Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
Hong Kong Exchanges and Clearing Limited (HKEX) is seeking an experienced security governance professional to lead enterprise security configuration standards, CIS Benchmark adoption, and exceptions management within a regulated financial services environment. The role also covers encryption/key management and internal CA governance, requiring strong analytical and stakeholder skills.
The ideal candidate will have 10+ years of information security governance experience, familiarity with CIS
We’re home to Asia’s most dynamic and vibrant capital markets.
Connecting capital, ideas, inspiration and innovation for deeper, more diverse and liquid global capital markets; providing greater choice and opportunity for our customers, each and every day.
HKEX is a purpose-driven company. Our commitment to the long-term development of our business and our markets is articulated in our purpose: “ToConnect,PromoteandProgressour Markets and the Communities they support for the prosperity of all.”
Manage and maintain enterprise security configuration standards and baselines.
Review and adopt the latest Center for Internet Security (CIS) Benchmarks, ensuring alignment with HKEX security requirements.
Oversee updates to security configuration scanning tools to incorporate the latest CIS Benchmarks and security checks.
Develop, review, and maintain Generic Security Baselines (GSBs) for technologies and platforms not covered by CIS Benchmarks.
Ensure security configuration standards remain current, effective, and aligned with industry best practices and regulatory requirements.
Administer the security exception management process for security findings.
Review and validate exception requests to confirm that appropriate business justification, risk assessment, compensating controls, and management approvals are in place.
Assess and validate potential false-positive findings identified through security configuration scans.
Maintain accurate records of approved exceptions and monitor their validity periods and expiry dates.
Conduct Security Acceptance Checklist (SAC) reviews and approvals as part of the SDLC process control.
Assess and approve SSR requests stating security requirements are not applicable, ensuring adequate justification and risk assessment are documented.
Minimum 10 years of relevant experience in in information security governance, information security, technology risk management, compliance, or IT audit functions, preferably within financial services or a regulated environment.
Good understanding of information security governance, risk, and control concepts.
Strong understanding of CIS Benchmarks, control principles, and security governance processes.
Excellent analytical, communication, and stakeholder management skills.
Ability to analyse processes and identify gaps or improvement opportunities.
Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Information Technology, or related discipline.
Relevant professional certifications such as CISSP, CISM, ISO 27001 Lead Implementer/Auditor, CCSP or equivalent are preferred.
HKEX is committed as an Equal Opportunity Employer. Diversity is one of our core values and we look to support, respect diverse perspectives, abilities, culture and experiences within our workplace.
HKEX - TKO
Standard - 40 Hours (Hong Kong SAR)
40
Permanent