50 Security Leadership jobs in Hong Kong
Manager/Associate Director, Cyber Security (Strategy, Governance & Risk), Technology Consulting
Posted 10 days ago
Job Viewed
Job Description
Join to apply for the Manager/Associate Director, Cyber Security (Strategy, Governance & Risk), Technology Consulting role at KPMG China
Manager/Associate Director, Cyber Security (Strategy, Governance & Risk), Technology Consulting1 year ago Be among the first 25 applicants
Join to apply for the Manager/Associate Director, Cyber Security (Strategy, Governance & Risk), Technology Consulting role at KPMG China
KPMG China provides multidisciplinary services from audit and tax to advisory, with a strong focus on serving our clients’ needs and their industries. Not only do we have an overriding commitment to provide the highest quality services for our clients, but we also strive to become a responsible corporate citizen that has a positive impact on our environment and community. At KPMG, you’ll translate insights into action and reveal opportunities for all—our teams, our clients and our world.
Service Line Overview
At KPMG's Consulting practice, we do not limit ourselves to either strategy or implementation. We deliver both. Our Hong Kong division is the fastest growing within KPMG China and represents a young and enthusiastic team that always pushes for success. Since our inception, we have acquired in-depth knowledge of an incredibly broad range of sectors and services.
KPMG is the firm that views cyber security as a business enabler, and not just an IT issue. From the boardroom to back office, we help clients through Strategy and Governance, Transformation, Cyber Defense and Cyber Response. So that they are prepared for uncertainty and use cyber security to advance the business, not stand in the way.
Our wide range of projects includes Cyber Strategy, Cyber Digital Transformation, Governance & Risk, as well as a growing presence in Attack & Penetration Tester or Ethical Hacker. We are keen to speaking with cyber security specialists with various expertise and experiences to join our growth story.
We are now seeking Manager / Associate Director candidates for Cyber Security Team.
Key Responsibilities
- Lead cyber security engagements including security strategy, policy and architecture, information privacy and governance, certification and compliance, business and technology resilience and security testing.
- Communicate technical issues in business terms with senior management and deliver value using a pragmatic approach to the technical components of information security.
- Lead Cybersecurity Maturity Assessments and Cybersecurity Control Gap Remediation (covering the design and implementation of controls to address the people, process and technology risks) projects.
- Assess the IT security architecture across application, database, operating system, hardware platforms (including web and mobile) and network infrastructure -for vulnerabilities to cyber-attack
- Lead Cybersecurity Maturity Assessments by assessing cyber risk factors across 6 functional domains - Leadership & Governance, Human Factors, Information Risk Management, Business Continuity, Technology & Operations, Legal & Compliance
- Design and implement processes for Identity & Access Controls, Cyber Incident Management, Intrusion Detection, Threat Intelligence, Cyber Data Analytics, Security Monitoring, etc.
- Identify and communicate engagement findings to senior management and client personnel
- Provide strategic advice to our clients
- Take the lead role in continuously enhancing the existing cyber assessment methodologies.
- Drive marketing and training materials to help develop staff awareness within the company and communicate KPMG’s capabilities to clients
- Build and maintain relationships with existing and prospective clients, and develop / improve your network of business contacts
- Lead with scoping prospective engagements and developing proposals
- Take an active role in KPMG’s global community of security professionals, assist with research into vulnerabilities and develop our ability to perform security engagements
- Work with multi-level of our clients from C-level executives, senior and management staff to on-the-ground professionals
- Bachelor’s degree or above in cybersecurity, technology, engineering, or business studies with information systems major/minor from an accredited college / university along with deep interest in technology risk, security and IT governance will be considered
- 5+ years' experience, ideally within a professional services environment or internal consultancy function delivering cyber security related projects
- Experience in financial services is preferred
- Professional qualification holder will be preferrable (e.g. OSCP, CISSP, CRISC, CISA, CISM, PMP or other relevant qualifications)
- Prior consulting experience in information security preferred, ideally within a professional services environment or internal consultancy function delivering cyber security related services
- Excellent written and verbal communication skills in English and Chinese (Mandarin or Cantonese)
- Has strong knowledge on the below skillsets are preferrable
- Interpersonal skills with a demonstrated ability to gain the confidence and respect of senior level executives
- Client services orientation and accustomed to taking an active role in executing client engagements
- Analytical skills and the ability to develop thought leadership publications
- Knowledge of enterprise technologies, especially networking principles and internet-based technologies, with self-motivated learning ability
- Knowledge of internet application security, including common internet application vulnerabilities and network architecture to support internet applications
- Knowledge base in operations, enterprise networking, operating systems and database security evaluation and architecture
- Knowledge of IT security vendor products
- Candidate with less experience will be considered as Manager
- Additional Qualifications for Associate Director
- A minimum of eight years of relevant experience
- Demonstrated ability to build market presence, identify business opportunities, lead project engagements, attract new business, and build lasting professional relationships with senior client executives
KPMG is looking for someone who is passionate about helping our clients with their cybersecurity challenges. In return, we are helping you to develop your skills and career within the KPMG network.
- Well-structured career development and learning path, 1-to-1 coaching by our partners
- Access to various learning resources
- Wide exposure to working with leading financial institutions and multi-national corporations
- Continuous sponsorship and support on professional certificate development
- Work in a passionate team with blended technology risk and cybersecurity talents
At KPMG China, we are committed to being an equal opportunity employer, with zero tolerance for any form of discrimination against any persons. It is important for us to create an inclusive, diverse and agile workplace for our people to develop and thrive at both a personal and professional level.
We strive to make ESG (environmental, social and governance) a watermark running through our organisation; from empowering our people to become agents of positive change, to providing better solutions and services to our clients to help them achieve their ESG goals. View Our Impact Plan to learn more about our ESG commitments and progress across four key pillars - Governance, People, Planet and Prosperity – and how we make a positive impact on our people, environment and society.
We encourage you to come as you are, and we welcome all qualified candidates to apply, and hope you unlock opportunities with us. Visit KPMG China website for more company information.
You acknowledge and agree that all personal information hereby provided regarding yourself will be used by KPMG China for its candidate selection purposed only. KPMG China collects, uses, processes, and retains your personal information in accordance with KPMG China’s Online Privacy Statement and/or KPMG China Privacy Statement (collectively "Privacy Statement "). During the recruitment process, KPMG China may need to store personal information of candidates in a designated third-party application tracking platform.
If you have any questions regarding the information you provided in the form or your job application in general, please contact KPMG China’s HR personnel in the location where your application is submitted (see here). Seniority level
- Seniority level Mid-Senior level
- Employment type Full-time
- Job function Information Technology
- Industries Professional Services
Referrals increase your chances of interviewing at KPMG China by 2x
Sign in to set job alerts for “Director of Cyber Security” roles. Associate Director, Data Security and ComplianceShenzhen, Guangdong, China CN¥20,000.00-CN¥30,000.00 2 years ago
Senior Manager, Group Information Security Security Architect - Director/Executive Level Manager/Associate Director, Cyber Security (Simulated Attack), Technology Consulting Manager/Associate Director , Cloud Security, Technology Consulting Equity Swaps Web UI Developer, Director P3, Institutional Securities Technology Java / Scala Full Stack Developer, Director P3, Institutional Securities TechnologyWe’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrManager/Associate Director, Cyber Security (Strategy, Governance & Risk), Technology Consulting
Posted 3 days ago
Job Viewed
Job Description
Join to apply for the Manager/Associate Director, Cyber Security (Strategy, Governance & Risk), Technology Consulting role at KPMG China
Manager/Associate Director, Cyber Security (Strategy, Governance & Risk), Technology Consulting1 year ago Be among the first 25 applicants
Join to apply for the Manager/Associate Director, Cyber Security (Strategy, Governance & Risk), Technology Consulting role at KPMG China
KPMG China provides multidisciplinary services from audit and tax to advisory, with a strong focus on serving our clients’ needs and their industries. Not only do we have an overriding commitment to provide the highest quality services for our clients, but we also strive to become a responsible corporate citizen that has a positive impact on our environment and community. At KPMG, you’ll translate insights into action and reveal opportunities for all—our teams, our clients and our world.
Service Line Overview
At KPMG's Consulting practice, we do not limit ourselves to either strategy or implementation. We deliver both. Our Hong Kong division is the fastest growing within KPMG China and represents a young and enthusiastic team that always pushes for success. Since our inception, we have acquired in-depth knowledge of an incredibly broad range of sectors and services.
KPMG is the firm that views cyber security as a business enabler, and not just an IT issue. From the boardroom to back office, we help clients through Strategy and Governance, Transformation, Cyber Defense and Cyber Response. So that they are prepared for uncertainty and use cyber security to advance the business, not stand in the way.
Our wide range of projects includes Cyber Strategy, Cyber Digital Transformation, Governance & Risk, as well as a growing presence in Attack & Penetration Tester or Ethical Hacker. We are keen to speaking with cyber security specialists with various expertise and experiences to join our growth story.
We are now seeking Manager / Associate Director candidates for Cyber Security Team.
Key Responsibilities
- Lead cyber security engagements including security strategy, policy and architecture, information privacy and governance, certification and compliance, business and technology resilience and security testing.
- Communicate technical issues in business terms with senior management and deliver value using a pragmatic approach to the technical components of information security.
- Lead Cybersecurity Maturity Assessments and Cybersecurity Control Gap Remediation (covering the design and implementation of controls to address the people, process and technology risks) projects.
- Assess the IT security architecture across application, database, operating system, hardware platforms (including web and mobile) and network infrastructure -for vulnerabilities to cyber-attack
- Lead Cybersecurity Maturity Assessments by assessing cyber risk factors across 6 functional domains - Leadership & Governance, Human Factors, Information Risk Management, Business Continuity, Technology & Operations, Legal & Compliance
- Design and implement processes for Identity & Access Controls, Cyber Incident Management, Intrusion Detection, Threat Intelligence, Cyber Data Analytics, Security Monitoring, etc.
- Identify and communicate engagement findings to senior management and client personnel
- Provide strategic advice to our clients
- Take the lead role in continuously enhancing the existing cyber assessment methodologies.
- Drive marketing and training materials to help develop staff awareness within the company and communicate KPMG’s capabilities to clients
- Build and maintain relationships with existing and prospective clients, and develop / improve your network of business contacts
- Lead with scoping prospective engagements and developing proposals
- Take an active role in KPMG’s global community of security professionals, assist with research into vulnerabilities and develop our ability to perform security engagements
- Work with multi-level of our clients from C-level executives, senior and management staff to on-the-ground professionals
- Bachelor’s degree or above in cybersecurity, technology, engineering, or business studies with information systems major/minor from an accredited college / university along with deep interest in technology risk, security and IT governance will be considered
- 5+ years' experience, ideally within a professional services environment or internal consultancy function delivering cyber security related projects
- Experience in financial services is preferred
- Professional qualification holder will be preferrable (e.g. OSCP, CISSP, CRISC, CISA, CISM, PMP or other relevant qualifications)
- Prior consulting experience in information security preferred, ideally within a professional services environment or internal consultancy function delivering cyber security related services
- Excellent written and verbal communication skills in English and Chinese (Mandarin or Cantonese)
- Has strong knowledge on the below skillsets are preferrable
- Interpersonal skills with a demonstrated ability to gain the confidence and respect of senior level executives
- Client services orientation and accustomed to taking an active role in executing client engagements
- Analytical skills and the ability to develop thought leadership publications
- Knowledge of enterprise technologies, especially networking principles and internet-based technologies, with self-motivated learning ability
- Knowledge of internet application security, including common internet application vulnerabilities and network architecture to support internet applications
- Knowledge base in operations, enterprise networking, operating systems and database security evaluation and architecture
- Knowledge of IT security vendor products
- Candidate with less experience will be considered as Manager
- Additional Qualifications for Associate Director
- A minimum of eight years of relevant experience
- Demonstrated ability to build market presence, identify business opportunities, lead project engagements, attract new business, and build lasting professional relationships with senior client executives
KPMG is looking for someone who is passionate about helping our clients with their cybersecurity challenges. In return, we are helping you to develop your skills and career within the KPMG network.
- Well-structured career development and learning path, 1-to-1 coaching by our partners
- Access to various learning resources
- Wide exposure to working with leading financial institutions and multi-national corporations
- Continuous sponsorship and support on professional certificate development
- Work in a passionate team with blended technology risk and cybersecurity talents
At KPMG China, we are committed to being an equal opportunity employer, with zero tolerance for any form of discrimination against any persons. It is important for us to create an inclusive, diverse and agile workplace for our people to develop and thrive at both a personal and professional level.
We strive to make ESG (environmental, social and governance) a watermark running through our organisation; from empowering our people to become agents of positive change, to providing better solutions and services to our clients to help them achieve their ESG goals. View Our Impact Plan to learn more about our ESG commitments and progress across four key pillars - Governance, People, Planet and Prosperity – and how we make a positive impact on our people, environment and society.
We encourage you to come as you are, and we welcome all qualified candidates to apply, and hope you unlock opportunities with us. Visit KPMG China website for more company information.
You acknowledge and agree that all personal information hereby provided regarding yourself will be used by KPMG China for its candidate selection purposed only. KPMG China collects, uses, processes, and retains your personal information in accordance with KPMG China’s Online Privacy Statement and/or KPMG China Privacy Statement (collectively "Privacy Statement "). During the recruitment process, KPMG China may need to store personal information of candidates in a designated third-party application tracking platform.
If you have any questions regarding the information you provided in the form or your job application in general, please contact KPMG China’s HR personnel in the location where your application is submitted (see here). Seniority level
- Seniority level Mid-Senior level
- Employment type Full-time
- Job function Information Technology
- Industries Professional Services
Referrals increase your chances of interviewing at KPMG China by 2x
Sign in to set job alerts for “Director of Cyber Security” roles. Associate Director, Data Security and ComplianceShenzhen, Guangdong, China CN¥20,000.00-CN¥30,000.00 2 years ago
Senior Manager, Group Information Security Security Architect - Director/Executive Level Manager/Associate Director, Cyber Security (Simulated Attack), Technology Consulting Manager/Associate Director , Cloud Security, Technology Consulting Equity Swaps Web UI Developer, Director P3, Institutional Securities Technology Java / Scala Full Stack Developer, Director P3, Institutional Securities TechnologyWe’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrInformation Security Management Lead
Posted 4 days ago
Job Viewed
Job Description
2 days ago Be among the first 25 applicants
Talent Acquisition Lead @ PCCW Media / HKTWe are seeking a highly capable and experienced professional with approximately 10 years of experience in cybersecurity governance, and IT audit and security assessment support. This role focuses on leading security assessments in collaboration with technical teams, reviewing and translating technical findings into clear and impactful reports for clients, regulators, and senior management. The ideal candidate will possess strong analytical skills, excellent communication abilities, and a solid understanding of security controls across various technology domains.
Your Role
- Lead and coordinate security assessments across infrastructure, applications, and cloud environments, working closely with technical SMEs.
- Interface with technical teams to understand control implementation and translate findings into governance insights.
- Prepare high-quality security reports and presentations tailored for client and senior stakeholders.
- Support responses to client and regulatory security inquiries, ensuring accuracy, clarity, and timely delivery.
- Support the development of security reporting and risk metrics
- Contribute to the development and refinement of security policies, standards, and procedures.
- Support audit and assessment activities, including evidence collection and coordination with internal teams.
- Promote security awareness and contribute to training initiatives across the organization.
To Succeed in this Role
- Minimum 10 years of experience in cybersecurity governance, technology risk, or audit-related roles.
- Strong understanding of security controls across infrastructure, application, and cloud domains.
- Proven ability to work with technical teams and translate technical content into business-friendly reporting.
- Experience in preparing client-facing documentation and presentations.
- Excellent written and verbal communication skills in English.
- Familiarity with regulatory frameworks and standards (e.g., ISO 27001, NIST, CIS).
- Relevant certifications such as CISM, CRISC, ISO 27001 Lead Implementer, or equivalent are preferred.
Preferred Attributes
- Experience in regulated industries such as finance, healthcare, or insurance.
- Strong stakeholder engagement and coordination skills.
- Detail-oriented with a proactive and structured approach to governance.
- Familiarity with GRC
- Seniority level Mid-Senior level
- Employment type Full-time
- Job function Information Technology
- Industries Software Development, Information Services, and Technology, Information and Media
Referrals increase your chances of interviewing at PCCW by 2x
Get notified about new Information Security Specialist jobs in Hong Kong, Hong Kong SAR .
Information Technology Cybersecurity Analyst / Specialist Cybersecurity Detection and Response Analyst Technology Consulting - Cyber Security - Security Governance - Senior Associate - Hong Kong Principal IT Lead (Information Security) (Ref: IT-ISNS-PITL-IS-LI)) Sr. Analyst, IAM & Cloud Security Engineering, ITWe’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrInformation Security Management Lead
Posted today
Job Viewed
Job Description
2 days ago Be among the first 25 applicants
Talent Acquisition Lead @ PCCW Media / HKTWe are seeking a highly capable and experienced professional with approximately 10 years of experience in cybersecurity governance, and IT audit and security assessment support. This role focuses on leading security assessments in collaboration with technical teams, reviewing and translating technical findings into clear and impactful reports for clients, regulators, and senior management. The ideal candidate will possess strong analytical skills, excellent communication abilities, and a solid understanding of security controls across various technology domains.
Your Role
- Lead and coordinate security assessments across infrastructure, applications, and cloud environments, working closely with technical SMEs.
- Interface with technical teams to understand control implementation and translate findings into governance insights.
- Prepare high-quality security reports and presentations tailored for client and senior stakeholders.
- Support responses to client and regulatory security inquiries, ensuring accuracy, clarity, and timely delivery.
- Support the development of security reporting and risk metrics
- Contribute to the development and refinement of security policies, standards, and procedures.
- Support audit and assessment activities, including evidence collection and coordination with internal teams.
- Promote security awareness and contribute to training initiatives across the organization.
To Succeed in this Role
- Minimum 10 years of experience in cybersecurity governance, technology risk, or audit-related roles.
- Strong understanding of security controls across infrastructure, application, and cloud domains.
- Proven ability to work with technical teams and translate technical content into business-friendly reporting.
- Experience in preparing client-facing documentation and presentations.
- Excellent written and verbal communication skills in English.
- Familiarity with regulatory frameworks and standards (e.g., ISO 27001, NIST, CIS).
- Relevant certifications such as CISM, CRISC, ISO 27001 Lead Implementer, or equivalent are preferred.
Preferred Attributes
- Experience in regulated industries such as finance, healthcare, or insurance.
- Strong stakeholder engagement and coordination skills.
- Detail-oriented with a proactive and structured approach to governance.
- Familiarity with GRC
- Seniority level Mid-Senior level
- Employment type Full-time
- Job function Information Technology
- Industries Software Development, Information Services, and Technology, Information and Media
Referrals increase your chances of interviewing at PCCW by 2x
Get notified about new Information Security Specialist jobs in Hong Kong, Hong Kong SAR .
Information Technology Cybersecurity Analyst / Specialist Cybersecurity Detection and Response Analyst Technology Consulting - Cyber Security - Security Governance - Senior Associate - Hong Kong Principal IT Lead (Information Security) (Ref: IT-ISNS-PITL-IS-LI)) Sr. Analyst, IAM & Cloud Security Engineering, ITWe’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrManager, Security Management
Posted 10 days ago
Job Viewed
Job Description
Join to apply for the Manager, Security Management role at Bank of Communications Co., Ltd. London Branch
Continue with Google Continue with Google
Join to apply for the Manager, Security Management role at Bank of Communications Co., Ltd. London Branch
Get AI-powered advice on this job and more exclusive features.
Sign in to access AI-powered advicesContinue with Google Continue with Google
Continue with Google Continue with Google
Continue with Google Continue with Google
Continue with Google Continue with Google
Continue with Google Continue with Google
Continue with Google Continue with Google
Company Description
Founded in 1908, Bank of Communications Co., Ltd. (Stock Code: 3328) is one of the oldest banks in China, and also acted as one of the country’s banknote-issuing institutions. The bank was listed on the Stock Exchange of Hong Kong Limited and the Shanghai Stock Exchange in June 2005 and May 2007 respectively. At present, apart from Tibet, BOCOM comprises 30 provincial branches across provinces, municipalities and autonomous regions, plus a network of 2,637 operating locations in 173 cities and 112 counties nationwide. Beyond China, BOCOM has established overseas centers in Hong Kong, New York, San Francisco, Tokyo, Singapore, Seoul, Frankfurt, Macau, Ho Chi Minh City, and Sydney; one subsidiary bank in the U.K. and one representative office in Taipei. BOCOM’s development strategy is to become a first class listed universal banking group focusing on international expansion and specializing in wealth management.
Company Description
Founded in 1908, Bank of Communications Co., Ltd. (Stock Code: 3328) is one of the oldest banks in China, and also acted as one of the country’s banknote-issuing institutions. The bank was listed on the Stock Exchange of Hong Kong Limited and the Shanghai Stock Exchange in June 2005 and May 2007 respectively. At present, apart from Tibet, BOCOM comprises 30 provincial branches across provinces, municipalities and autonomous regions, plus a network of 2,637 operating locations in 173 cities and 112 counties nationwide. Beyond China, BOCOM has established overseas centers in Hong Kong, New York, San Francisco, Tokyo, Singapore, Seoul, Frankfurt, Macau, Ho Chi Minh City, and Sydney; one subsidiary bank in the U.K. and one representative office in Taipei. BOCOM’s development strategy is to become a first class listed universal banking group focusing on international expansion and specializing in wealth management.
Job Description
- Motivate an effective security operations team to oversee the security services
- Follow up the incident report and drive the analysis of security incidents
- Analyze industry trends and make recommendation to Senior Management for improving risk exposure
- Manage the external vendors in respect of regular communications and ad-hoc work as assigned
- Degree holder or above in Business Administration or related disciplines
- Minimum 5 years' work experience in security service industry or disciplinary service
- Excellent leadership with practical knowledge and good problem-solving skills
- Self-motivated with professional appearance and be customer-oriented
- Strong analytical mind with good communication and interpersonal skills
- Seniority level Mid-Senior level
- Employment type Full-time
- Job function Accounting/Auditing and Finance
- Industries Banking and Investment Banking
Referrals increase your chances of interviewing at Bank of Communications Co., Ltd. London Branch by 2x
Get notified about new Security Manager jobs in Hong Kong, Hong Kong SAR .
Deputy Executive Manager, Security ArchitectureSha Tin District, Hong Kong SAR 20 minutes ago
Senior IT Operations and Security Manager - Prominent Tech Firm Manager, Operational and Strategic Risk (Cyber Security) Regional Assistant Infrastructure Manager, APACShenzhen, Guangdong, China
CN¥40,000.00
-
CN¥60,000.00
1 year ago
We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrManager, Security Management
Posted 3 days ago
Job Viewed
Job Description
Join to apply for the Manager, Security Management role at Bank of Communications Co., Ltd. London Branch
Continue with Google Continue with Google
Join to apply for the Manager, Security Management role at Bank of Communications Co., Ltd. London Branch
Get AI-powered advice on this job and more exclusive features.
Sign in to access AI-powered advicesContinue with Google Continue with Google
Continue with Google Continue with Google
Continue with Google Continue with Google
Continue with Google Continue with Google
Continue with Google Continue with Google
Continue with Google Continue with Google
Company Description
Founded in 1908, Bank of Communications Co., Ltd. (Stock Code: 3328) is one of the oldest banks in China, and also acted as one of the country’s banknote-issuing institutions. The bank was listed on the Stock Exchange of Hong Kong Limited and the Shanghai Stock Exchange in June 2005 and May 2007 respectively. At present, apart from Tibet, BOCOM comprises 30 provincial branches across provinces, municipalities and autonomous regions, plus a network of 2,637 operating locations in 173 cities and 112 counties nationwide. Beyond China, BOCOM has established overseas centers in Hong Kong, New York, San Francisco, Tokyo, Singapore, Seoul, Frankfurt, Macau, Ho Chi Minh City, and Sydney; one subsidiary bank in the U.K. and one representative office in Taipei. BOCOM’s development strategy is to become a first class listed universal banking group focusing on international expansion and specializing in wealth management.
Company Description
Founded in 1908, Bank of Communications Co., Ltd. (Stock Code: 3328) is one of the oldest banks in China, and also acted as one of the country’s banknote-issuing institutions. The bank was listed on the Stock Exchange of Hong Kong Limited and the Shanghai Stock Exchange in June 2005 and May 2007 respectively. At present, apart from Tibet, BOCOM comprises 30 provincial branches across provinces, municipalities and autonomous regions, plus a network of 2,637 operating locations in 173 cities and 112 counties nationwide. Beyond China, BOCOM has established overseas centers in Hong Kong, New York, San Francisco, Tokyo, Singapore, Seoul, Frankfurt, Macau, Ho Chi Minh City, and Sydney; one subsidiary bank in the U.K. and one representative office in Taipei. BOCOM’s development strategy is to become a first class listed universal banking group focusing on international expansion and specializing in wealth management.
Job Description
- Motivate an effective security operations team to oversee the security services
- Follow up the incident report and drive the analysis of security incidents
- Analyze industry trends and make recommendation to Senior Management for improving risk exposure
- Manage the external vendors in respect of regular communications and ad-hoc work as assigned
- Degree holder or above in Business Administration or related disciplines
- Minimum 5 years' work experience in security service industry or disciplinary service
- Excellent leadership with practical knowledge and good problem-solving skills
- Self-motivated with professional appearance and be customer-oriented
- Strong analytical mind with good communication and interpersonal skills
- Seniority level Mid-Senior level
- Employment type Full-time
- Job function Accounting/Auditing and Finance
- Industries Banking and Investment Banking
Referrals increase your chances of interviewing at Bank of Communications Co., Ltd. London Branch by 2x
Get notified about new Security Manager jobs in Hong Kong, Hong Kong SAR .
Deputy Executive Manager, Security ArchitectureSha Tin District, Hong Kong SAR 20 minutes ago
Senior IT Operations and Security Manager - Prominent Tech Firm Manager, Operational and Strategic Risk (Cyber Security) Regional Assistant Infrastructure Manager, APACShenzhen, Guangdong, China
CN¥40,000.00
-
CN¥60,000.00
1 year ago
We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrSecurity Risk Management Specialist
Posted 10 days ago
Job Viewed
Job Description
Join to apply for the Security Risk Management Specialist role at Canonical
Join to apply for the Security Risk Management Specialist role at Canonical
In security risk management we're looking to harness the power of industry best practice combined with driving new innovation on how we do security risk assessments and modelling. Our security risk management team is the primary owner of the strategy and practices of how we identify, track and reduce our security risk across everything we do.
To support this we need to use industry best practices paired with emerging threat information to to promote risk identification, quantification, impact analysis, and modelling to ultimately drive decision making. In this role, you will help establish and execute a broad strategic vision for the security risk program at Canonical. You will not only work within the team but also cross-functionally with various teams across the organisation. The team contributes ideas and requirements for Canonical product security, improving the resilience and robustness of all Ubuntu customers and users subject to cyber attacks. Additionally, the team collaborates with our Organisational Learning and Development team to develop playbooks and facilitate security training across Canonical.
The security risk management team's mission is not only to secure Canonical, but also to contribute to the security of the wider open source ecosystem. They might share knowledge through public presentations and industry events, and share threat intelligence with the wider community or represent Canonical in sector-specific governance bodies.
What you will do in this role:
- Define Canonical's security risk management standards and playbooks
- Analyse and improve Canonical's security risk practices
- Evaluate, select and implement new security requirements, tools and practices
- Grow the presence and thought leadership of Canonical security risk management practice
- Develop Canonical security risk learning and development materials
- Work with Security leadership to present information and influence change
- Participate in developing key risk indicators, provide inputs to the development of key control indicators, and key performance indicators for various programs
- Apply statistical models to risk frameworks (such as FAIR, sensitivity analysis, and others)
- Participate in risk management, decision-making, and collaborative discussions
- Lead quantified risk assessments and understand the value of qualitative data for improvements to quality and engineering processes
- Interpret internal or external cyber security risk analyses in business terms and recommend a responsible course of action
- Develop templates and materials to help with self-service risk management actions
- Monitor and identify opportunities to improve the effectiveness of risk management processes
- Launch campaigns to perform security assessments and help mitigate security risks across the company
- Build evaluation methods and performance indicators to measure efficiency of security functions and capabilities.
- An exceptional academic track record
- Undergraduate degree in Computer Science or STEM, or a compelling narrative about your alternative path
- Drive and a track record of going above-and-beyond expectations
- Deep personal motivation to be at the forefront of technology security
- Leadership and management ability
- Excellent business English writing and presentation skills
- Problem-solver with excellent communication skills, a deep technical understanding of security assessments and risk management
- Expertise in threat modelling and risk management frameworks
- Broad knowledge of how to operationalize the management of security risk
- Experience in Secure Development Lifecycle and Security by Design methodology
We consider geographical location, experience, and performance in shaping compensation worldwide. We revisit compensation annually (and more often for graduates and associates) to ensure we recognise outstanding performance. In addition to base pay, we offer a performance-driven annual bonus. We provide all team members with additional benefits, which reflect our values and ideals. We balance our programs to meet local needs and ensure fairness globally.
- Distributed work environment with twice-yearly team sprints in person
- Personal learning and development budget of USD 2,000 per year
- Annual compensation review
- Recognition rewards
- Annual holiday leave
- Maternity and paternity leave
- Employee Assistance Programme
- Opportunity to travel to new locations to meet colleagues
- Priority Pass, and travel upgrades for long haul company events
Canonical is a pioneering tech firm at the forefront of the global move to open source. As the company that publishes Ubuntu, one of the most important open source projects and the platform for AI, IoT and the cloud, we are changing the world on a daily basis. We recruit on a global basis and set a very high standard for people joining the company. We expect excellence - in order to succeed, we need to be the best at what we do. Canonical has been a remote-first company since its inception in 2004. Working here is a step into the future, and will challenge you to think differently, work smarter, learn new skills, and raise your game.
Canonical is an equal opportunity employer
We are proud to foster a workplace free from discrimination. Diversity of experience, perspectives, and background create a better work environment and better products. Whatever your identity, we will give your application fair consideration.
Seniority level
- Seniority level Entry level
- Employment type Full-time
- Job function Finance and Sales
- Industries Software Development
Referrals increase your chances of interviewing at Canonical by 2x
Business Analyst - Insurance (WFH/Multiple Headcounts) Global Security GRC Analyst (Governance, Risk, and Compliance) Senior Product Manager (Security and Risk Control)We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrBe The First To Know
About the latest Security leadership Jobs in Hong Kong !
Security Risk Management Specialist
Posted 10 days ago
Job Viewed
Job Description
Join to apply for the Security Risk Management Specialist role at Canonical
Join to apply for the Security Risk Management Specialist role at Canonical
In security risk management we're looking to harness the power of industry best practice combined with driving new innovation on how we do security risk assessments and modelling. Our security risk management team is the primary owner of the strategy and practices of how we identify, track and reduce our security risk across everything we do.
To support this we need to use industry best practices paired with emerging threat information to to promote risk identification, quantification, impact analysis, and modelling to ultimately drive decision making. In this role, you will help establish and execute a broad strategic vision for the security risk program at Canonical. You will not only work within the team but also cross-functionally with various teams across the organisation. The team contributes ideas and requirements for Canonical product security, improving the resilience and robustness of all Ubuntu customers and users subject to cyber attacks. Additionally, the team collaborates with our Organisational Learning and Development team to develop playbooks and facilitate security training across Canonical.
The security risk management team's mission is not only to secure Canonical, but also to contribute to the security of the wider open source ecosystem. They might share knowledge through public presentations and industry events, and share threat intelligence with the wider community or represent Canonical in sector-specific governance bodies.
What you will do in this role:
- Define Canonical's security risk management standards and playbooks
- Analyse and improve Canonical's security risk practices
- Evaluate, select and implement new security requirements, tools and practices
- Grow the presence and thought leadership of Canonical security risk management practice
- Develop Canonical security risk learning and development materials
- Work with Security leadership to present information and influence change
- Participate in developing key risk indicators, provide inputs to the development of key control indicators, and key performance indicators for various programs
- Apply statistical models to risk frameworks (such as FAIR, sensitivity analysis, and others)
- Participate in risk management, decision-making, and collaborative discussions
- Lead quantified risk assessments and understand the value of qualitative data for improvements to quality and engineering processes
- Interpret internal or external cyber security risk analyses in business terms and recommend a responsible course of action
- Develop templates and materials to help with self-service risk management actions
- Monitor and identify opportunities to improve the effectiveness of risk management processes
- Launch campaigns to perform security assessments and help mitigate security risks across the company
- Build evaluation methods and performance indicators to measure efficiency of security functions and capabilities.
- An exceptional academic track record
- Undergraduate degree in Computer Science or STEM, or a compelling narrative about your alternative path
- Drive and a track record of going above-and-beyond expectations
- Deep personal motivation to be at the forefront of technology security
- Leadership and management ability
- Excellent business English writing and presentation skills
- Problem-solver with excellent communication skills, a deep technical understanding of security assessments and risk management
- Expertise in threat modelling and risk management frameworks
- Broad knowledge of how to operationalize the management of security risk
- Experience in Secure Development Lifecycle and Security by Design methodology
We consider geographical location, experience, and performance in shaping compensation worldwide. We revisit compensation annually (and more often for graduates and associates) to ensure we recognise outstanding performance. In addition to base pay, we offer a performance-driven annual bonus. We provide all team members with additional benefits, which reflect our values and ideals. We balance our programs to meet local needs and ensure fairness globally.
- Distributed work environment with twice-yearly team sprints in person
- Personal learning and development budget of USD 2,000 per year
- Annual compensation review
- Recognition rewards
- Annual holiday leave
- Maternity and paternity leave
- Employee Assistance Programme
- Opportunity to travel to new locations to meet colleagues
- Priority Pass, and travel upgrades for long haul company events
Canonical is a pioneering tech firm at the forefront of the global move to open source. As the company that publishes Ubuntu, one of the most important open source projects and the platform for AI, IoT and the cloud, we are changing the world on a daily basis. We recruit on a global basis and set a very high standard for people joining the company. We expect excellence - in order to succeed, we need to be the best at what we do. Canonical has been a remote-first company since its inception in 2004. Working here is a step into the future, and will challenge you to think differently, work smarter, learn new skills, and raise your game.
Canonical is an equal opportunity employer
We are proud to foster a workplace free from discrimination. Diversity of experience, perspectives, and background create a better work environment and better products. Whatever your identity, we will give your application fair consideration.
Seniority level
- Seniority level Entry level
- Employment type Full-time
- Job function Finance and Sales
- Industries Software Development
Referrals increase your chances of interviewing at Canonical by 2x
Business Analyst - Insurance (WFH/Multiple Headcounts) Global Security GRC Analyst (Governance, Risk, and Compliance) Senior Product Manager (Security and Risk Control)We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrInformation Security Officer
Posted 8 days ago
Job Viewed
Job Description
4 days ago Be among the first 25 applicants
Talent Acquisition Lead @ PCCW Media / HKTWe are seeking a diligent and proactive Information Security Officer to oversee and maintain the operational integrity, security, and compliance of our secured room facilities. This role is critical in supporting ongoing monitoring, access control, and administrative processes to ensure the highest standards of safety and regulatory compliance are met.
Your Role
- Conduct monthly inspection of access logs and CCTV reviews to ensure adherence to security protocols.
- Manage user access applications on a bi-weekly or ad hoc basis, in line with corporate access governance procedures.
- Complete and maintain a monthly secured room checklist, covering physical and operational controls.
- Perform monthly access inventory assessments, including user recertification activities. • Address administrative and technical issues such as network or hardware incidents on an ad hoc basis.
- Coordinate monitoring and inspection of the Foshan secured room (monthly and as needed).
- Perform daily monitoring of security guard performance and escalate concerns when appropriate.
- Assist in implementing security control enhancements such as mobile device management (MDM), two-factor authentication (2FA), and ID verification improvements
To Succeed in this Role
- Bachelor’s degree in Information Security, Computer Science, Information Technology, or a related field.
- Minimum of 3 years of experience in information security, risk management, or a related role.
- Knowledge of network security principles and incident response procedures.
- Excellent analytical skills with the ability to assess security risks and implement effective mitigation strategies.
- Strong problem-solving abilities to address technical and administrative issues as they arise.
- Effective verbal and written communication skills to convey security policies and procedures clearly to stakeholders.
- Seniority level Mid-Senior level
- Employment type Contract
- Job function Information Technology
- Industries Software Development, Information Services, and Technology, Information and Media
Referrals increase your chances of interviewing at PCCW by 2x
Sign in to set job alerts for “Information Security Officer” roles.We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrInformation Security Manager
Posted 10 days ago
Job Viewed
Job Description
Join to apply for the Information Security Manager role at Michael Page .
1 day ago Be among the first 25 applicants.
About Our ClientOur client is a well-established organization within the financial services sector. With a large workforce and a solid market presence in Hong Kong, they are committed to maintaining high standards in technology and information security.
Job DescriptionAs a 'Manager, Information Security,' your main responsibilities will include:
- Overseeing the implementation and maintenance of the bank's information security systems.
- Conducting regular audits and risk assessments to ensure adherence to security protocols.
- Developing and implementing information security policies and procedures.
- Training and mentoring staff on information security best practices.
- Conducting cybersecurity assessments, including penetration testing and infrastructure/web application reviews.
- Managing and maintaining security systems such as firewalls, NAC, IPS, and SIEM.
- Leading and coordinating information security projects across departments.
- Managing incident responses and investigations into security breaches.
- Staying updated on the latest trends and developments in information security.
- Reporting on the status of information security to senior management.
A Successful 'Manager, Information Security' Should Have
- A degree in Computer Science, Information Security, or a related field.
- Proven experience in a managerial role within the field of information security.
- Familiarity with information security regulations and standards in the financial services industry.
- Exceptional leadership and communication skills.
- The ability to handle sensitive information with discretion and integrity.
- A competitive salary in the range of HKD 648,000 - HKD 792,000 per annum.
- Standard benefits package.
- The chance to work in a fast-paced, technology-driven environment within the financial services industry.
- Opportunities for career progression and professional development.
- A supportive and collaborative company culture.
We encourage all candidates who believe they can fulfill these responsibilities and possess the necessary qualifications and skills to apply. This is a fantastic opportunity to join a leading financial organization in Hong Kong and make a significant impact in the field of Information Security.
Contact: Alexis Wee
Quote job ref: JN-052025-6742617
Seniority level- Mid-Senior level
- Full-time
- Information Technology and Engineering
- Financial Services, Accounting, and Banking