Jobiglo

No results.

IT Audit & Advisory – Technology Risk Specialist (All Levels)

EY · Île de Hong Kong

New
🇬🇧 English
CISA CISM CISSP CRTP CRTE OSCP GPEN GXPN ISO NIST COBIT SANS vulnerability scanning

Job description

About the role

As a technology risk specialist at EY, you will guide financial‑sector clients in Hong Kong and the Greater Bay Area to manage technology risks, meet regulatory requirements and strengthen cybersecurity postures.

Key responsibilities

  • Conduct technology compliance reviews for banking, wealth, asset management and insurance institutions across Hong Kong and the Greater Bay Area.
  • Analyse client IT environments, identify risks, evaluate controls—including cloud security—and ensure alignment with regulatory requirements and industry standards.
  • Act as licensing advisor, helping clients navigate technology risk aspects of financial activity licensing.
  • Assess and implement information security management frameworks such as ISO, NIST, COBIT and SANS.
  • Develop holistic governance and incident‑management frameworks and advise on emerging technologies like blockchain, AI/ML and big data.
  • Perform vulnerability scanning, penetration testing and cyber‑attack simulations to validate control effectiveness.
  • Deliver information‑security awareness training and support the creation of security strategy plans.
  • Mentor junior team members, contribute to proposals and maintain client relationships using project‑management principles.

Required profile

  • Bachelor’s or master’s degree in Information Security, Computer Science, Engineering or related fields.
  • Relevant experience in technology risk, IT audit or cybersecurity, with hands‑on exposure to compliance reviews and risk assessments.
  • Professional certifications such as CISA, CISM or CISSP; additional certifications (CRTP, CRTE, OSCP, GPEN, GXPN, cloud‑related) are valued.
  • Strong written and spoken English and Chinese; Mandarin is a plus.
  • Proficiency with Microsoft Office tools (Word, Excel, PowerPoint, Visio).

Required skills

  • CISA, CISM, CISSP certifications.
  • Cloud security and related certifications.
  • Experience with ISO, NIST, COBIT, SANS frameworks.
  • Vulnerability scanning, penetration testing, cyber‑attack simulation.
  • Knowledge of blockchain, virtual assets, AI/ML, big data security.

What we offer

  • Competitive performance‑based compensation.
  • Coaching, feedback and development from senior colleagues.
  • Opportunities to acquire new skills and advance your career.
  • Flexibility to manage your role in a way that suits you.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec EY.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Explore further

Salaries, guides and searches in Hong Kong.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

Apply now →

By continuing, you accept our terms of use.

Already have an account? Login

A question about this job?

Ask it here: you will get the full job summary by e-mail, right away.

💬 Chat with us on Telegram

Published 5 days ago

Expires 1 month from now

18 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

EY

Île de Hong Kong