Cyber Security Manager
Other service activities
Our client is a well-established organization undergoing continuous digital transformation across multiple business functions, including customer-facing platforms, logistics operations, and corporate systems. They are seeking an experienced Cyber Security Manager to strengthen cybersecurity governance, risk management, compliance, and security controls across regional operations.
Responsibilities
- Lead the development and implementation of cybersecurity strategies, policies, standards, and governance frameworks.
- Manage cybersecurity risks across customer data platforms, internal applications, logistics systems, HR systems, and other enterprise platforms.
- Conduct security risk assessments, vulnerability assessments, and security reviews for new and existing systems.
- Ensure compliance with regulatory requirements, cybersecurity standards, and internal control frameworks.
- Partner with IT, business stakeholders, and regional teams to identify and mitigate cyber risks.
- Drive incident response planning, cybersecurity monitoring, and remediation activities.
- Oversee third-party security assessments and vendor risk management processes.
- Monitor emerging cybersecurity threats and recommend appropriate security controls and improvements.
- Support security awareness programs and promote a strong cybersecurity culture across the organization.
- Prepare cybersecurity reports, risk dashboards, and governance updates for senior management.
- Participate in regional cybersecurity initiatives and projects as required.
- Travel occasionally to support regional operations, security reviews, and project implementations.
Qualifications
- Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Systems, or a related discipline.
- 8-10 years of experience in Information Security, Cybersecurity, IT Risk, Governance, or related functions within an in-house environment.
- Strong knowledge of cybersecurity governance, risk management, compliance, and security frameworks.
- Experience managing cyber risks related to customer data protection, privacy controls, and regulatory compliance.
- Hands-on experience securing enterprise platforms, including internal business applications, logistics systems, and HR systems.
- Experience managing security controls across Microsoft 365, network infrastructure, cloud services, and enterprise technology environments.
- Familiarity with cybersecurity standards and frameworks such as ISO 27001, NIST, CIS Controls, or equivalent.
- Experience conducting security assessments, control reviews, vulnerability management, and risk management activities.
- Regional exposure within APAC is preferred but not mandatory.
- Willingness to travel as required to support regional projects and security initiatives.
- Strong stakeholder management, communication, and project coordination skills.
- Fluent in Cantonese, Mandarin, and English, both written and spoken.
- Professional security certifications such as CISSP, CISM, CISA, GIAC, or equivalent are highly preferred.
Please note that only shortlisted candidates will be notified. All information gathered will be treated with strict confidentiality and solely used for recruitment purposes.
Ref: JN-092026-209546