Vice President, IT Security & Platform

HKTHong KongOn-siteFull-timeStaff, 8–12 yearsListed 2 days ago

Apply now

About this role

Key Responsibilities

Cybersecurity Leadership & Governance

- Develop and execute the enterprise cybersecurity strategy and roadmap

- Establish security governance, policies, and control frameworks.

- Lead cybersecurity transformation initiatives and continuous improvement programs.

- Provide strategic direction for security technologies, and cybersecurity capabilities.

- Establish and promote a cybersecurity awareness program across the organisation, including security training, phishing simulations, and awareness campaigns.

- Present cybersecurity strategy, risk posture, and key initiatives to senior management, risk committees, and the Board where applicable.

Technology Risk Management

- Establish and maintain the technology risk management framework.

- Oversee technology risk and control assessments

- Manage technology risk committees, risk reporting and Key Risk Indicators (KRIs).

- Oversee IT exemption management and risk acceptance processes.

- Manage IT audits, regulatory reviews, and other assessment engagements, and oversee the implementation of remediation programs.

- Drive continuous improvement initiatives to enhance technology risk management and governance practices.

- Lead and coordinate security drills and cyber resilience exercises.

Security Operations & Incident Response

- Provide executive oversight of Security Operations Centre (SOC) functions.

- Ensure effective 24x7 monitoring, threat detection, investigation, and incident response.

- Oversee security incident management, forensic investigations, root cause analysis, containment, and recovery activities.

- Direct threat intelligence, threat hunting, alert management, and use case development activities.

- Ensure timely management reporting on security events and operational effectiveness.

Security Engineering

- Lead the implementation of security engineering to deploy new security tools and processes.

- Ensure secure implementation of infrastructure security controls including firewalls, VPNs, endpoint security, and network security.

- Conduct the security assessment for new initiatives

- Oversee the operation of application security including DevSecOps, API security, container security, and CI/CD security.

- Govern security tool implementation and optimization including SIEM, EDR, SOAR, DLP, and vulnerability management technologies.

- Drive security automation, orchestration, and hardening initiatives.

- Oversee vulnerability assessment, penetration testing and security validation

- Provide security advisory

Identity & Access Management (IAM)

- Establish IAM governance, strategy, and operational controls.

- Oversee identity lifecycle management, authentication services, privileged access management, and access recertification programs.

- Manage the administration of privileged accounts to ensure they’re secured.

- Conduct day-to-day operation for user accounts including provisioning/deprovisioning, recertification, dormant ID management, etc

- Ensure segregation of duties controls are effectively implemented and monitored.

- Oversee key and certificate management operations.

- Lead IAM transformation and integration initiatives across the enterprise.

Third-Party Security Management

- Conduct the third-party cybersecurity assessment for key service providers.

- Oversee security assessments of vendors and external service providers.

- Monitor third-party security risks and remediation activities

Secured Room Management

- Manage the operation and administration of physical access controls for secured rooms.

- Conduct periodic security reviews to verify compliance with physical security requirements for secured rooms.

- Develop and enhance automated workflow for physical access request, approval, provisioning, and revocation processes.

Qualifications & Experience

Education

- Degree in Computer Science, Information Systems and Technology, or related discipline.

Experience

- 8+ years of information security and technology risk management experience.

- 10+ years in a senior leadership role managing multi-disciplinary technology teams.

- Proven experience leading Security Operations, Security Engineering, IAM, and Technology Risk functions.

- Experience reporting cybersecurity risk posture to senior executives and risk committees.

- Proven track record in cybersecurity transformation and security program leadership.

- Experience within financial services, government, or highly regulated environments is highly desirable.