InfoSec & Compliance Analyst (1.5 LoD)

Mavence Group Limited

Hong Kong

On-site

HKD 350,000 - 550,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

One of APAC's fastest-growing B2B AI product companies seeks an Information Security & Compliance Analyst in Hong Kong. You will own audits, manage risk, and build data governance while collaborating with engineering and business teams to mitigate threats.

The role requires 3+ years in InfoSec/compliance, ISO 27001 exposure, and strong English/Chinese communication. Start-up environment experience and CISSP/CCEP are advantageous.

Qualifications

  • 3+ years in InfoSec, compliance or risk.
  • Experience responding to internal incidents and managing vendors.
  • Exposure to ISO 27001 or similar certifications.
  • Knowledge of data governance frameworks and best practices.
  • Understanding of software development and IT infrastructure.
  • Proactive and independent in a lean startup environment.
  • Strong stakeholder management with fluency in English and Chinese.
  • Certifications such as CISSP or CCEP are a plus.

Responsibilities

  • Own internal and external IT/compliance audits while maintaining certifications like ISO 27001.
  • Lead risk assessments, oversee SAST/DAST testing, and manage vulnerability scans.
  • Build data governance policies and privacy standards (e.g., GDPR).
  • Monitor security alerts across cloud infrastructure and manage incident response lifecycle.
  • Proactively look out for hidden threats using updated intelligence data.
  • Work closely with engineering and business teams to monitor and mitigate issues.

Skills

InfoSec
Compliance
Risk management
Incident response
Vendor management
Stakeholder management
Bilingual English/Chinese
Startup environment

Tools

ISO 27001
SAST/DAST
Vulnerability scanning

Job description

Our client is One of the fastest-growing B2B AI Product Companies in the APAC region. They are currently seeking an Information Security & Compliance Analyst to join their growing team.

Responsibilities:
  • Own internal and external IT/compliance audits whilst maintaining industry certifications (e.g., ISO 27001)
  • Conduct ongoing risk assessments, oversee application security testing (SAST/DAST), and manage vulnerability scanning schedules
  • Build data governance frameworks, policies, and privacy standards (e.g., GDPR)
  • Monitor security alerts across cloud infrastructure and own the incident response lifecycle
  • Proactively look out for hidden threats using updated intelligence data
  • Work closely with engineering and business teams to monitor and mitigate potential issues
Requirements:
  • 3+ years of proven experience in InfoSec, compliance or risk
  • Proven track record responding to internal incidents, whilst capable of managing vendors
  • Exposure with ISO 27001 or other industry-standard certifications
  • Sound knowledge of data governance frameworks and best practices
  • Good understanding of software development and IT infrastructure
  • Highly proactive and quality-driven, capable of working independently in a leaner start-up environment
  • Strong ability in stakeholder management, with fluent communication skills in English & Chinese
  • Related professional certifications (e.g. CISSP, CCEP) would be an added advantage

[Please note: Personal data collected will be used for recruitment purposes only. Shortlisted applicants will be contacted for a confidential discussion by members of our team/company. Applicants not notified within eight weeks may consider their application unsuccessful.]

Unlock job insights

Your application will include the following questions:

  • Which of the following statements best describes your right to work in Hong Kong?
  • What's your expected monthly basic salary?
  • Do you have experience working for a start-up?
  • Do you have Incident Management experience?
  • Have you worked in a role which requires a sound understanding of ISO Standards?
  • How many years' experience do you have as an Information Security Analyst?
  • How would you rate your Cantonese language skills?
  • Which of the following cybersecurity certifications have you completed?

Venue Operations and Event Planning Manager

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

InfoSec & Compliance Analyst (1.5 LoD)
InfoSec & Compliance Analyst (1.5 LoD)

Mavence Group • Hong Kong

On-site
HKD 480,000 - 720,000
InfoSec & Compliance Analyst — ISO 27001 & Risk
InfoSec & Compliance Analyst — ISO 27001 & Risk

Mavence Group Limited • Hong Kong

On-site
HKD 350,000 - 550,000
InfoSec & Compliance Analyst — ISO/GDPR, Bilingual EN/CN
InfoSec & Compliance Analyst — ISO/GDPR, Bilingual EN/CN

Mavence Group • Hong Kong

On-site
HKD 480,000 - 720,000
Assistant Manager - Cyber Security Ops - Tech Risk & Security Assessment
Assistant Manager - Cyber Security Ops - Tech Risk & Security Assessment

New Galaxy Entertainment 2006 Company Limited • Hong Kong

On-site
HKD 420,000 - 700,000
Compliance & Information Security Specialist | World-class AI product
Compliance & Information Security Specialist | World-class AI product

Osmium Consulting Group Limited • Hong Kong

On-site
HKD 420,000 - 540,000
IT Security Manager (Finance/up to 70K)
IT Security Manager (Finance/up to 70K)

Manpower Services (Hong Kong) Limited • Hong Kong Island

On-site
HKD 900,000 - 1,400,000
IT Security Manager - IC
IT Security Manager - IC

Classy Wheeler Limited • Hong Kong

On-site
HKD 600,000 - 900,000
(Senior) Security Specialist - Multiple Headcounts
(Senior) Security Specialist - Multiple Headcounts

Michael Page International (Hong Kong) Limited • Hong Kong Island

On-site
HKD 400,000 - 600,000
Comprehensive benefits package
Friendly work and team culture
Growth and development opportunities
GRC Analyst
GRC Analyst

IO Tech Solutions Limited • Hong Kong

On-site
HKD 420,000 - 640,000
Technology Risk Manager (Information Security Control Division)
Technology Risk Manager (Information Security Control Division)

Bank of China (Hong Kong) • Hong Kong

On-site
HKD 450,000 - 650,000
Medical insurance
Life insurance
Allowances