Cyber Security Risk Consultant

Electricity, gas, steam and air conditioning supply

location_onkowloon
acuteTemporary

Copy Linklink

Our client is a Well known Public Corporation based in HK, and they are looking for a senior risk consultant to join their team.

The Role:

  • Conduct cybersecurity risk assessments for IT and operational technology (OT) environments in accordance with industry standards and best practices
  • Identify, analyse, and evaluate cybersecurity risks affecting business operations, industrial control systems, and critical infrastructure assets
  • Assess the effectiveness of existing cybersecurity controls and recommend remediation measures
  • Conduct gap assessments against relevant cybersecurity standards and regulations, such as NIST SP 800-82, IEC 62443, and ISO 27001
  • Develop risk registers, risk treatment plans, and mitigation recommendations
  • Collaborate with operational, engineering, IT, and cybersecurity teams to gather information and understand system architectures
  • Facilitate risk assessment workshops and interviews with system owners, drawing out the technical and operational detail needed to reach a defensible risk rating
  • Assess third-party and supply chain cyber risk arising from vendors, contractors, and operations and maintenance (O&M) service providers.
  • Track risk treatment actions to closure and escalate overdue or accepted risks through the appropriate governance forums
  • Prepare clear assessment reports and present findings to technical teams and senior management


Qualifications:

  • University degree in Computer Science, Information Technology, Information Security, Engineering, or a related discipline
  • Minimum 5 years of hands-on experience in cyber security risk assessment, of which at least 2 years in a regulated or critical infrastructure environment is preferred
  • Professional certification in one or more of the following areas:
    • Auditing: CISA, ISO/IEC 27001 Lead Auditor, IEC 62443 Assessor / Expert
    • Risk assessment and management: CRISC, ISO 31000, CISSP, CISM
    • Compliance and governance: CGEIT, ISO/IEC 42001 Lead Auditor, or equivalent
    • OT / ICS security (advantageous): GICSP, ISA/IEC 62443 Cybersecurity Specialist
  • Familiarity with local regulatory requirements applicable to critical infrastructure (e.g. Protection of Critical Infrastructures (Computer Systems) Ordinance) is an advantage
  • Strong written and spoken English; Chinese is an advantage



Ref: JN-082026-206149