Cybersecurity and Information Security Analyst

Not Another Headhunting Company

Hong Kong

On-site

HKD 420,000 - 780,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Not Another Headhunting Company seeks an experienced Compliance and Information Security Analyst to safeguard its digital infrastructure across multi-region operations. The role leads vulnerability management, incident response, and audit readiness while driving data governance and GDPR compliance in a fast-paced technology environment.

Strong collaboration with engineering and security teams is essential to elevate enterprise controls.

Qualifications

  • 2+ years in information security, IT compliance, or risk management in tech/cloud environments.
  • Hands-on with ISO 27001, SOC reporting, and ISO 42001 knowledge.
  • Strong understanding of SDLC, IT infra, networks, vulnerability management.
  • Knowledge of GDPR and data governance frameworks.
  • Certifications such as CISSP, CCEP, ISO Lead Implementer/Auditor preferred.
  • Excellent analytical and communication skills to translate risks to stakeholders.

Responsibilities

  • Oversee vulnerability management and remediation across applications and infrastructure.
  • Lead incident response lifecycle and executive reporting.
  • Direct internal and external audits and maintain ISO/SOC certifications.
  • Develop data governance and privacy frameworks (GDPR) across regions.
  • Conduct threat hunting using updated intel to strengthen controls.
  • Collaborate with engineering and operations to enforce security standards and train staff.

Skills

InfoSec
Compliance
GDPR
Threat Hunting
Audits

Job description

Overview

Our client is an expanding global technology company, seeking an experienced Compliance and Information Security Analyst to safeguard its digital infrastructure and maintain top-tier international standards. You will oversee corporate compliance, audit readiness, data privacy frameworks, and threat mitigation across multi-region operating markets. This position is ideal for a detail-oriented security professional looking to drive enterprise compliance, AI data governance, and proactive risk management in a fast-paced environment.

What You Will Do
  • Own end-to-end vulnerability management—scheduling automated scans, prioritizing SAST/DAST findings, and driving technical remediation across application and infrastructure layers
  • Lead the complete incident response lifecycle, managing security event monitoring, containment, forensic mitigation, and root-cause reporting for executive leadership
  • Direct internal and external IT audits, maintaining certification programs across ISO 27001, ISO 42001 standards and SOC compliance
  • Develop, implement, and maintain data governance and privacy frameworks (e.g., GDPR) across existing and expanding global operating regions
  • Conduct continuous threat hunting using updated threat intelligence to proactively strengthen controls and prevent security violations
  • Partner with engineering and operational squads to enforce security standards, evaluate risks in new initiatives, and conduct staff cybersecurity training
What You Will Need
  • 2+ years of hands-on experience in information security, IT compliance, or risk management within modern technology or cloud environments
  • Practical expertise with core compliance frameworks and standards, specifically ISO 27001, SOC reporting, and ISO 42001 (Artificial Intelligence Management Systems)
  • Solid technical understanding of software development lifecycles, IT infrastructure, network architectures, vulnerability scanning, and structured incident response
  • Deep knowledge of global data privacy regulations (e.g., GDPR) and data governance frameworks
  • Industry security or compliance certifications (e.g., CISSP, CCEP, ISO Lead Implementer/Auditor, or equivalent professional credentials) are strongly preferred
  • Excellent analytical, problem-solving, and communication skills to effectively translate technical risks to cross-functional stakeholders

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Analyst, Digital Trust and Resilience
Senior Analyst, Digital Trust and Resilience

Crypto.com • Hong Kong

On-site
HKD 600,000 - 900,000
InfoSec & Compliance Analyst: ISO 27001, GDPR, IR
InfoSec & Compliance Analyst: ISO 27001, GDPR, IR

Not Another Headhunting Company • Hong Kong

On-site
HKD 420,000 - 780,000
Information Technology Security Engineer
Information Technology Security Engineer

Midland Holdings Limited • Hong Kong

On-site
HKD 480,000 - 720,000
Information Security Manager
Information Security Manager

NTT Com Asia • Hong Kong

On-site
HKD 900,000 - 1,500,000
Senior Analyst, Digital Trust and Resilience
Senior Analyst, Digital Trust and Resilience

crypto • Hong Kong

On-site
HKD 900,000 - 1,200,000
Analyst – Technology Risk Management (Ref: 260000SP)
Analyst – Technology Risk Management (Ref: 260000SP)

MTR Corporation Limited 香港鐵路有限公司 • Hong Kong

On-site
HKD 480,000 - 720,000
Compliance & Information Security Specialist | World-class AI product
Compliance & Information Security Specialist | World-class AI product

Osmium Consulting Group Limited • Hong Kong

On-site
HKD 420,000 - 540,000
Security IT Support Engineer
Security IT Support Engineer

Crypto.com • Hong Kong

Hybrid
HKD 240,000 - 320,000
Competitive salary
Medical insurance for dependents
Generous annual leave
+3
Assistant Manager - Cyber Security Ops - Tech Risk & Security Assessment
Assistant Manager - Cyber Security Ops - Tech Risk & Security Assessment

New Galaxy Entertainment 2006 Company Limited • Hong Kong

On-site
HKD 420,000 - 700,000
IT Security Operations Manager - IC
IT Security Operations Manager - IC

Classy Wheeler Limited • Hong Kong

On-site
HKD 700,000 - 900,000