Cybersecurity Risk & Governance Manager
Airport area, HK
The HAECO Group is an independent global provider of high-quality MRO services. We offer a broad range of aviation products and services that enable our customers to operate their aircraft, engines and components safely and efficiently. Headquartered in Hong Kong since 1950, our global reach has extended as we have grown. We now have operations throughout the Asia-Pacific region, Americas and other parts of the world.
Based at Hong Kong International Airport (HKIA), HAECO Hong Kong offer a full range of services including airframe services, line services, component services, engine services, freighter conversions, technical training and AOG support.
Position Description
The Cybersecurity Risk & Governance Manager is responsible for establishing and maintaining HAECO’s overall IT risk management program to ensure that HAECO’s IT/OT systems and information assets are adequately protected. He/She will identify, evaluate and report on IT/OT security risks; and advise HAECO entities on implementing practices that meet HAECO’s defined policies and standards for cybersecurity risk management.
What You'll Do
- Develop appropriate standards and practices in relations to security governance & compliance.
- Review, maintain and enhance security standards, procedures and guidelines to ensure they are current and adequate.
- Facilitate cybersecurity risk assessment with Entities.
- Monitor and report effective IT risk mitigating controls with application and infrastructure owners.
- Analyse threat intelligence and recommend improvement on security controls for Entities to evaluate and implement
- Manage cybersecurity incidents and participate in the cybersecurity crisis drill in order to minimize the damage/loss due to cybersecurity attacks.
- Deploy cybersecurity training program to uplift business cybersecurity awareness.
What You'll Need
1. Functional and other Relevant Experience
- A minimum of 6 years of combined experience in information security, security operations, security program and project management.
2. Qualifications and other Relevant Knowledge
- Bachelor’s or master’s degree in Computer Science, Information Security or a related field or discipline.
- Certified CISSP, CISM, CISA, CRISC or other similar credentials
- Knowledge and understanding of NIST and ITIL.
- In-depth knowledge of information security risk management and cybersecurity technologies.
- Fluent in English, Mandarin is an advantage
HAECO Group is an equal opportunity employer. At HAECO, we are committed to creating an inclusive and supportive working environment for all our people regardless of their age, gender, gender identity, sexual orientation, relationship, family status, disability, race, ethnicity, nationality, religious or political beliefs. We believe in creating an environment where people feel comfortable at work and are able to realise their full potential.
Build your career with us and be part of something bigger at HAECO!
Reference ID: 1204
Candidates not contacted 4-6 weeks after submission of applications and/or interviews may consider their application unsuccessful.
All information provided by candidates will be treated in strict confidence and will be used for employment purpose only.