M/SM - Tech Risk
A large enterprise client is now looking for candidates with strong cyber tech risk background to support their risk assessment program.
Responsibilities:
- Support and drive Cybersecurity management’s directives in priority
- Contribute to the enhancement and evolution of the CSRM programme and framework, including execution of targeted risk assessments on holistic Cybersecurity risk and enhance current practices to mitigate cyber risks and the establishment of a risk framework
- Align risk appetite and fine-tune processes necessary within the business
- Follow and execute risk management practices with Risks & Controls Library, Impact Thresholds, Security Governance, Controls Testing, Issue Management, Risk Registers, Risk Reporting, etc.
- Assess risks based on policy, standards, technology compliance requirements and best practices for IT and business projects and activities
- Ensure security measures are properly adopted for risk mitigation
- Risk exception and acceptance must be well governed, timely validated and properly escalated
- Prepare a report to senior management on the current security posture
- Partner with Information Security and IT teams to implement appropriate solutions to mitigate exposure as needed
- Participate and contribute positively to create a diverse and inclusive culture with trust and respect. Play an active role to support cross-team/division/department efforts and model collaborative behaviours
Requirements:
- University degree in Computer Science, Information Technology/Security Management, Cybersecurity, or a related field
- Sound experience working in technology risk management
- Strong consulting background in IT/Security/ IT Audit is desired
- At least eight years’ experience in IT technical roles and audit, three years of hand-on in technology risk assessment and security compliance aspects
- CISA, CISSP, CRISC or equivalent is preferable
- Experience in adopting risk-based assessment methodologies and engaging audit counter-parts
- Experience in performing risk assessment and evaluation
- Experience in reporting risk tailored to IT and business stakeholders about most significant risks to the business
- Competency consulting background in IT, Cyber Security and/or IT Audit and Control Compliance
- Competency interacting with seasoned colleagues on Technology and Cybersecurity Risk, Audit and compliance agenda
- Knowledge of ISMS, ISO27000, ISO31000 and other major information security frameworks/Practices e.g. NIST, COBIT etc.
- Strong knowledge of Audit control framework, IT general controls, Cybersecurity Risk, Tech Risk (including infrastructure, cloud and applications security)
- IT background with operations, enterprise networking, operating systems and database security risk controls
If you would like to apply for this role or find out more, please apply online or contact Vivian Tsang at Robert Walters on +852 2161 9400 or VivianYW.Tsang@robertwalters.com.hk quoting the Job Reference: E2QV5F
About the job
Contract Type: Perm
Specialism: Tech & Transformation
Focus: Cyber Security
Industry: IT
Salary: Negotiable
Workplace Type: On-site
Experience Level: Senior Management
Location: Central and Western District
FULL_TIMEJob Reference: E2QV5F-3763D67A
Date posted: 27 October 2025
Consultant: Vivian Tsang
hong-kong tech-transformation/it-security 2025-10-27 2025-12-26 it Hong Kong Central and Western District HK Robert Walters https://www.robertwalters.com.hk https://www.robertwalters.com.hk/content/dam/robert-walters/global/images/logos/web-logos/square-logo.png true