H
Vice President, IT Security & Platform
HKT Services Limited
Hong Kong · hk
6h ago
81%
Strong
Job description
Key Responsibilities Cybersecurity Leadership & Governance Develop and execute the enterprise cybersecurity strategy and roadmap Establish security governance, policies, and control frameworks. Lead cybersecurity transformation initiatives and continuous improvement programs. Provide strategic direction for security technologies, and cybersecurity capabilities. Establish and promote a cybersecurity awareness program across the organisation, including security training, phishing simulations, and awareness campaigns. Present cybersecurity strategy, risk posture, and key initiatives to senior management, risk committees, and the Board where applicable. Technology Risk Management Establish and maintain the technology risk management framework. Oversee technology risk and control assessments Manage technology risk committees, risk reporting and Key Risk Indicators (KRIs). Oversee IT exemption management and risk acceptance processes. Manage IT audits, regulatory reviews, and other assessment engagements, and oversee the implementation of remediation programs. Drive continuous improvement initiatives to enhance technology risk management and governance practices. Lead and coordinate security drills and cyber resilience exercises. Security Operations & Incident Response Provide executive oversight of Security Operations Centre (SOC) functions. Ensure effective 24x7 monitoring, threat detection, investigation, and incident response. Oversee security incident management, forensic investigations, root cause analysis, containment, and recovery activities. Direct threat intelligence, threat hunting, alert management, and use case development activities. Ensure timely management reporting on security events and operational effectiveness. Security Engineering Lead the implementation of security engineering to deploy new security tools and processes. Ensure secure implementation of infrastructure security controls including firewalls, VPNs, endpoint security, and network security. Conduct the security assessment for new initiatives Oversee the operation of application security including DevSecOps, API security, container security, and CI/CD security. Govern security tool implementation and optimization including SIEM, EDR, SOAR, DLP, and vulnerability management technologies. Drive security automation, orchestration, and hardening initiatives. Oversee vulnerability assessment, penetration testing and security validation Provide security advisory Identity & Access Management (IAM) Establish IAM governance, strategy, and operational controls. Oversee identity lifecycle management, authentication services, privileged access management, and access recertification programs. Manage the administration of privileged accounts to ensure they’re secured. Conduct day-to-day operation for user accounts including provisioning/deprovisioning, recertification, dormant ID management, etc Ensure segregation of duties controls are effectively implemented and monitored. Oversee key and certificate management operations. Lead IAM transformation and integration initiatives across the enterprise. Third-Party Security Management Conduct the third-party cybersecurity assessment for key service providers. Oversee security assessments of vendors and external service providers. Monitor third-party security risks and remediation activities Secured Room Management Manage the operation and administration of physical access controls for secured rooms. Conduct periodic security reviews to verify compliance with physical security requirements for secured rooms. Develop and enhance automated workflow for physical access request, approval, provisioning, and revocation processes. Qualifications & Experience Education Degree in Computer Science, Information Systems and Technology, or related discipline. Experience 8+ years of information security and technology risk management experience. 10+ years in a senior leadership role managing multi-disciplinary technology teams. Proven experience leading Security Operations, Security Engineering, IAM, and Technology Risk functions. Experience reporting cybersecurity risk posture to senior executives and risk committees. Proven track record in cybersecurity transformation and security program leadership. Experience within financial services, government, or highly regulated environments is highly desirable.