Information Security Manager

PCCW Solutions

Hong Kong

On-site

HKD 850,000 - 1,350,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

PCCW Solutions is seeking an experienced Information Security Manager to oversee security policies, audit activities, and regulatory compliance in Hong Kong. The role requires strong governance capabilities and collaboration with technical teams to drive security initiatives.

The candidate should have approximately 10 years in information security management, with expertise in ISO 27001/22301, NIST, and COBIT, and a deep understanding of Hong Kong regulatory requirements.

Qualifications

  • Minimum ~10 years of information security management experience.
  • Strong knowledge of ISO 27001/22301, NIST, COBIT frameworks.
  • Solid understanding of Hong Kong information security regulations and reporting requirements.

Responsibilities

  • Maintain and review IT Security Policies and related documentation.
  • Lead and manage IT security audits and security testing projects through the entire lifecycle.
  • Perform gap analyses against internal policies and regulatory requirements, and manage follow-up actions.
  • Act as the primary point of contact for inquiries related to Information Security Policies, audit activities, and control gap assessments.
  • Assist in technology disaster recovery planning (DRP) and preparation of DR drills.
  • Provide ad hoc support for security-related projects as needed.
  • Drive continuous improvements in overall information security posture from a governance and compliance perspective.

Skills

IT security governance
Audit management
Regulatory compliance
Stakeholder communication

Job description

Position Summary:

We are seeking an experienced professional in Information Security Management. The ideal candidate should have a strong understanding of IT Security policies, industry control frameworks, and local regulatory requirements, as well as the ability to manage audit lifecycle and participate in disaster recovery (DR) planning. This role will be responsible for managing security policies and standards, conducting control gap analyses and assessments, overseeing IT Security audit and testing activities, and presenting assessment results to management. The candidate must be detail-oriented, possess strong technical comprehension, communicate effectively with technical teams, and be proficient in professional technical writing.

Your Role:
  • Maintain and review IT Security Policies and related documentation.
  • Lead and manage IT security audits and security testing projects in entire lifecycle
  • Perform gap analyses against internal policies and regulatory requirements, and manage the necessary follow-up actions.
  • Act as the primary point of contact for inquiries related to Information Security Policies, audit activities, and control gap assessments.
  • Assist in technology disaster recovery planning (DRP) and preparation of DR drills.
  • Provide ad hoc support for security-related projects as needed.
  • Drive continuous improvements in overall information security posture from a governance and compliance perspective.
To Succeed in this Role:
  • Approximately 10 years of experience in information security management, cybersecurity, or related fields.
  • Strong understanding of IT policies, control, and risk frameworks (e.g., ISO 27001/22301, NIST, COBIT).
  • Solid understanding of Hong Kong’s information security regulatory requirements.
  • Proven experience collaborating across technical teams and engaging with stakeholders across different levels.
  • Excellent written and reading skills in English.
  • Strong analytical capabilities with attention to detail and the ability to consolidate information effectively.
  • Relevant certifications (e.g., CISM, CISA, CISSP, ISO 27001 Lead Auditor) are highly desirable.
Preferred Attributes:
  • Strategic mindset with a hands-on approach to problem-solving and the ability to work independently.
  • Experience in regulated industries (e.g., finance, healthcare) is a plus.
  • Knowledge of emerging technologies (e.g., Generative AI) is an advantage.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Manager - IC
IT Security Manager - IC

Classy Wheeler Limited • Hong Kong

On-site
HKD 600,000 - 900,000
IT Security Manager (banking) (Finance/up to 70K)
IT Security Manager (banking) (Finance/up to 70K)

Manpower Services (Hong Kong) Limited • Hong Kong Island

On-site
HKD 469,000 - 781,000
IT Security Manager (Finance/up to 70K)
IT Security Manager (Finance/up to 70K)

Manpower Services (Hong Kong) Limited • Hong Kong Island

On-site
HKD 900,000 - 1,400,000
Director, Deputy Head of Information Security, IT
Director, Deputy Head of Information Security, IT

Be Myjob Company Limited • Hong Kong

On-site
HKD 900,000 - 1,500,000
Insurance - Manager, Technology Risk & Security
Insurance - Manager, Technology Risk & Security

Cornerstone Global Partners • Hong Kong

On-site
HKD 900,000 - 1,500,000
Technology Risk Manager (Information Security Control Division)
Technology Risk Manager (Information Security Control Division)

Bank of China (Hong Kong) • Hong Kong

On-site
HKD 700,000 - 1,000,000
Information Security Consultant
Information Security Consultant

Zurich 56 Company Ltd • Hong Kong

On-site
HKD 600,000 - 800,000
IT Security Manager / Associate Director
IT Security Manager / Associate Director

Recruit Squad Limited • Hong Kong Island

On-site
HKD 900,000 - 1,600,000
Information Security & Governance Specialist - Financial Services Group
Information Security & Governance Specialist - Financial Services Group

Cornerstone Global Partners • Hong Kong Island

On-site
HKD 480,000 - 720,000
Information Security Leader: Policy, Compliance & Risk
Information Security Leader: Policy, Compliance & Risk

PCCW Solutions • Hong Kong

On-site
HKD 850,000 - 1,350,000