Position Overview
Job Title: IT Security Manager / Assistant Manager (Title commensurate with experience)
Location: Hong Kong / Mainland China
Industry: Regulated Financial Services (Banking / Insurance / Financial Services preferred)
Function: Information Technology / Cyber Security
Employment Type: Full-time
Key Responsibilities
1. Security Operations & Threat Management
Support and enhance the organisation's cybersecurity framework, policies, standards, and procedures.
Monitor cyber threats, security events, and vulnerabilities, coordinating remediation and response actions.
Oversee security monitoring, threat detection, and incident response with internal teams and external providers.
Investigate security incidents, perform root-cause analysis, and coordinate containment, remediation, and post-incident follow-up.
Manage vulnerability assessments, penetration testing, and security reviews.
2. Security Controls & Technical Architecture
Review and enhance security controls across multiple domains
3. Risk Assessment & Compliance Audits
Conduct security and technology risk assessments for new systems, applications, and technology projects.
Perform periodic reviews of user access, privileged accounts, and security configurations.
Support third-party / vendor security assessments and evaluate risks associated with external partners.
Assist in managing regulatory, compliance, and audit requirements, coordinating responses to internal/external audits and regulatory reviews.
Track security findings and audit issues to ensure timely closure.
4. Governance, Awareness & Support
Maintain cybersecurity documentation, risk assessments, incident records, security metrics, and management reports.
Support cybersecurity awareness programmes, security training, and phishing awareness exercises.
Participate in incident response exercises, disaster recovery, and operational resilience activities.
Provide security advisory support to business and technology stakeholders.
Job Requirements
Experience: Relevant background in IT Security, Cyber Security, Information Security, Technology Risk, or related areas. Experience in banking, insurance, financial services, or other regulated industries is highly preferred.
Compliance & Audit: Exposure to regulatory, technology risk, internal audit, or security compliance activities within a financial institution is an advantage.
Certifications: Professional certifications such as CISSP, CISM, CISA, CCSP, CEH or equivalent are advantageous (not mandatory).
Soft Skills:
Strong analytical, problem-solving, and stakeholder management capabilities.
Good communication skills to collaborate with both technical and business stakeholders.
Good command of written and spoken English and Chinese is preferred.
Please Contact: Tommy.huang@manpowergrc.hk OR WhatsApp: +852 94168664