talent Acquisition Lead @ PCCW Media / HKTWe are seeking a highly capable and experienced professional with approximately 10 years of experience in cybersecurity governance, and IT audit and security assessment support. This role focuses on leading security assessments in collaboration with technical teams, reviewing and translating technical findings into clear and impactful reports for clients, regulators, and senior management. The ideal candidate will possess strong analytical skills, excellent communication abilities, and a solid understanding of security controls across various technology domains.
Your Role
- Lead and coordinate security assessments across infrastructure, applications, and cloud environments, working closely with technical SMEs.
- Interface with technical teams to understand control implementation and translate findings into governance insights.
- Prepare high-quality security reports and presentations tailored for client and senior stakeholders.
- Support responses to client and regulatory security inquiries, ensuring accuracy, clarity, and timely delivery.
- Support the development of security reporting and risk metrics
- Contribute to the development and refinement of security policies, standards, and procedures.
- Support audit and assessment activities, including evidence collection and coordination with internal teams.
- Promote security awareness and contribute to training initiatives across the organization.
To Succeed in this Role
- Minimum 10 years of experience in cybersecurity governance, technology risk, or audit-related roles.
- Strong understanding of security controls across infrastructure, application, and cloud domains.
- Proven ability to work with technical teams and translate technical content into business-friendly reporting.
- Experience in preparing client-facing documentation and presentations.
- Excellent written and verbal communication skills in English.
- Familiarity with regulatory frameworks and standards (e.g., ISO 27001, NIST, CIS).
- Relevant certifications such as CISM, CRISC, ISO 27001 Lead Implementer, or equivalent are preferred.
Preferred Attributes
- Experience in regulated industries such as finance, healthcare, or insurance.
- Strong stakeholder engagement and coordination skills.
- Detail-oriented with a proactive and structured approach to governance.
- Familiarity with GRC
- Seniority level Mid-Senior level
- Employment type Full-time
- Job function Information Technology
- Industries Software Development, Information Services, and Technology, Information and Media
Referrals increase your chances of interviewing at PCCW by 2x
Get notified about new Information Security Specialist jobs in Hong Kong, Hong Kong SAR .
Information Technology Cybersecurity Analyst / Specialist Cybersecurity Detection and Response Analyst Technology Consulting - Cyber Security - Security Governance - Senior Associate - Hong Kong Principal IT Lead (Information Security) (Ref: IT-ISNS-PITL-IS-LI)) Sr. Analyst, IAM & Cloud Security Engineering, ITWe’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrBe The First To Know
About the latest Cism Jobs in Hong Kong !
Information Security Management Lead
Posted 22 days ago
Job Viewed
Job Description
2 days ago Be among the first 25 applicants
Talent Acquisition Lead @ PCCW Media / HKTWe are seeking a highly capable and experienced professional with approximately 10 years of experience in cybersecurity governance, and IT audit and security assessment support. This role focuses on leading security assessments in collaboration with technical teams, reviewing and translating technical findings into clear and impactful reports for clients, regulators, and senior management. The ideal candidate will possess strong analytical skills, excellent communication abilities, and a solid understanding of security controls across various technology domains.
Your Role
- Lead and coordinate security assessments across infrastructure, applications, and cloud environments, working closely with technical SMEs.
- Interface with technical teams to understand control implementation and translate findings into governance insights.
- Prepare high-quality security reports and presentations tailored for client and senior stakeholders.
- Support responses to client and regulatory security inquiries, ensuring accuracy, clarity, and timely delivery.
- Support the development of security reporting and risk metrics
- Contribute to the development and refinement of security policies, standards, and procedures.
- Support audit and assessment activities, including evidence collection and coordination with internal teams.
- Promote security awareness and contribute to training initiatives across the organization.
To Succeed in this Role
- Minimum 10 years of experience in cybersecurity governance, technology risk, or audit-related roles.
- Strong understanding of security controls across infrastructure, application, and cloud domains.
- Proven ability to work with technical teams and translate technical content into business-friendly reporting.
- Experience in preparing client-facing documentation and presentations.
- Excellent written and verbal communication skills in English.
- Familiarity with regulatory frameworks and standards (e.g., ISO 27001, NIST, CIS).
- Relevant certifications such as CISM, CRISC, ISO 27001 Lead Implementer, or equivalent are preferred.
Preferred Attributes
- Experience in regulated industries such as finance, healthcare, or insurance.
- Strong stakeholder engagement and coordination skills.
- Detail-oriented with a proactive and structured approach to governance.
- Familiarity with GRC
- Seniority level Mid-Senior level
- Employment type Full-time
- Job function Information Technology
- Industries Software Development, Information Services, and Technology, Information and Media
Referrals increase your chances of interviewing at PCCW by 2x
Get notified about new Information Security Specialist jobs in Hong Kong, Hong Kong SAR .
Information Technology Cybersecurity Analyst / Specialist Cybersecurity Detection and Response Analyst Technology Consulting - Cyber Security - Security Governance - Senior Associate - Hong Kong Principal IT Lead (Information Security) (Ref: IT-ISNS-PITL-IS-LI)) Sr. Analyst, IAM & Cloud Security Engineering, ITWe’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrInformation Security Manager - Dah Sing Financial Group
Posted today
Job Viewed
Job Description
About Dah Sing Group
The Dah Sing Group is a leading financial services group in Hong Kong offering banking, insurance, financial and other related services through its growing network of over 70 branches in Hong Kong, Macau and Mainland China.
Our currency is caring, teamwork and progressiveness. We accept that everyone is unique and different in talent, but alike in the capacity for growth. Our task is to shape a culture that creates a sense of pride in achieving something beyond just a job, and an environment where you can be your true and authentic self, like at home.
Job Purpose:
Reporting to the Head of Information Security to support delivering information security services and carrying out information security related activities.
Job Description of the position:
• Conduct cyber security testing covering penetration test, Infra and Web Manage security tools
• Manage network security system covering firewall, NAC, IPS, SIEM and etc.
• Act as project manager role on Information security projects.
• Support and Analyze cybersecurity incidents and make recommendations on remedial actions.
• Define and design adequate security controls to maintain secure control environment.
• Provide security advisory service to stakeholders on new initiatives and development projects.
• Implement systems and procedures to enable digital forensics capabilities
• Maintain Cyber Incident Response plan and playbook. Conduct cyber incident response drill in regular basis.
Incumbent Requirements:
• University graduate in Computer Science / Information Technology or equivalent.
• Minimum 6 years of relevant work experience in information security, cybersecurity or technology risk
• Possess one or more professional certificates : OCSP, CISSP, CISM, CCSP, CISA
• Solid experience on penetration test, red/blue team exercise and network security including firewall, NAC, IPS.
• Sound knowledge of regulators' requirement on Cyber Resilience Assessment Framework (CRAF)
• Sound knowledge of vulnerability management and threat intelligence analysis.
• Strong communication in both Chinese and English; Good communication and interpersonal skills.
• Mature, independent and able to deliver quality results under tight schedule.
Please note that only shortlisted candidates will be notified.
Senior Manager Information Security
Posted 18 days ago
Job Viewed
Job Description
Daily Operations – Information Security Governance & Control
- Develop and maintain the information security governance framework and risk portfolio in alignment with Company’s IT policies, standards, and guidelines.
- Oversee regular security assessments, including identity and access management (IAM) reviews, vulnerability management, remediation activities, and independent testing of IT infrastructure and applications to ensure compliance with security standards.
- Establish and manage processes to proactively identify technology risks and potential security breaches, ensuring continuous protection of organizational systems and data.
- Supervise IAM operations, including access provisioning, role-based access control, and periodic access certifications, ensuring adherence to compliance and audit requirements.
- Lead the execution of key local information security initiatives, such as IAM enhancements and vulnerability remediation efforts.
- Drive the deployment of groupwide strategic information security solutions across local IT infrastructure and systems.
- Enhance security assessment practices for applications and infrastructure, providing actionable recommendations to strengthen the organization’s security posture.
- Lead ad-hoc cross-functional teams on special projects and strategic initiatives related to information security.
- Develop and implement plans to uplift information security controls across the organization.
- Serve as a key liaison with group offices, business partners, corporate clients, IT vendors, and external parties on IT security matters as needed.
- Mid-Senior level
- Full-time
- Information Technology
Location: Wan Chai District, Hong Kong SAR
#J-18808-Ljbffr