IT Manager – Cybersecurity & Risk (MNC)
An established multinational corporation is seeking an experienced IT Manager – Cybersecurity & Risk to oversee the organisation's cybersecurity governance, technology risk management, and compliance initiatives.
Reporting to senior IT leadership, this role is responsible for establishing and maintaining effective security controls, managing IT and cyber risks, ensuring compliance with regulatory requirements, and strengthening the overall security posture of the organisation.
The successful candidate will work closely with internal stakeholders, business units, technology teams, auditors, and external partners to drive security governance, risk assessment, and compliance programmes across a multinational environment.
Key responsibilities:
- Develop, implement, and maintain IT security policies, standards, procedures, and governance frameworks
- Lead enterprise-wide IT and cybersecurity risk assessments and maintain risk registers
- Ensure compliance with applicable regulatory, legal, and industry requirements related to information security and technology risk
- Conduct security control reviews, compliance assessments, and gap analyses against industry standards and frameworks
- Oversee the implementation and effectiveness of security controls across infrastructure, applications, cloud environments, and third-party services
- Track and manage remediation of audit findings, control gaps, security vulnerabilities, and compliance issues
- Lead security due diligence and risk assessments for vendors, suppliers, and outsourced service providers
- Provide guidance and advisory support to business and technology stakeholders on security and risk matters
- Prepare management reports, dashboards, and metrics for senior leadership and governance committees
- Promote security awareness and foster a strong risk-conscious culture across the organisation
Candidate profile:
- Bachelor's degree in Information Security, Computer Science, Information Technology, Risk Management, or a related discipline
- Minimum 8 years’ experience in information security, IT risk management, cybersecurity governance, IT audit, or related areas
- At least 2 years’ experience in a managerial or team leadership role
- Strong understanding of cybersecurity governance, IT risk management, and control frameworks
- Familiarity with cloud security, third-party risk management, identity and access management, vulnerability management, and data protection
- Relevant professional certifications, such as CISSP, CISM, CISA, or CRISC would be an advantage
- Good command of both English and Chinese, including fluent spoken Cantonese
About this company:
A leading multinational aviation and engineering organisation is recognised for its high standards in technical excellence, safety, and operational reliability. It fosters a collaborative, supportive workplace with strong professional development, international exposure, and opportunities to drive innovation and build a future-ready career.
Keywords: Cybersecurity Governance, IT Risk Management, Regulatory Compliance, Cloud Security, Vulnerability Management
What’s next:
Shape the future of risk management and lead the way in cybersecurity governance. Apply now!
About the job
Contract Type: Perm
Specialism: Tech & Transformation
Focus: Cyber Security
Industry: IT
Salary: Negotiable
Workplace Type: Hybrid
Experience Level: Mid Management
Location: Central
FULL_TIMEJob Reference: V0K5KA-9A53E749
Date posted: 4 September 2026
Consultant: Cass Tse
hong-kong tech-transformation/it-security 2026-09-07 2026-11-03 it Central Central and Western District HK Robert Walters https://www.robertwalters.com.hk https://www.robertwalters.com.hk/content/dam/robert-walters/global/images/logos/web-logos/square-logo.png true