Manager, Cybersecurity Governance & Risk

Anglo-Eastern Ship Management

Hong Kong

On-site

HKD 900,000 - 1,300,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Anglo-Eastern Ship Management seeks a senior leader to own governance, risk and regulatory obligations across global maritime operations. Turn risk strategy into practical roadmaps, drive policy and standards, and align controls with ISO/IEC 27001, ISO 22301 and NIST CSF 2.0.

You will lead risk assessments across shore, vessel, cloud and OT, maintain the risk register, and report KRIs to senior management. Embed cybersecurity into safety management and run a third‑party programme with Legal and

Qualifications

  • Bachelor’s degree in information security, CS, engineering or risk management (or equivalent).
  • 8–12 years of experience in cybersecurity GRC, information security governance, IT audit or security assurance with leadership responsibility.
  • Hands-on experience with ISO/IEC 27001, ISO 22301 and NIST CSF audits, evidence collection and remediation.

Responsibilities

  • Translate cyber and technology risk strategy into practical roadmaps, policies and standards.
  • Lead risk assessments across shore, vessel, cloud and OT environments; maintain risk register and KPI/KRI dashboards.
  • Maintain an obligations register covering maritime cyber requirements and regulations (Hong Kong PDPO, Singapore PDPA, NIS2).
  • Embed cybersecurity into safety management systems and vessel assurance with cross‑functional teams.
  • Run a risk‑based third‑party programme with Legal and Privacy, from due diligence to monitoring and exit.
  • Coordinate internal, external, certification and client audits end to end; handle security questionnaires and tenders.
  • Lead crisis management, business continuity and disaster recovery exercises; automate control monitoring.

Skills

GRC leadership
Risk management
Executive reporting
Stakeholder management
InfoSec governance

Education

Bachelor's degree in information security

Tools

ISO/IEC 27001
ISO 22301
NIST CSF
Audit management tools

Job description

Governance, risk and regulatory obligations
  • Turn the Group's cyber and technology risk strategy into a practical roadmap, policies and standards, built on a control framework aligned to ISO/IEC 27001, ISO 22301 and NIST CSF 2.0.
  • Lead risk assessments across shore, vessel, cloud and OT environments; maintain the risk register and report clear KRI/KPI dashboards to senior management.
  • Maintain an obligations register covering maritime cyber requirements, client commitments and the regulations applying across our operating jurisdictions, such as Hong Kong PDPO, Singapore PDPA and NIS2.
  • Partner with QHSE, Fleet and Vessel IT to embed cybersecurity into the safety management system and strengthen vessel assurance.
  • Run a risk-based third-party programme with Legal and Privacy, from due diligence and contract controls through to monitoring and exit.
Certification, audits and assurance
  • Keep the organisation continuously certification-ready, rather than preparing for each audit in isolation.
  • Coordinate internal, external, certification and client audits end to end, from scope and evidence through to management reporting.
  • Handle security questionnaires, tenders and due diligence from clients and shipowners, and track corrective actions through to closure.
Technology, security-by-design and resilience
  • Work hands-on with Infrastructure & Operations on the security of the underlying estate — network segmentation and perimeter controls, Windows Server and Active Directory hardening including Group Policy baselines, endpoint configuration, patch and vulnerability management, and privileged access
  • Partner with Development and Digitalisation on security-by-design and DevSecOps across cloud, applications and data.
  • Assess AI tools and use cases for data exposure, access and model risk, and set proportionate guardrails drawing on references such as the NIST AI RMF and ISO/IEC 42001.
  • Lead crisis management, business continuity and disaster recovery exercises, and automate control monitoring where you can.
Leadership and stakeholder partnership
  • Lead and develop the GRC team, and coordinate control owners across offices and vessels.
  • Work with our shore and maritime training organizations to build cybersecurity and AI-risk content into training for seafarers and shore staff.
  • Act as a trusted partner across IT, QHSE, Fleet, Legal and the business, translating technical and regulatory risk into clear options for senior leaders, clients and auditors
  • Bachelor’s degree in information security, Computer Science, Engineering, Risk Management or a related discipline; equivalent professional experience will be considered.
  • CISM, CRISC, CISA, CISSP, ISO/IEC 27001 or ISO 22301 Lead Implementer or Lead Auditor, or an equivalent GRC qualification, is strongly preferred.
  • Approximately 8-12 years of experience in cybersecurity GRC, information security governance, technology risk, IT audit or security assurance, including leadership responsibility.
  • Hands-on experience with ISO/IEC 27001, ISO 22301, NIST CSF or a comparable framework, including audits, control assessment, evidence and remediation.
  • Strong understanding of risk registers, control design and testing, exceptions, risk acceptance, KRIs/KPIs and executive reporting.
  • Broad technical grounding across infrastructure and operations — networks, Windows and Active Directory and endpoints — as well as cloud, identity and security operations.
  • Experience supporting clients, external auditors, regulators or industry bodies in a complex, global or operationally intensive organisation.
  • Exposure to AI risk management or enterprise AI governance; maritime cybersecurity or OT experience is advantageous but not essential.
  • Strong written and spoken English. Cantonese and/or Mandarin is advantageous.
  • Pragmatic, engineering-informed builder who creates governance that works in real operations and can follow a control from policy through to implementation, evidence and outcome.
  • Structured, risk-based decision-maker who remains calm and accountable under pressure.
  • Clear communicator who can write concise policies, audit responses and executive updates without unnecessary jargon.
  • Genuinely curious and self-driven — owns their development and keeps looking for better ways to do things, including responsible use of AI.
  • Gets things done through others — a strong team player who engages people well beyond their own reporting line and builds successful professional connections with colleagues and stakeholders.
About Anglo-Eastern

Anglo-Eastern is a global leader in independent ship management services. The Group manages over 700 vessels under full technical management, supports around 500 additional ships under crew management, and has overseen more than 1,000 newbuildings and conversions through its newbuilding supervision and project management divisions.

Headquartered in Hong Kong, Anglo-Eastern operates through a network of 30 offices across Asia, Europe, and the Americas, including wholly owned maritime training facilities. Our strength lies in our people: over 39,000 seafarers and 2,350 shore-based employees who work together to support clients across ship types while building trust, driving performance, and shaping a better maritime future.

Why join Anglo-Eastern?
  • Join a globally respected company with a strong maritime heritage of over 50 years
  • Work in an environment anchored in integrity, trust, and long-term relationships
  • Access continuous learning and structured career development across a truly global network
  • Be part of a team committed to delivering excellence and shaping a better maritime future
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, Cybersecurity Governance & Risk
Manager, Cybersecurity Governance & Risk

Anglo-Eastern Ship Management Limited • Hong Kong

On-site
HKD 900,000 - 1,100,000
QHSE Officer
QHSE Officer

Anglo-Eastern Ship Management • Hong Kong

On-site
HKD 300,000 - 520,000
QHSE Officer
QHSE Officer

Anglo--eastern-Group • Hong Kong

On-site
HKD 240,000 - 420,000
Commercial Officer
Commercial Officer

Anglo-Eastern Ship Management Limited • Hong Kong

On-site
HKD 420,000 - 700,000
Manager, Digital Solutions
Manager, Digital Solutions

Anglo-Eastern • Hong Kong

On-site
HKD 900,000 - 1,300,000
Commercial Officer
Commercial Officer

Anglo--eastern-Group • Hong Kong

On-site
HKD 240,000 - 360,000
Senior Vessel Manager
Senior Vessel Manager

Anglo-Eastern • Hong Kong

On-site
HKD 900,000 - 1,200,000
Executive Secretary
Executive Secretary

Anglo-Eastern Ship Management • Hong Kong

On-site
HKD 240,000 - 360,000
Executive Secretary
Executive Secretary

Anglo-Eastern • Hong Kong

On-site
HKD 335,000 - 469,000
Manager, Digital Solutions
Manager, Digital Solutions

Leadingnation • Hong Kong

On-site
HKD 600,000 - 900,000