
Cyber Security Consultant (Governance & Risk)
- Kowloon, Hong Kong
- Permanent
- Full-time
- Lead standard, and support complex, cyber security projects in the Governance, Risk and Compliance domain.
- Perform technology risk assessments, assess the effectiveness of processes/controls and make recommendations to improve the technology control environment.
- Perform maturity assessments using the NIST Cybersecurity Framework (CSF) to identify and address gaps in security practices.
- Perform pre-assessments to ensure compliance with Multi-Level Protection Scheme (MLPS) requirements and guide remediation efforts.
- Conduct ISO 27001 gap analysis and audits to identify non-compliance areas and recommend corrective actions.
- Design and facilitate tabletop exercises to simulate security incidents for senior executives.
- Support in the development of privacy-related services, including client engagement and commercial frameworks.
- Prepare and present high-quality reports detailing security issues, making recommendations, and identifying solutions
- Support pre-sales processes and working with the Business Development team to win new deals.
- Degree in information security, computer science or related field
- At least 4 years of information security exposure
- Good working knowledge of relevant standards, security frameworks and regulations (ISO27001, NIST, GDPR, CSL, MLPS, GL20, PDPO, PIPL)
- Excellent written and verbal communication skills
- Broad knowledge across multiple technical domains and willing to learn
- Confident and assured presentation skills – at ease with senior stakeholder engagement
- Good communication/presentation skills
- Continuous learning: ability to stay up to date with the latest security trends, techniques, and tools.
- Able to work collaboratively and independently
- Knowledge of security regulations and standards such as NIST Cybersecurity Framework and ISO 27001.
- Industry certifications such as CISSP/CISM/CRISC highly preferred
- Medical Insurance (includes dependents)
- 18 - 21 working days’ annual leave
- Discretionary bonus
- Study and Continuous Learning Sponsorship
- On-the-job training
CTgoodjobs