GRC Analyst

IO Tech Solutions Limited

Hong Kong

On-site

HKD 420,000 - 640,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

IO Tech Solutions Limited in Hong Kong is seeking a GRC Analyst to join our information security team. The role focuses on governance, risk and compliance, working with technology and business stakeholders to identify and manage security risks and ensure regulatory compliance.

You will support GRC activities, conduct risk and control assessments, assist with ISO 27001 controls, and prepare risk and compliance reports for management.

Qualifications

  • The role requires a degree in Information Security, Cybersecurity, IT, or related field.
  • Minimum 2 years of GRC/InfoSec/IT Risk or compliance experience; senior roles may require 8–10+ years.
  • Practical experience with ISO 27001 is highly preferred.
  • Experience conducting risk assessments, control assessments, gap analyses, or security compliance reviews.
  • Knowledge of frameworks such as NIST CSF, ISO 27001, COBIT or CIS Controls is advantageous.

Responsibilities

  • Support Information Security GRC activities across the organisation.
  • Conduct IT and Information Security risk assessments, control assessments and gap analyses.
  • Assist in implementing and maintaining ISO 27001 security controls and requirements.
  • Review security policies, standards, procedures and control frameworks.
  • Monitor risks, exceptions and remediation actions with timely follow-up.
  • Support internal and external audits including evidence collection and remediation tracking.
  • Assess regulatory and compliance requirements and support their implementation.
  • Prepare risk, compliance and security reports for management and stakeholders.
  • Collaborate with IT, cybersecurity and business teams to close control gaps.

Skills

GRC expertise
Stakeholder management
Analytical skills
Documentation
English Cantonese communication

Education

Information Security degree

Tools

ISO 27001
NIST CSF
COBIT/CIS Controls

Job description

We are currently looking for a GRC Analyst to join a leading organisation in Hong Kong. This role will focus on Information Security Governance, Risk and Compliance, working closely with technology and business stakeholders to identify and manage security risks and ensure compliance with relevant standards and regulatory requirements.

Key Responsibilities
  • Support Information Security Governance, Risk and Compliance (GRC) activities across the organisation.
  • Conduct IT and Information Security risk assessments, control assessments and gap analyses.
  • Support the implementation and maintenance of ISO 27001 security controls and requirements.
  • Assist in reviewing security policies, standards, procedures and control frameworks.
  • Monitor security risks, exceptions and remediation actions, ensuring timely follow-up.
  • Support internal and external audits, including audit preparation, evidence collection and remediation tracking.
  • Assess applicable regulatory and compliance requirements and support their implementation within the organisation.
  • Prepare risk, compliance and security reports for management and relevant stakeholders.
  • Work closely with IT, cybersecurity and business teams to identify control gaps and recommend appropriate improvements.
  • Support ongoing security governance initiatives and maintain relevant risk and compliance documentation.
Requirements
  • Degree in Information Security, Cybersecurity, IT, Computer Science or a related discipline.
  • Min.2years of relevant experience in GRC, Information Security, IT Risk, Technology Risk, IT Compliance or Security Governance.
  • Candidates with 8–10+ years of relevant Information Security / GRC / IT Risk experience are also welcome to apply for senior-level opportunities.
  • Practical experience with ISO 27001 is highly preferred.
  • Experience in risk assessment, control assessment, gap analysis or security compliance.
  • Knowledge of security frameworks such as NIST CSF, ISO 27001, COBIT or CIS Controls is an advantage.
  • Experience supporting security audits, regulatory assessments or compliance reviews.
  • Strong analytical, documentation and stakeholder management skills.
  • Good command of English and Cantonese; Mandarin is an advantage.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC & Information Security Compliance Analyst
GRC & Information Security Compliance Analyst

IO Tech Solutions Limited • Hong Kong

On-site
HKD 420,000 - 640,000
Security Compliance (GRC) Manager/Specialist
Security Compliance (GRC) Manager/Specialist

OSL • Hong Kong

On-site
HKD 180,000 - 300,000
Assistant Manager - Cyber Security Ops - Tech Risk & Security Assessment
Assistant Manager - Cyber Security Ops - Tech Risk & Security Assessment

New Galaxy Entertainment 2006 Company Limited • Hong Kong

On-site
HKD 420,000 - 700,000
IT Security Manager - IC
IT Security Manager - IC

Classy Wheeler Limited • Hong Kong

On-site
HKD 600,000 - 900,000
IT Security Manager (Finance/up to 70K)
IT Security Manager (Finance/up to 70K)

Manpower Services (Hong Kong) Limited • Hong Kong Island

On-site
HKD 900,000 - 1,400,000
Senior/Junior Information Security Consultant (Governance, Risk and Compliance)
Senior/Junior Information Security Consultant (Governance, Risk and Compliance)

wizlynx group • Hong Kong Island

On-site
USD 6,431 - 11,576
Technology Risk Manager (Information Security Control Division)
Technology Risk Manager (Information Security Control Division)

Bank of China (Hong Kong) • Hong Kong

On-site
HKD 700,000 - 1,000,000
Senior Manager (GRC Digital Transformation) - Regulatory & Financial Risk
Senior Manager (GRC Digital Transformation) - Regulatory & Financial Risk

Deloitte Touche Tohmatsu • Hong Kong

On-site
HKD 900,000 - 1,300,000
Business and Risk Analyst - ERM, TRM framework, COBIT, ISO27001, NIST
Business and Risk Analyst - ERM, TRM framework, COBIT, ISO27001, NIST

InfoTech Services (Hong Kong) Limited • Sha Tin

On-site
Assistant Vice President / Vice President, IT Risk Management
Assistant Vice President / Vice President, IT Risk Management

cncbinternational • Hong Kong

On-site
HKD 900,000 - 1,200,000