Senior Project Manager - AVP - Information Security - IT - 12 months contract

Hong Kong Exchanges and Clearing Limited (HKEX)

Hong Kong

On-site

HKD 900,000 - 1,800,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Hong Kong Exchanges and Clearing Limited (HKEX) is seeking an AVP, Senior Project Manager – Information Security to lead end‑to‑end security programs and project governance across the organization. You will ensure alignment with enterprise security standards, regulatory requirements, and procurement, finance, and reporting controls.

You will drive secure project execution, risk mitigation, and stakeholder alignment within complex IT environments, coordinating with security teams, vendors, and

Qualifications

  • Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, Information Systems, or Business Administration related.
  • A Master’s degree (e.g., MBA, MSc in Cybersecurity, or Information Systems) is preferred and considered an advantage.
  • 8–12+ years of IT project management experience, with strong exposure to cybersecurity / security services.
  • Proven track record delivering large‑scale, complex IT/security programs.
  • Experience in regulated environments (e.g., financial services) preferred.
  • Solid understanding of IT Security frameworks (ISO 27001, NIST, CIS, etc.).
  • Security domains (IAM, network security, endpoint security, cloud security, SIEM, vulnerability management).
  • SDLC and secure system development; enterprise security controls and governance models.
  • PM methodologies (PMF, SDLC, waterfall; agile exposure is a plus); risk, change, budget, and stakeholder management.

Responsibilities

  • Delivery of projects within scope, time, and budget
  • Compliance with security and regulatory requirements
  • Effective risk mitigation and issue resolution
  • Stakeholder satisfaction and business alignment
  • Lead full project lifecycle delivery (planning, initiation, design, build, implementation, closure) per PMF
  • Establish governance structures (PSC, PMT, PWT) and reporting cadence
  • Develop and maintain PID, project schedule, risk register, status and closure reports
  • Ensure adherence to change control, milestone reviews, and approval processes
  • Drive implementation of SMF controls across projects (SDLC)
  • Ensure security requirements across design, development, testing, deployment
  • Lead security initiatives: access control, network security, monitoring, data protection
  • Align with ISO 27001, NIST, and internal policies
  • Identify, assess, and manage project and security risks; drive mitigation
  • Coordinate security reviews, vulnerability assessments, and audits
  • Engage stakeholders and vendors; report to governance bodies
  • Manage budgets, forecasts, and resource allocation

Skills

IT project management
Security program governance
Leadership
Stakeholder communication
Risk management
Budget & resource management

Education

Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, Information Systems, or Business Administration related
Master’s degree preferred (MBA, MSc in Cybersecurity, or Information Systems)

Job description

Company Introduction

We’re home to Asia's most dynamic and vibrant capital markets. Connecting capital, ideas, inspiration and innovation for deeper, more diverse and liquid global capital markets; providing greater choice and opportunity for our customers, each and every day. HKEX is a purpose-driven company. Our commitment to the long-term development of our business and our markets is articulated in our purpose: "To Connect, Promote and Progress our Markets and the Communities they support for the prosperity of all."

Job Summary

The AVP, Senior Project Manager – Information Security is a key strategic role responsible for delivering end-to-end security initiatives and programs across the organization, ensuring alignment with enterprise security standards, regulatory requirements, and project governance frameworks. This position focuses on driving secure project execution, risk mitigation, and stakeholder alignment within complex IT and security environments. It also requires strict adherence to organizational processes and controls, including procurement, financial governance, and project reporting requirements.

Job Responsibilities
  • Delivery of projects within scope, time, and budget
  • Compliance with security and regulatory requirements
  • Effective risk mitigation and issue resolution
  • Stakeholder satisfaction and business alignment
  • Project Delivery & Governance
  • Lead full project lifecycle delivery (planning, initiation, design, build, implementation, closure) in accordance with the Project Management Framework (PMF).
  • Establish and manage project governance structures (Project Steering Committee (PSC), Project Management Team (PMT), Project Working Team (PWT)) and reporting cadence.
  • Develop and maintain key project artifacts (Project Initiation Document (PID), project schedule, risk register, status reports, closure reports).
  • Ensure adherence to change control, milestone reviews, and approval processes.
  • Security Program & Controls Implementation
  • Drive implementation of IT Security Management Framework (SMF) controls across projects, e.g., Software Development Life Cycle (SDLC).
  • Ensure security requirements are embedded across system lifecycle (design, development, testing, deployment).
  • Lead security-related initiatives including:
    • Access control and identity management
    • Infrastructure and network security
    • Security monitoring and incident readiness
    • Data protection, encryption, and compliance
  • Ensure alignment with standards such as ISO 27001, NIST, and internal policies.
  • Project Risk & Compliance Management
  • Identify, assess, and manage project and security risks through formal risk registers and assessments.
  • Drive mitigation strategies for technology, operational, and security risks.
  • Ensure compliance with internal security policies, audit requirements, and regulatory obligations.
  • Coordinate project specific security reviews, vulnerability assessments, and audits.
  • Project Stakeholder & Vendor Management
  • Engage senior stakeholders including business owners, IT leadership, and security teams.
  • Provide regular reporting on progress, risks, budget, and issues to governance bodies.
  • Manage external vendors and service providers, ensuring delivery against SLAs and contractual requirements.
  • Facilitate cross-functional collaboration across IT, security, and business teams.
  • Project Resource & Financial Management
  • Manage project budgets, forecasts, and expenditure tracking.
  • Plan and allocate project resources effectively across teams.
  • Ensure projects are delivered within scope, time, and budget constraints.
Job Qualifications

Education

  • Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, Information Systems, or Business Administration related.
  • A Master’s degree (e.g., MBA, MSc in Cybersecurity, or Information Systems) is preferred and considered an advantage.

Experience

  • 8–12+ years of IT project management experience, with strong exposure to cybersecurity / security services.
  • Proven track record delivering large‑scale, complex IT/security programs.
  • Experience in regulated environments (e.g., financial services) preferred.

Technical & Domain Knowledge

  • Solid understanding of:
    • IT Security frameworks (ISO 27001, NIST, CIS, etc.)
    • Security domains (IAM, network security, endpoint security, cloud security, SIEM, vulnerability management)
    • SDLC and secure system development
  • Familiar with enterprise security controls and governance models.

Project Management Skills

  • Strong knowledge of structured PM methodologies (PMF, SDLC, waterfall; agile exposure is a plus).
  • Expertise in:
    • Risk management
    • Change management
    • Budget & resource management
    • Stakeholder communication
Certifications (Preferred)
  • PMP / PRINCE2
  • CISSP / CISM / CISA (or equivalent security certification)
Key Competencies
  • Leadership and stakeholder influence
  • Strong analytical and problem‑solving skills
  • Excellent communication and executive reporting
  • Risk‑aware mindset with attention to detail
  • Ability to operate under pressure and manage competing priorities

HKEX is committed as an Equal Opportunity Employer. Diversity is one of our core values and we look to support, respect diverse perspectives, abilities, culture and experiences within our workplace.

Location

HKEX - TKO

Shift

Standard - 40 Hours (Hong Kong SAR)

Scheduled Weekly Hours

40

Worker Type

Permanent

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Project Manager - AVP - Information Security - IT - 12 months contract
Senior Project Manager - AVP - Information Security - IT - 12 months contract

Hong Kong Exchanges and Clearing Limited • Hong Kong

On-site
HKD 900,000 - 1,150,000
Senior Information Security Program Lead
Senior Information Security Program Lead

Hong Kong Exchanges and Clearing Limited (HKEX) • Hong Kong

On-site
HKD 900,000 - 1,800,000
AVP Information Security Program Lead
AVP Information Security Program Lead

Hong Kong Exchanges and Clearing Limited • Hong Kong

On-site
HKD 900,000 - 1,150,000
AVP - Senior Technical Project Manager - Cloud Platform Services - IT
AVP - Senior Technical Project Manager - Cloud Platform Services - IT

Hong Kong Exchanges and Clearing Limited (HKEX) • Hong Kong

On-site
HKD 600,000 - 800,000
AVP - Senior Systems Manager– Infrastructure Critical Services - IT
AVP - Senior Systems Manager– Infrastructure Critical Services - IT

Hong Kong Exchanges and Clearing Limited (HKEX) • Hong Kong

On-site
HKD 800,000 - 1,200,000
AVP - Senior Systems Manager- Infrastructure Critical Services - IT
AVP - Senior Systems Manager- Infrastructure Critical Services - IT

Hong Kong Exchanges & Clearing Ltd • Hong Kong

On-site
HKD 900,000 - 1,300,000
Systems Development Manager – AVP – Post-Trade Systems – IT – 12months Contract
Systems Development Manager – AVP – Post-Trade Systems – IT – 12months Contract

Hong Kong Exchanges and Clearing Limited (HKEX) • Hong Kong

On-site
HKD 600,000 - 800,000
Strategic Project and Network Architecture - VP - Network Infrastructure - IT
Strategic Project and Network Architecture - VP - Network Infrastructure - IT

Hong Kong Exchanges and Clearing Limited (HKEX) • Hong Kong

On-site
HKD 1,200,000 - 1,500,000
Equal Opportunity Employer
Diversity Support
Assistant Vice President, Cybersecurity
Assistant Vice President, Cybersecurity

Randstad Hong Kong Limited • Hong Kong

On-site
HKD 1,100,000 - 1,800,000
Senior Analyst, Information Security (Architecture & Change)
Senior Analyst, Information Security (Architecture & Change)

PFCC Group • Hong Kong

On-site
HKD 180,000 - 240,000