IT Security Assurance Lead (Audit Coordination) (24-month Contract)

Cathay Pacific Airways Limited

Hong Kong

On-site

HKD 900,000 - 1,100,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Cathay Pacific is seeking an IT Security Assurance Lead to drive security testing and assurance across initiatives. You will oversee risk-based assessments, elevate testing quality, and guide mitigation strategies for projects, vendors, and platforms.

You will mentor security teams, enhance assurance frameworks, and promote secure development practices to strengthen Cathay Pacific's resilient technology landscape.

Qualifications

  • 5-7 years in IT Security Assurance, security testing or risk assessment.
  • Experience leading small teams and mentoring teammates.
  • Certification such as OSCP, GWAPT, OSEP, OSWE, OSCE or CEH preferred.
  • Expert knowledge of cyber threats, testing methods, standards and tools.
  • Strong vendor management for external testing providers.
  • Hands-on use of vulnerability assessment, penetration testing and OWASP.

Responsibilities

  • Lead IT security risk assessments and assurance activities, track risks and mitigations.
  • Advise stakeholders on residual risks, vulnerabilities, and non-compliance.
  • Evaluate risks from exceptions and recommend mitigations.
  • Develop and improve security assessment frameworks and testing standards.
  • Oversee security testing delivery across projects and BAU activities.
  • Manage external testing vendors and testing tools quality.

Skills

IT Security Assurance
Security Testing
Risk Assessment
Vendor Management
Penetration Testing
Ethical Hacking
Threat Awareness
Leadership

Education

Certifications in security (OSCP/GWAPT/CEH)

Tools

NIST
OWASP
OSSTMM
OSINT

Job description

IT Security Assurance Lead (Audit Coordination) (24-month Contract)

Cathay Pacific

Digital & Information Technology

Contract

Hong Kong SAR (China)

Role Introduction

Drive the security assurance and testing practices that help protect Cathay's technology landscape. You will lead IT security assessments, oversee security testing activities, and ensure projects, applications, vendors, and technology initiatives are evaluated against security requirements, risk standards, and industry best practices. Working across assurance and testing disciplines, you will help teams understand security exposures, evaluate mitigation options, and make informed risk-based decisions.


Partnering with stakeholders across Information Technology and the wider business, you will oversee security testing quality, manage external testing vendors, guide responses to security findings, and develop frameworks covering areas such as cloud security assessments, contractual security requirements, and risk assessment methodologies. Your expertise in security standards, penetration testing practices, vulnerability assessment, ethical hacking, and threat awareness will help strengthen security outcomes across both project delivery and operational environments.


This is a role for a security professional who enjoys combining technical depth with leadership. By mentoring team members, improving assurance processes, promoting secure development practices, and influencing security decisions at multiple levels, you will help deliver a stronger and more resilient technology environment that supports Cathay's commitment to moving people forward in life.

Key Responsibilities
  • Item 1 of 10, Lead IT security risk assessments and security assurance activities, ensuring identified risks and mitigation actions are appropriately managed and tracked. Lead IT security risk assessments and security assurance activities, ensuring identified risks and mitigation actions are appropriately managed and tracked.
  • Item 2 of 10, Advise senior stakeholders on residual risks, vulnerabilities, security exposures, information asset misuse, and security non-compliance. Advise senior stakeholders on residual risks, vulnerabilities, security exposures, information asset misuse, and security non-compliance.
  • Item 3 of 10, Evaluate security risks associated with exception requests and recommend appropriate mitigation measures to business units. Evaluate security risks associated with exception requests and recommend appropriate mitigation measures to business units.
  • Item 4 of 10, Develop, maintain, and continuously improve security assessment frameworks, testing procedures, methodologies, standards, and guidelines. Develop, maintain, and continuously improve security assessment frameworks, testing procedures, methodologies, standards, and guidelines.
  • Item 5 of 10, Drive efficiency and consistency in assurance activities through the enhancement of control assessment approaches and security governance practices. Drive efficiency and consistency in assurance activities through the enhancement of control assessment approaches and security governance practices.
  • Item 6 of 10, Oversee security testing delivery across projects and business-as-usual activities, ensuring testing approaches, documentation, and outcomes are fit for purpose. Oversee security testing delivery across projects and business-as-usual activities, ensuring testing approaches, documentation, and outcomes are fit for purpose.
  • Item 7 of 10, Manage external testing vendors, assessment tools, testing quality standards, and acceptance criteria to ensure effective and reliable security testing outcomes. Manage external testing vendors, assessment tools, testing quality standards, and acceptance criteria to ensure effective and reliable security testing outcomes.
  • Item 8 of 10, Prioritize and coordinate internal and external security testing resources while coaching and managing security testing team members. Prioritize and coordinate internal and external security testing resources while coaching and managing security testing team members.
  • Item 9 of 10, Investigate and communicate security findings, provide support during security incident resolution, and ensure residual risks are documented and understood by stakeholders. Investigate and communicate security findings, provide support during security incident resolution, and ensure residual risks are documented and understood by stakeholders.
  • Item 10 of 10, Promote security awareness and capability development by delivering training, encouraging secure coding practices, and monitoring emerging cyber threats and industry best practices. Promote security awareness and capability development by delivering training, encouraging secure coding practices, and monitoring emerging cyber threats and industry best practices.
Requirements
  • Item 1 of 10, 5-7 years of relevant experience in IT Security Assurance, Security Testing, Risk Assessment, or related cybersecurity disciplines 5-7 years of relevant experience in IT Security Assurance, Security Testing, Risk Assessment, or related cybersecurity disciplines
  • Item 2 of 10, Experience leading and mentoring small teams, with the ability to manage and develop team members Experience leading and mentoring small teams, with the ability to manage and develop team members
  • Item 3 of 10, Relevant security certification such as OSCP, GWAPT, OSEP, OSWE, OSCE, or CEH is preferred for assessment-related responsibilities Relevant security certification such as OSCP, GWAPT, OSEP, OSWE, OSCE, or CEH is preferred for assessment-related responsibilities
  • Item 4 of 10, Expert knowledge of cyber threats, attack techniques, security testing methodologies, security standards, and assessment tools Expert knowledge of cyber threats, attack techniques, security testing methodologies, security standards, and assessment tools
  • Item 5 of 10, Strong vendor management experience, including oversight of external security testing and assessment providers Strong vendor management experience, including oversight of external security testing and assessment providers
  • Item 6 of 10, Hands-on knowledge of security frameworks and practices, including Vulnerability Assessment, IT Risk Assessment, Penetration Testing, Ethical Hacking, OWASP, NIST, OSSTMM, and OSINT Hands-on knowledge of security frameworks and practices, including Vulnerability Assessment, IT Risk Assessment, Penetration Testing, Ethical Hacking, OWASP, NIST, OSSTMM, and OSINT
  • Item 7 of 10, Expert understanding of security solutions and tools used across assessment, testing, and assurance activities Expert understanding of security solutions and tools used across assessment, testing, and assurance activities
  • Item 8 of 10, Strong communication and presentation skills, with the ability to articulate security risks and recommendations to both technical and non-technical stakeholders Strong communication and presentation skills, with the ability to articulate security risks and recommendations to both technical and non-technical stakeholders
  • Item 9 of 10, Excellent interpersonal, analytical, problem-solving, and decision-making skills, with strong troubleshooting capabilities Excellent interpersonal, analytical, problem-solving, and decision-making skills, with strong troubleshooting capabilities
  • Item 10 of 10, Proactive, customer-focused mindset with the ability to drive change, build stakeholder relationships, and understand user and business needs Proactive, customer-focused mindset with the ability to drive change, build stakeholder relationships, and understand user and business needs
Personal & Application Information

Cathay Pacific is an Equal Opportunities Employer. Personal data provided by job applicants will be used strictly in accordance with our Applicant Personal Information Collection Statement and for recruitment purposes only. Candidates not notified within eight weeks may consider their application unsuccessful. We keep records of your data for no longer than is necessary for the purpose for which we obtained them and any other permitted linked purposes. If your application is unsuccessful, we will keep your details on file for as long as is necessary to process your application or for the purposes of further job opportunities if you agree to such longer periods.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Head of Internal Audit
Head of Internal Audit

Cathay Pacific Airways Limited • Hong Kong

On-site
HKD 1,300,000 - 2,000,000
Platform Ops Lead
Platform Ops Lead

Cathay Pacific Airways Limited • Hong Kong

On-site
HKD 1,200,000 - 1,800,000
Security Assurance Lead: Risk, Testing & Governance
Security Assurance Lead: Risk, Testing & Governance

Cathay Pacific Airways Limited • Hong Kong

On-site
HKD 900,000 - 1,100,000
Procurement Centre of Excellence Lead - Procure-to-Pay Global Process Owner
Procurement Centre of Excellence Lead - Procure-to-Pay Global Process Owner

Cathay Pacific Airways Limited • Hong Kong

On-site
HKD 900,000 - 1,500,000
Assistant Manager - Cyber Security Ops - Tech Risk & Security Assessment
Assistant Manager - Cyber Security Ops - Tech Risk & Security Assessment

New Galaxy Entertainment 2006 Company Limited • Hong Kong

On-site
HKD 420,000 - 700,000
Business Analyst - P2P Transformation (12-month contract)
Business Analyst - P2P Transformation (12-month contract)

Cathay Pacific Airways Limited • Hong Kong

On-site
HKD 420,000 - 600,000
Solution Analyst Subsidiaries (Cathay Cargo Terminal)
Solution Analyst Subsidiaries (Cathay Cargo Terminal)

Cathay Pacific Airways Limited • Hong Kong

On-site
HKD 600,000 - 900,000
Technology Risk Manager (Information Security Control Division)
Technology Risk Manager (Information Security Control Division)

Bank of China (Hong Kong) • Hong Kong

On-site
HKD 450,000 - 650,000
Medical insurance
Life insurance
Allowances
2027 Digital & IT Graduate Trainee Programme (HK & GBA)
2027 Digital & IT Graduate Trainee Programme (HK & GBA)

Cathay Pacific Airways Limited • Hong Kong

On-site
HKD 268,000 - 402,000
VP, IT Audit (Corporate Banking/Cyber Security/Technology Risk)
VP, IT Audit (Corporate Banking/Cyber Security/Technology Risk)

Randstad Hong Kong Limited • Hong Kong

On-site
HKD 900,000 - 1,300,000