Manager, Information Security Policy & Compliance
Job Summary
Reporting to the Senior Manager, ISRA, you will be a key member involved in uplifting the Club’s information security assurance as a second line of defence. You will be developing and maintaining Information Security Policy, Acceptable Use Policy and other policies. You will also be designing and implementing a compliance self-assessment programme for the compliance of the policies. You will also be involved in other information security assurance and technology risk management activities as assigned.
The Job
You will:
- Develop and maintain information security policies.
- Perform compliance assessment against information security policies.
- Assist in programme management, and work with external consultants to deliver technology risk and information security projects.
- Conduct information security risk assessments and control assurance testing.
- Assist in delivering information security initiatives and prepare necessary documentation.
- Assist in technology risk management activities.
- Monitor and report on security metrics and trends to monitor the technology and information security risks.
- Promote security awareness within the organization, fostering a culture of risk management.
About You
You should have:
- University degree in Computer Science, Information Technology, Cybersecurity, Engineering, Risk Management or related fields.
- 5 to 7 years of practical experience in Cyber Security or Technology Risk roles.
- Hands-on experience in enterprise security infrastructure, risk assessments, and security testing.
- Experience with identity and access management systems and principles.
- Familiarity with security frameworks and standards (e.g. ISO27001, NIST).
- Understand second line of defence roles and responsibilities.
- Relevant certifications such as CISSP, CISA or CISM are preferred.
Terms of Employment
The level of appointment will be commensurate with qualification and experience.
How to Apply
Please send your resume, complete with expected salary and job reference by clicking the Apply Now.
We are an equal opportunity employer. Personal data provided by job applicants will be used strictly in accordance with the Club's notice to employees and prospective employees relating to the Personal Data (Privacy) Ordinance. A copy of which will be provided immediately upon request.
Share this Job :
To share this job on WeChat, please click the button below to copy the link: