Security Compliance (GRC) Manager/Specialist

OSL

Hong Kong

On-site

HKD 180,000 - 300,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

OSL in Hong Kong is seeking an experienced Security & Compliance Specialist/Manager to bridge technical cyber security and regulatory requirements. You will oversee HKMA/SFC mandates, manage certification programs, and coordinate external audits.

The role covers policy development, third-party risk, incident response support, and ensuring ITGC controls across cloud and on-prem environments. Strong English/Chinese communication and 4+ years in financial services security are essential.

Qualifications

  • 4+ years of Information Security Compliance, IT Audit, or Cyber Risk in Financial Services, FinTech, VASP, or Big 4 consulting.
  • Solid knowledge of Hong Kong regulatory requirements (HKMA/SFC).
  • Experience coordinating external audits and managing security certifications.

Responsibilities

  • Interpret regulatory requirements and map them to internal controls and procedures.
  • Lead and maintain certifications (ISO 27001, SOC 1/2 Type II, PCI-DSS) and coordinate audits.
  • Develop security policies, standards, and SOPs aligned with best practices.
  • Oversee third-party risk assessments and security awareness programs.

Skills

Regulatory compliance
Information security
Audit management
Vendor risk management
Regulatory reporting
Regulatory interpretation
Communication with leadership

Education

Bachelor’s degree in a relevant field

Tools

ISO 27001
SOC 2 Type II
PCI-DSS
NIST CSF

Job description

We are seeking an experienced Security & Compliance Specialist / Manager to join our Information Security team in Hong Kong. In this role, you will bridge the gap between technical cyber security and regulatory compliance. You will be responsible for upholding our security compliance frameworks, ensuring alignment with HKMA/SFC regulatory mandates, managing ISO 27001 / SOC 2 certifications, and facilitating external audits.

Key Responsibilities:
1. Regulatory Compliance & Alignment (HKMA / SFC)
  • Interpret and map information security requirements from regulatory bodies (such as HKMA e-Banking / SPM guidelines, SFC regulatory requirements for VASP/Exchange platforms, and international standards).
  • Assess internal infrastructure, application security, and operational controls against regulatory mandates to identify gaps and enforce remediation.
  • Prepare compliance documentation, regulatory reporting, and risk assessment disclosures required by HKMA, SFC, or other overseas regulators.
2. Security Frameworks & Audit Management
  • Lead and maintain corporate security certifications, including ISO 27001, SOC 1 / SOC 2 Type II, and PCI-DSS.
  • Coordinate third-party security audits, penetration testing remediation, and regulatory inspections. Serve as the primary point of contact for external auditors and regulatory examiners.
  • Drive internal security controls testing and periodic IT General Controls (ITGC) reviews across cloud and on-premise environments.
3. Third-Party Risk Management (TPRM) & InfoSec Governance
  • Establish and execute vendor security risk assessment processes, evaluating technical and operational risks of third-party service providers.
  • Draft, review, and update information security policies, standards, and SOPs to ensure alignment with industry best practices.
  • Deliver tailored security awareness training to internal teams, ensuring high compliance and security awareness across the organization.
4. Incident Response & Business Continuity
  • Support the incident response team from a regulatory notification and compliance standpoint during security incidents.
  • Collaborate with IT and Operations to maintain Business Continuity Plans (BCP) and Disaster Recovery (DR) testing compliance.
Requirements:
Experience:
  • 4+ years of experience in Information Security Compliance, IT Audit, or Cyber Risk within Financial Services, FinTech, Virtual Asset Service Providers (VASP), or Tier-1 Consulting (Big 4).
Technical & Regulatory Knowledge:
  • Strong knowledge of Hong Kong financial regulations (SFC VASP guidelines, HKMA SPM/OR-1/TM-E-1).
  • Hands-on experience managing ISO 27001, SOC 2 Type II, or NIST CSF frameworks.
  • Solid understanding of cloud security (AWS/GCP), API security, and modern DevSecOps practices.
Certifications (Preferred):
  • CISSP, CISA, CRISC, CISM, or ISO 27001 Lead Auditor certifications are highly preferred.
Skills & Mindset:
  • Exceptional communication skills with the ability to articulate technical risk to executive leadership and regulators.
  • Excellent command of spoken and written English and Chinese (Cantonese and/or Mandarin).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Analyst
GRC Analyst

IO Tech Solutions Limited • Hong Kong

On-site
HKD 420,000 - 640,000
Security & Compliance Leader (Regulatory) — HK
Security & Compliance Leader (Regulatory) — HK

OSL • Hong Kong

On-site
HKD 180,000 - 300,000
IT Security Manager (Finance/up to 70K)
IT Security Manager (Finance/up to 70K)

Manpower Services (Hong Kong) Limited • Hong Kong Island

On-site
HKD 900,000 - 1,400,000
IT Security Manager (banking) (Finance/up to 70K)
IT Security Manager (banking) (Finance/up to 70K)

Manpower Services (Hong Kong) Limited • Hong Kong Island

On-site
HKD 469,000 - 781,000
Technology Risk Manager (Information Security Control Division)
Technology Risk Manager (Information Security Control Division)

Bank of China (Hong Kong) • Hong Kong

On-site
HKD 700,000 - 1,000,000
Assistant Vice President, Cybersecurity
Assistant Vice President, Cybersecurity

Randstad Hong Kong Limited • Hong Kong

On-site
HKD 1,100,000 - 1,800,000
Assistant Manager - Cyber Security Ops - Tech Risk & Security Assessment
Assistant Manager - Cyber Security Ops - Tech Risk & Security Assessment

New Galaxy Entertainment 2006 Company Limited • Hong Kong

On-site
HKD 420,000 - 700,000
Manager / Assistant Manager, Compliance & Risk
Manager / Assistant Manager, Compliance & Risk

KOS International Limited • Hong Kong

On-site
HKD 900,000 - 1,200,000
Compliance & Information Security Specialist | World-class AI product
Compliance & Information Security Specialist | World-class AI product

Osmium Consulting Group Limited • Hong Kong

On-site
HKD 420,000 - 540,000
IT Security Manager - IC
IT Security Manager - IC

Classy Wheeler Limited • Hong Kong

On-site
HKD 600,000 - 900,000