A consultancy firm in Hong Kong is seeking an IT Security Specialist / Architect to develop and implement information security policies and procedures. The ideal candidate will possess over 7 years of experience in managing information security functions and have a strong understanding of data protection and compliance. Key responsibilities include advising stakeholders on security issues and overseeing daily security operations. This is an opportunity to play a crucial role in ensuring data safety and compliance with relevant legislation.
Qualifications
7 years or above experience in managing information security for a sizable company.
Hands-on experience in developing and implementing enterprise-level information security policies.
In-depth understanding of data privacy and security principles.
Responsibilities
Develop and implement policies & procedures for information security.
Ensure compliance with relevant legislation and regulations.
Act as the Security Subject Matter Expert.
Oversee daily operations of the information security function.
Skills
Information security management
Data protection
Risk assessment
Stakeholder communication
CISSP
CISM
TOGAF
SABSA
Education
Degree in computer science, engineering, or related fields
Job description
SW8765 |25 Feb 2025 IT Security Specialist / Architect
Develop and implement policies & procedures for information security and data protection, governance model, design patterns and security standards aligned with business and IT strategies and industry standards.
Ensure security principle and compliance with relevant information security and data privacy legislation, regulations
Manage risk assessment program targeting information security, data protection and data privacy matters, and implement risk mitigation plans
Act as the Security Subject Matter Expert to advise on security and technology issues to stakeholders in different levels.
Oversee the daily operations of the information security function, including security monitoring, incident handling, and investigation in collaboration with the Security Operations Centers
Provide expert advice on information security aspects of new projects and systems, evaluating risks and recommending appropriate security controls and measures
Degree in computer science, engineering or related fields.
7 years or above experience in managing information security function for a sizable company
Hands‑on experience in developing and implementing enterprise‑level information security policies & procedures, and training
In depth understanding of data privacy, security principles, and knowledge of emerging technologies and related security patterns.
Strong interpersonal, communication, writing, and presentation skills. Experience in client‑facing role or management consultancy is highly preferred.
Holder of CISSP, CISM, TOGAF, and SABSA are preferred.