Cyber Security Risk Consultant
Electricity, gas, steam and air conditioning supply
Our client is a Well known Public Corporation based in HK, and they are looking for a senior risk consultant to join their team.
The Role:
- Conduct cybersecurity risk assessments for IT and operational technology (OT) environments in accordance with industry standards and best practices
- Identify, analyse, and evaluate cybersecurity risks affecting business operations, industrial control systems, and critical infrastructure assets
- Assess the effectiveness of existing cybersecurity controls and recommend remediation measures
- Conduct gap assessments against relevant cybersecurity standards and regulations, such as NIST SP 800-82, IEC 62443, and ISO 27001
- Develop risk registers, risk treatment plans, and mitigation recommendations
- Collaborate with operational, engineering, IT, and cybersecurity teams to gather information and understand system architectures
- Facilitate risk assessment workshops and interviews with system owners, drawing out the technical and operational detail needed to reach a defensible risk rating
- Assess third-party and supply chain cyber risk arising from vendors, contractors, and operations and maintenance (O&M) service providers.
- Track risk treatment actions to closure and escalate overdue or accepted risks through the appropriate governance forums
- Prepare clear assessment reports and present findings to technical teams and senior management
Qualifications:
- University degree in Computer Science, Information Technology, Information Security, Engineering, or a related discipline
- Minimum 5 years of hands-on experience in cyber security risk assessment, of which at least 2 years in a regulated or critical infrastructure environment is preferred
- Professional certification in one or more of the following areas:
- Auditing: CISA, ISO/IEC 27001 Lead Auditor, IEC 62443 Assessor / Expert
- Risk assessment and management: CRISC, ISO 31000, CISSP, CISM
- Compliance and governance: CGEIT, ISO/IEC 42001 Lead Auditor, or equivalent
- OT / ICS security (advantageous): GICSP, ISA/IEC 62443 Cybersecurity Specialist
- Familiarity with local regulatory requirements applicable to critical infrastructure (e.g. Protection of Critical Infrastructures (Computer Systems) Ordinance) is an advantage
- Strong written and spoken English; Chinese is an advantage
Ref: JN-082026-206149