(Senior) Technology Risk Manager (Cyber Security Control)
Other service activities
A leading bank in Hong Kong
• Degree holder in Computer Science, Information Systems, or related discipline, with a solid understanding of IT security concepts and technology risk management frameworks relevant to financial institutions.
• At least 2 years of experience in IT security, technology risk management, compliance, or IT audit function, gained from other sizable financial institutions, with practical exposure to security controls and risk assessment.
• Holding at least one recognized professional qualification under HKMA enhanced competency framework such as CISA, CISSP, or CISM, with these certifications forming a core requirement for the position.
• Industry-recognized cyber security certifications such as OSCP, OSCE, OSWE, OSEE, GXPN, GPEN, GCPN, GCIH, GSOC, GCFA, OSDA, CCIE, or CCNP are preferable and indicate strong capabilities in both offensive and defensive cyber security.
• Familiar with HKMA TM-E-1, TM-C-1, TM-G-1, C-RAF, PCI-DSS, ISO 27001, PDPO, NIST, MITRE ATT&CK, OWASP, Protection of Critical Infrastructures (Computer Systems) Bill, or other security risk management framework or regulatory requirements is an advantage.
• Familiar with technologies such as Firewall, IDS, IPS, WAF, DNS Security, Email Security, SIEM, SOAR, DLP, UEBA, BAS, XDR, Deception, Generative AI/Machine Learning, Zero Trust, Micro-segmentation, Unified endpoint management, SASE/SSE Solution, Database security, and Network/Cloud security is preferable.
• Experience with Application of AI/ML/LLM/MCP/RAG libraries in Python and AI/LLM security considerations is relevant for supporting advanced analytics, automation, and security use cases in the Cyber Security Control Division.
• Independent working style with strong self-initiative, good communication and interpersonal skills, and a clear passion in cyber security professional practice, particularly in complex and regulated financial institution environments.
• Good command of written and spoken English, with Mandarin preferable, enabling effective communication with local and overseas entities and coordination of cross-border cyber security initiatives.
• Candidates with less experience or qualification will also be considered as Assistant Technology Risk Manager, depending on overall suitability and alignment with client expectations.
• Formulate, maintain, and govern cyber security policies, standards, and procedures supporting technology related risk management strategies, processes, and work plans across the Cyber Security Control Division.
• Lead or participate in Cyber Security projects covering the design, development, and implementation of cyber security controls, solutions, and capabilities aligned with corporate information security policies.
• Plan and perform cyber security assessment and IT risk evaluation, including reviews of IT general controls, information asset management processes, and access controls across critical systems and information assets.
• Conduct cloud, server, endpoint, network, and middleware security review activities to support compliance with corporate information security policies and relevant internal and external compliance standards.
• Organize and execute penetration test, red, blue, and purple teaming exercises, vulnerability assessment, and validation controls for local and overseas entities in accordance with established cyber security methodologies.
• Provide Cyber Security incident response operation and support, working closely with local and regional SOC team on daily Cyber Security monitoring, incident analysis and investigation, and continuous improvement of incident response operation and support.
• Arrange and coordinate cross-countries cyber incident response drills, ensuring that lessons learned are documented and integrated into cyber incident response procedures and operational playbooks.
• Perform Security operations activities including managing SOC, Offensive security, Container security, CSPM, Threat Hunting, OSINT, Dark Web monitoring, Malware analysis, SecOps, and Digital forensics to safeguard the organization’s technology environment.
• Oversee Attack surface management and managing Cloud, ISP, and On-premises Anti-DDoS solution deployments, while maintaining AI/LLM security practices and robust Vulnerability management across infrastructure and applications.
• Apply Threat modeling techniques and address Supply chain cybersecurity risks, serving as subject matter expert to support business units and cross-functional teams in identifying and addressing cybersecurity risks.
• Engage with various business units and teams to discuss risk issues and control gaps, propose effective remediation strategies, and follow up on the implementation of agreed cyber security and technology risk measures.
• Research and evaluate latest security threats and Cyber Threat Intelligence, staying informed about latest developments in cyber security field and advising stakeholders on emerging threat trends and countermeasures.
• Support regional cyber security assessment, provide cyber security incident and response support, and participate in different training and red team exercises, including occasional travel to Asia Pacific area, Shenzhen, and Shanghai.
Ref: JN-072026-204872