We are seeking an experienced Security & Compliance Specialist / Manager to join our Information Security team in Hong Kong. In this role, you will bridge the gap between technical cyber security and regulatory compliance. You will be responsible for upholding our security compliance frameworks, ensuring alignment with HKMA/SFC regulatory mandates, managing ISO 27001 / SOC 2 certifications, and facilitating external audits.
Key Responsibilities:
1. Regulatory Compliance & Alignment (HKMA / SFC)
- Interpret and map information security requirements from regulatory bodies (such as HKMA e-Banking / SPM guidelines, SFC regulatory requirements for VASP/Exchange platforms, and international standards).
- Assess internal infrastructure, application security, and operational controls against regulatory mandates to identify gaps and enforce remediation.
- Prepare compliance documentation, regulatory reporting, and risk assessment disclosures required by HKMA, SFC, or other overseas regulators.
2. Security Frameworks & Audit Management
- Lead and maintain corporate security certifications, including ISO 27001, SOC 1 / SOC 2 Type II, and PCI-DSS.
- Coordinate third-party security audits, penetration testing remediation, and regulatory inspections. Serve as the primary point of contact for external auditors and regulatory examiners.
- Drive internal security controls testing and periodic IT General Controls (ITGC) reviews across cloud and on-premise environments.
3. Third-Party Risk Management (TPRM) & InfoSec Governance
- Establish and execute vendor security risk assessment processes, evaluating technical and operational risks of third-party service providers.
- Draft, review, and update information security policies, standards, and SOPs to ensure alignment with industry best practices.
- Deliver tailored security awareness training to internal teams, ensuring high compliance and security awareness across the organization.
4. Incident Response & Business Continuity
- Support the incident response team from a regulatory notification and compliance standpoint during security incidents.
- Collaborate with IT and Operations to maintain Business Continuity Plans (BCP) and Disaster Recovery (DR) testing compliance.
Requirements:
Experience:
- 4+ years of experience in Information Security Compliance, IT Audit, or Cyber Risk within Financial Services, FinTech, Virtual Asset Service Providers (VASP), or Tier-1 Consulting (Big 4).
Technical & Regulatory Knowledge:
- Strong knowledge of Hong Kong financial regulations (SFC VASP guidelines, HKMA SPM/OR-1/TM-E-1).
- Hands-on experience managing ISO 27001, SOC 2 Type II, or NIST CSF frameworks.
- Solid understanding of cloud security (AWS/GCP), API security, and modern DevSecOps practices.
Certifications (Preferred):
- CISSP, CISA, CRISC, CISM, or ISO 27001 Lead Auditor certifications are highly preferred.
Skills & Mindset:
- Exceptional communication skills with the ability to articulate technical risk to executive leadership and regulators.
- Excellent command of spoken and written English and Chinese (Cantonese and/or Mandarin).