Jobiglo

No results.

Manager, Cybersecurity Governance & Risk

Anglo-Eastern · Hong Kong

Senior 🇬🇧 English
ISO/IEC 27001 ISO 22301 NIST CSF risk assessment network segmentation Windows Server Active Directory Group Policy endpoint configuration vulnerability management security-by-design DevSecOps crisis management business continuity disaster recovery

Job description

About the role

The Manager, Cybersecurity Governance & Risk will translate the Group's cyber and technology risk strategy into actionable policies, standards and controls. You will lead risk assessments across shore, vessel, cloud and OT environments and ensure continuous compliance with maritime and data‑privacy regulations.

Key responsibilities

  • Develop and maintain a control framework aligned to ISO/IEC 27001, ISO 22301 and NIST CSF 2.0.
  • Lead risk assessments, maintain the risk register and produce KPI/KRI dashboards for senior management.
  • Manage an obligations register covering maritime cyber requirements, client commitments and regional regulations (e.g., Hong Kong PDPO, Singapore PDPA, NIS2).
  • Coordinate internal, external, certification and client audits end‑to‑end.
  • Run a risk‑based third‑party programme with Legal and Privacy, from due‑diligence to contract monitoring.
  • Work hands‑on with Infrastructure & Operations on network segmentation, perimeter controls, Windows Server and Active Directory hardening, endpoint configuration, patch and vulnerability management, and privileged access.
  • Partner with Development and Digitalisation on security‑by‑design, DevSecOps and AI‑risk frameworks.
  • Lead crisis‑management, business continuity and disaster‑recovery exercises.
  • Develop and mentor the GRC team and embed cybersecurity training for seafarers and shore staff.

Required profile

  • Bachelor's degree in Information Security, Computer Science, Engineering, Risk Management or related field (or equivalent experience).
  • 8‑12 years of experience in cybersecurity GRC, information security governance, technology risk, IT audit or security assurance, including leadership responsibility.
  • Professional certifications such as CISM, CRISC, CISA, CISSP, ISO/IEC 27001 Lead Implementer or Lead Auditor, ISO 22301 Lead Implementer/Auditor are strongly preferred.

Required skills

  • ISO/IEC 27001, ISO 22301, NIST CSF implementation.
  • Risk assessment and risk register management.
  • Network segmentation, perimeter security, Windows Server and Active Directory hardening (Group Policy baselines).
  • Endpoint configuration, patch management, vulnerability management, privileged access management.
  • Security‑by‑design, DevSecOps, cloud security.
  • AI risk assessment frameworks (NIST AI RMF, ISO/IEC 42001).
  • Crisis management, business continuity, disaster recovery planning.
  • Audit coordination and certification readiness.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec Anglo-Eastern.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Explore further

Salaries, guides and searches in Hong Kong.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

By continuing, you accept our terms of use.

Already have an account? Login

A question about this job?

Ask it here: you will get the full job summary by e-mail, right away.

💬 Chat with us on Telegram

Published 2 weeks ago

Expires 1 month from now

21 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

Anglo-Eastern

Hong Kong