(Senior) echnology Risk Manager (Cyber Security Control Division)

Bank of China (Hong Kong)

Hong Kong

On-site

HKD 500,000 - 800,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Medical insurance
Life insurance
Various allowances

Job summary

Bank of China (Hong Kong) is seeking a Cyber Security Manager responsible for formulating and managing cyber security policies, conducting risk evaluations, and supporting incident response operations.

Candidates should have a degree in Computer Science or related fields with at least 2 years of experience in IT security. Strong communication skills in English and Mandarin are preferred. We offer a competitive remuneration package and fringe benefits.

Qualifications

  • At least 2 years of experience in IT security or technology risk management.
  • Holding recognized professional qualifications like CISA or CISSP.
  • Good command of written and spoken English and Mandarin is preferable.

Responsibilities

  • Formulate and manage cyber security policies and standards.
  • Conduct cyber security assessments and IT risk evaluations.
  • Support business units in identifying cybersecurity risks.

Skills

Cyber security policies management
IT risk management
Penetration testing
Incident response
Threat hunting

Education

Degree in Computer Science or Information Systems

Tools

Firewall
SIEM
Cloud security
Malware analysis

Job description

Responsibilities
  • Formulate and manage cyber security policies, standards and procedures.
  • Assist in planning of technology related risk management strategies, processes and work plans.
  • Participate in Cyber Security projects for the design, development and implementation.
  • Plan and conduct cyber security assessment and IT risk evaluation in area covering IT general controls, information asset management, access controls, cloud/server/endpoint/network/middleware security review. Support the implementation of security initiatives to ensure compliance with corporate information security policies and compliance standards.
  • Participate in organizing/conducting penetration test, red/blue/purple teaming exercises, vulnerability assessment, validation controls for local/overseas entities.
  • Provide Cyber Security incident response operation and support, work with local & regional SOC team to seek continuous improvement for daily Cyber Security monitoring, incident analysis & investigation, incident response operation and support.
  • Experience in arrangement and co-ordination of cross-countries cyber incident response drills.
  • Experience in Security operations, managing SOC, Offensive security, Container security, CSPM, Threat Hunting, OSINT, Dark Web monitoring, Malware analysis, SecOps, Digital forensics, Attack surface management, managing Cloud/ISP/On-premises Anti-DDoS solution, AI/LLM security, Threat modeling, Supply chain cybersecurity and Vulnerability management.
  • Serve as a subject matter expert to support business units and cross-functional teams in identifying and addressing cybersecurity risks. Engage with various business units and teams to discuss risk issues and control gaps, and propose effective remediation strategies.
  • Research and evaluate latest security threats and Cyber Threat Intelligence, stay informed about latest developments in cyber security field.
  • Familiar with technologies on Firewall, IDS, IPS, WAF, DNS Security, Email Security, SIEM, SOAR, DLP, UEBA, BAS, XDR, Deception, Generative AI/Machine Learning, Application of AI/ML/LLM/MCP/RAG libraries in Python, Zero Trust, Micro-segmentation, Unified endpoint management, SASE/SSE Solution, Database security, and Network/Cloud security are preferable.
  • Willing to travel to different overseas regions occasionally to conduct regional cyber security assessment, provide cyber security incident and response support, and participate in different training / red team exercises (e.g., Asia Pacific area, Shenzhen and Shanghai).
General Job Requirements
  • Degree holder in Computer Science or other degree majoring in Information Systems, or related discipline.
  • At least 2 years of experience in IT security, technology risk management, compliance or IT audit function, gained from other sizable financial institutions.
  • Holding at least one recognized professional qualification under HKMA enhanced competency framework such as CISA, CISSP, CISM. Industry-recognized cyber security certifications, such as OSCP/OSCE/OSWE/OSEE/GXPN/GPEN/GCPN/GCIH/GSOC/GCFA/OSDA/CCIE/CCNP, are preferable.
  • Familiar with HKMA TM-E-1, TM-C-1, TM-G-1, C-RAF, PCI-DSS, ISO 27001, PDPO, NIST, MITRE ATT&CK, OWASP, Protection of Critical Infrastructures (Computer Systems) Bill or other security risk management framework or regulatory requirements is an advantage.
  • Independent, strong self-initiative and passion in cyber security professional.
  • Good command of written and spoken English with Mandarin preferable.
  • Good communication and interpersonal skills.
  • Candidate with less experience or qualification will also be considered as Assistant Technology Risk Manager.

We offer competitive remuneration package and comprehensive fringe benefits including medical and life insurance, and different types of allowances to the right candidates.

Interested parties, please submit your application online.

Data collected would be used for recruitment purposes only. Applicants who do not hear from us within 8 weeks may consider their application unsuccessful and their data will be destroyed within 12 months of receipt.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

(Senior) Technology Risk Manager (Cyber Security Control Division)
(Senior) Technology Risk Manager (Cyber Security Control Division)

Bank of China (Hong Kong) Limited • Hong Kong

On-site
HKD 420,000 - 750,000
(Senior) Technology Risk Manager (Cyber Security Control Division)
(Senior) Technology Risk Manager (Cyber Security Control Division)

Hong Kong Job Consulting • Hong Kong

On-site
HKD 700,000 - 1,000,000
Technology Risk Manager (Information Security Control Division)
Technology Risk Manager (Information Security Control Division)

Bank of China (Hong Kong) • Hong Kong

On-site
HKD 700,000 - 1,000,000
Manager - Technology Compliance
Manager - Technology Compliance

InfoTech Services (Hong Kong) Limited • Hong Kong

On-site
HKD 500,000 - 700,000
Technology Risk Manager (Information Security Control Division)
Technology Risk Manager (Information Security Control Division)

Bank of China (Hong Kong) Limited • Hong Kong

On-site
HKD 700,000 - 1,000,000
Technology Risk / Cyber Security Manager (Banking)
Technology Risk / Cyber Security Manager (Banking)

Hong Kong Job Consulting • Hong Kong

On-site
HKD 600,000 - 1,200,000
IT Security Manager (banking) (Finance/up to 70K)
IT Security Manager (banking) (Finance/up to 70K)

Manpower Services (Hong Kong) Limited • Hong Kong Island

On-site
HKD 469,000 - 781,000
Technology Risk Manager (APAC Centre Technology Risk & Compliance Management)
Technology Risk Manager (APAC Centre Technology Risk & Compliance Management)

Bank of China (Hong Kong) Limited • Sha Tin

On-site
HKD 900,000 - 1,200,000
Technology Risk Manager (Asia-pacific Centre Technology Risk & Compliance Management)
Technology Risk Manager (Asia-pacific Centre Technology Risk & Compliance Management)

Bank of China (Hong Kong) Limited • Hong Kong

On-site
HKD 600,000 - 1,000,000
Technology Risk Manager (Asia-pacific Centre Technology Risk & Compliance Mgmnt)
Technology Risk Manager (Asia-pacific Centre Technology Risk & Compliance Mgmnt)

Bank of China (Hong Kong) Limited • Hong Kong

On-site
HKD 900,000 - 1,200,000