Manager, Cybersecurity Governance & Risk
Anglo-Eastern · Hong Kong
Job description
About the role
The Manager, Cybersecurity Governance & Risk will translate the Group's cyber and technology risk strategy into actionable policies, standards and controls. You will lead risk assessments across shore, vessel, cloud and OT environments and ensure continuous compliance with maritime and data‑privacy regulations.
Key responsibilities
- Develop and maintain a control framework aligned to ISO/IEC 27001, ISO 22301 and NIST CSF 2.0.
- Lead risk assessments, maintain the risk register and produce KPI/KRI dashboards for senior management.
- Manage an obligations register covering maritime cyber requirements, client commitments and regional regulations (e.g., Hong Kong PDPO, Singapore PDPA, NIS2).
- Coordinate internal, external, certification and client audits end‑to‑end.
- Run a risk‑based third‑party programme with Legal and Privacy, from due‑diligence to contract monitoring.
- Work hands‑on with Infrastructure & Operations on network segmentation, perimeter controls, Windows Server and Active Directory hardening, endpoint configuration, patch and vulnerability management, and privileged access.
- Partner with Development and Digitalisation on security‑by‑design, DevSecOps and AI‑risk frameworks.
- Lead crisis‑management, business continuity and disaster‑recovery exercises.
- Develop and mentor the GRC team and embed cybersecurity training for seafarers and shore staff.
Required profile
- Bachelor's degree in Information Security, Computer Science, Engineering, Risk Management or related field (or equivalent experience).
- 8‑12 years of experience in cybersecurity GRC, information security governance, technology risk, IT audit or security assurance, including leadership responsibility.
- Professional certifications such as CISM, CRISC, CISA, CISSP, ISO/IEC 27001 Lead Implementer or Lead Auditor, ISO 22301 Lead Implementer/Auditor are strongly preferred.
Required skills
- ISO/IEC 27001, ISO 22301, NIST CSF implementation.
- Risk assessment and risk register management.
- Network segmentation, perimeter security, Windows Server and Active Directory hardening (Group Policy baselines).
- Endpoint configuration, patch management, vulnerability management, privileged access management.
- Security‑by‑design, DevSecOps, cloud security.
- AI risk assessment frameworks (NIST AI RMF, ISO/IEC 42001).
- Crisis management, business continuity, disaster recovery planning.
- Audit coordination and certification readiness.
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Hong Kong.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
A question about this job?
Ask it here: you will get the full job summary by e-mail, right away.
Published 2 weeks ago
Expires 1 month from now
21 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Anglo-Eastern
Hong Kong