Job Description
The Cybersecurity Specialist / Cybersecurity Manager is responsible for the firm’s information security, cyber risk, and technology control framework within a SFC licensed corporation. The role focuses on governance, internal controls, SOC oversight, operational resilience, and regulatory compliance, including management reporting, incident handling, and audit / regulatory enquiry coordination.
Responsibilities of the Role
Develop and maintain information security policies, standards, procedures, and controls aligned to the firm’s risk profile and regulatory obligations.
Operate key controls across access management, endpoint and network security, logging and monitoring, vulnerability management, encryption, backup, and recovery.
Manage or oversee SOC operations, including alert monitoring, triage, escalation, and incident coordination.
Lead cyber risk assessments, control testing, and remediation tracking for internal, cloud, and outsourced environments.
Oversee incident response, including containment, investigation, root cause analysis, and follow-up remediation.
Manage third-party and cloud security risk, including due diligence, control review, and ongoing monitoring.
Support resilience through secure remote access, business continuity, disaster recovery, and staff security awareness.
Provide regular reporting to senior management on cyber risks, incidents, control effectiveness, and remediation status.
Ensure policies and controls are documented, approved, implemented, reviewed, and supported by audit-ready evidence.
Coordinate responses to internal audit, external audit, regulatory inspections, and cybersecurity enquiries, including evidence gathering and remediation tracking.
Work with Compliance, Internal Audit, Operations, and IT to embed effective cybersecurity controls across the business.
Escalate material cyber risks, incidents, and control gaps promptly with clear recommendations and action plans.
Required Skills for the Role
Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Risk Management, or a related discipline.
Relevant experience in information security, cyber risk, IT audit, security operations, or SOC within financial services or another regulated environment.
For Manager level, experience leading security governance, controls, SOC oversight, or risk management programmes and engaging senior stakeholders.
Strong understanding of security controls, cloud and third-party risk, incident response, audit support, and regulatory enquiry handling.
Good communication skills in English; Mandarin proficiency is an advantage.
Professional certifications such as CISSP, CISM, CISA, CRISC are preferred.
Experience in financial services, preferably within an SFC licensed corporation or related regulated institution.
Familiarity with SFC expectations on cybersecurity governance, senior management accountability, incident handling, and third-party oversight.
| 薪酬 | 薪金面議 |
| 工種 |
|
| 僱用形式 |
|
| 教育程度 |
|