A fast-growing IT solutions provider is seeking an experienced IT Security Manager in Hong Kong. The role involves developing IT security policies, performing vulnerability assessments, and ensuring compliance with industry standards. Candidates should hold a degree in a related field and possess at least 8 years of relevant experience in information security. Preferred certifications include CISSP or CISA. A good command of Cantonese and English is required, and business travel will be necessary.
Qualifications
At least 8 years of relevant experience in Information Security, Risk Management.
Solid experience with key security technologies.
Mature and adaptive with strong analytical skills.
Responsibilities
Develop IT Security and technology risk policies and procedures.
Conduct regular security assessments and compliance reviews.
Perform vulnerability scanning and penetration tests with analysis.
Skills
IT Security management
Risk management
Vulnerability assessment
Penetration testing
Interpersonal skills
Analytical skills
Communication skills
Education
Degree in Computer Science, Information Technology or related disciplines
Tools
CISSP
CISA
SANS GCIH
SANS GPEN
SANS GWAPT
OSCP
OSCE
Job description
Fast-growing software house and IT solutions provider in Hong Kong
Job Description
Responsible for the development of the company IT Security and technology risk related policies, guidelines and standards operating procedures
Participate in internal regular security assessment and compliance review activities
Perform vulnerability scanning and penetration test, analyses the results and propose solutions
Ensure internal IT departments and key business units are compliant with the company IT Security Policies and standard
Provide technology risk management support, security incident responses and security threat intelligence analysis
Maintain a regular governance for managing the information security risks performance
Support the on-going maintenance and update of the company IT Security Policies and Standard according to the industry best practices (i.e. ISO 27001 and SANS)
Preferably with technical background in networking/coding/security control and practice in Financial Industry
Conduct necessary IT Security and Risk control monitoring, testing to determine the control effectiveness
Direct report to Managing Director
Job Requirements
Degree holder in Computer Science, Information Technology or related disciplines
At least 8 years’ relevant experience in Information Security, Risk Management area
Solid experience and knowledgeable of key security technologies
Certification holders of CISSP / CISA is preferred
Information Security Certification holders of SANS GCIH/ SANS GPEN/ SANS GWAPT/ OSCP/ OSCE is preferred
Mature, adaptive with good analytical skills
Strong interpersonal and communication skills
Good command of both spoken and written Cantonese, Chinese and English