Manager/Associate Director, Cyber Security

4 weeks ago


Hong Kong, Hong Kong SAR China KPMG China Full time
KPMG China provides multidisciplinary services from audit and tax to advisory, with a strong focus on serving our clients' needs and their industries. Not only do we have an overriding commitment to provide the highest quality services for our clients, but we also strive to become a responsible corporate citizen that has a positive impact on our environment and community. At KPMG, you'll translate insights into action and reveal opportunities for all-our teams, our clients and our world.

Service Line Overview

At KPMG's Consulting practice, we do not limit ourselves to either strategy or implementation. We deliver both. Our Hong Kong division is the fastest growing within KPMG China and represents a young and enthusiastic team that always pushes for success. Since our inception, we have acquired in-depth knowledge of an incredibly broad range of sectors and services.

KPMG is the firm that views cyber security as a business enabler, and not just an IT issue. From the boardroom to back office, we help clients through Strategy and Governance, Transformation, Cyber Defense and Cyber Response. So that they are prepared for uncertainty and use cyber security to advance the business, not stand in the way.

To expand our team, we are seeking Cyber simulated attack managers to join our Cyber Defence team. This role focuses on various technical areas such as red teaming, purple teaming, simulation attack, iCAST, TIBAS, advanced security assessment and infrastructure penetration testing, and social engineering simulation.

Key Responsibilities

Lead various cyber-attack simulation projects using red team / blue team / purple team exercisesConduct social engineering and email phishing attacks to simulate the theft of passwords, infiltrate systems, and download malware / ransomwareLead advanced security assessment and infrastructure penetration tests on different complex platforms and emerging technologiesReport testing results to senior stakeholders, Board and Audit CommitteeDevelop proposal, project scoping, and the review of deliverablesDrive continuously improvement in security assessment methodologiesDevelop marketing and training materials to help develop staff awareness within the company and communicate KPMG's capabilities to clientsBuild and maintain relationships with existing and prospective clients, and develop / improve your network of business contactsCoach and develop team members through sharing of experience and knowledge

Additional Responsibilities for Associate Director

Drive team built and growth in Hong Kong and GBA regionIdentify business opportunities and work with wider team to generate growthLead business development activities by building propositions, identifying of new target clients, building business relationships with key executives, drive client presentations, speaking at industrial conferencesDevelop internal networks and maintain excellent relationships with colleagues across KPMGPlans, and performance management while contributing to industry and regulatory publications, writing

Experience & Background
Bachelor's degree in computer science, Information Technology, or related field. At least one professionally qualification required: CREST Certified Simulated Attack Manager, GXPN, OSCE3, OSEE or other relevant qualifications• Minimum of 5 years of experience working in Red Teaming, Purple Teaming, simulation attack, iCAST, Web/Mobile/Network/OT/IoT/other Penetration Tests, Vulnerability Assessment, Source Code Review, Appliance/System/Cloud Configuration Review, Malware development, Social Engineering. Strong knowledge in threat intelligence, reverse engineering, security products, incident response, SOC operation or other related areas will be an advantage• Delivered projects in accordance with industry recognised testing standards and experience in common red teaming tools• Strong knowledge base in enterprise technologies and operations, enterprise networking, internet application security, database security evaluation and architecture, with self-motivated learning ability• Be able to lead a team• Have strong analytical, problem solving and inter -personal skills• Commands excellent written and oral communication skills with the ability to present ideas and results to technical and non-technical audiences. Possess a recognised Degree in Computer Science, Cyber Security, Computer/Information Engineering,Information Technology or a related discipline (STEM) is preferred• Excellent written and verbal communication skills in English and Chinese (Mandarin or Cantonese)

Benefits we offer:

KPMG is looking for someone who is passionate about helping our clients with their cyber security challenges. In return, we are helping you to develop your skills and career within the KPMG network.
Well-structured career development and learning path, 1-to-1 coaching by our cybersecurity partnersAccess to various cyber security learning resourcesWide exposure to working with leading financial institutions and multi-national corporationsContinuous sponsorship and support on professional certificate development ( Offensive Security, GIAC, CREST, etc.)Opportunities to attend overseas Cyber Events - such as KPMG HackNet / BlackHatWork in a passionate team with blended cybersecurity talents

About KPMG

At KPMG China, we are committed to being an equal opportunity employer, with zero tolerance for any form of discrimination against any persons. It is important for us to create an inclusive, diverse and agile workplace for our people to develop and thrive at both a personal and professional level.

We strive to make ESG (environmental, social and governance) a watermark running through our organisation; from empowering our people to become agents of positive change, to providing better solutions and services to our clients to help them achieve their ESG goals. View Our Impact Plan to learn more about our ESG commitments and progress across four key pillars - Governance, People, Planet and Prosperity - and how we make a positive impact on our people, environment and society.

We encourage you to come as you are, and we welcome all qualified candidates to apply, and hope you unlock opportunities with us. Visit KPMG China website for more company information.

You acknowledge and agree that all personal information hereby provided regarding yourself will be used by KPMG China for its candidate selection purposed only. KPMG China collects, uses, processes, and retains your personal information in accordance with KPMG China's Online Privacy Statement and/or KPMG China Privacy Statement (collectively "Privacy Statement"). During the recruitment process, KPMG China may need to store personal information of candidates in a designated third-party application tracking platform.

If you have any questions regarding the information you provided in the form or your job application in general, please contact KPMG China's HR personnel in the location where your application is submitted [see here].

  • Hong Kong, Hong Kong SAR China Hip Hing Construction Ltd Full time

    Job Duties Reporting to the IT Manager, the candidate is responsible for leading cybersecurity projects, performing security assessments, and developing and implementing security solutions. Lead cybersecurity projects from start to finish. Perform security assessments and identify vulnerabilities. Design and implement security solutions to protect...


  • Hong Kong, Hong Kong SAR China KPMG China Full time

    Service Line Overview KPMG China has experienced forensic resources based in Beijing, Shanghai and Hong Kong. We provide clients with commercial and financial expertise in the areas of Anti-money Laundering/ Counter Terrorist Financing and Sanctions Compliance Services, Fraud Risk Management, Forensic Technology, Investigations, Cyber Response and Forensic...


  • Hong Kong, Central and Western District, Hong Kong SAR China Zurich Insurance Company Ltd. Full time

    Job AccountabilitiesMaintain knowledge of latest cyber threats and industry best practices Identify relevant threats, assess risk and generate technical & non-technical reports for a variety of stakeholders Perform external and internal threat discovery, define and categorize the threat, characterize the risk posed to Zurich information systems, assess the...


  • Hong Kong, Hong Kong SAR China KPMG China Full time

    KPMG China provides multidisciplinary services from audit and tax to advisory, with a strong focus on serving our clients' needs and their industries. Not only do we have an overriding commitment to provide the highest quality services for our clients, but we also strive to become a responsible corporate citizen that has a positive impact on our environment...


  • Hong Kong, Hong Kong SAR China Zurich Insurance Company Full time

    Job Accountabilities Maintain knowledge of latest cyber threats and industry best practices Identify relevant threats, assess risk and generate technical & non-technical reports for a variety of stakeholders Perform external and internal threat discovery, define and categorize the threat, characterize the risk posed to Zurich information systems,...


  • Hong Kong, Hong Kong SAR China Wizlynx Group Full time

    About us At wizlynx group, we're on a mission to fortify the digital defense of our clients by staying one step ahead of cyber threats. As a Red Team Specialist, you'll play a pivotal role in our cybersecurity team, focusing on emulating threat actors to assess and enhance the security of enterprise networks. Your mission: to penetrate, identify...


  • Hong Kong, Hong Kong SAR China KPMG China Full time

    KPMG China provides multidisciplinary services from audit and tax to advisory, with a strong focus on serving our clients' needs and their industries. Not only do we have an overriding commitment to provide the highest quality services for our clients, but we also strive to become a responsible corporate citizen that has a positive impact on our environment...


  • Hong Kong, Hong Kong SAR China Zurich Insurance Company Full time

    Job Summary With the nature of Cybersecurity evolving so rapidly, Zurich Commercial Insurance is searching for an experienced Cyber risk specialist to further strengthen Zurich’s capability with regards to Cyber insurance, Cyber risk advisory and Cyber services for businesses. This role will be part of our global Zurich Resilience Solutions (ZRS)...


  • Hong Kong, Central and Western District, Hong Kong SAR China Zurich Insurance Company Ltd. Full time

    Job Summary With the nature of Cybersecurity evolving so rapidly, Zurich Commercial Insurance is searching for an experienced Cyber risk specialist to further strengthen Zurich's capability with regards to Cyber insurance, Cyber risk advisory and Cyber services for businesses. This role will be part of our global Zurich Resilience Solutions (ZRS) advisory...

  • IT Project Manager

    3 weeks ago


    Hong Kong, Hong Kong SAR China AXA Group Full time

    We are looking for a talented IT Security Portfolio Manager, with good IT (cloud, applications, Security) security knowledge, motivated by challenges and looking for developing his/her career in a dynamic organization. This is an exciting opportunity to drive both the strategic direction of the cyber capability, as well as get close to the technology and...


  • Hong Kong, Hong Kong SAR China Joint Electronic Teller Services Limited Full time

    RESPONSIBILITIES Lead and manage Information Security initiatives; Maintain and drive comprehensive information security programme, deliver security strategy, policies, procedures, communications and training;  Responsible for direct client-facing engagement in the banking sector related to information security domain and initiatives; Stay...


  • Hong Kong, Hong Kong SAR China Wizlynx Group Full time

    Key Role As (Senior) Cyber Security Consultant & Penetration Tester, you will execute a variety of engagements, conducting advanced hands-on penetration testing beyond automated tool validation, which will focus on targets that may include network devices, servers, web and mobile apps, web APIs, wireless infrastructures, IoT devices, and other...

  • Product Analyst

    2 weeks ago


    Hong Kong, Hong Kong SAR China HSBC Full time

    Some careers have more impact than others. If you’re looking for a career where you can make a real impression, join HSBC and discover how valued you’ll be. Whether you want a career that could take you to the top, or simply take you in an exciting new direction, HSBC offers opportunities, support and rewards that will take you further. Securities...


  • Hong Kong, Hong Kong SAR China Wing Lung Bank Ltd. Full time

    Senior Security Engineer Responsibilities Acting as a first line defence on the Information and Cyber security matters Assisting in security solution selection, evaluation and implementation based on the procedures and guidelines of the Bank Performing security operation matters including key management, privileged account management,...


  • Hong Kong, Hong Kong SAR China AIA Full time

    FIND YOUR 'BETTER' AT Blue Cross If you believe in better, we’d love to hear from you. About the Role Responsible for ensuring the security and integrity of AIA's information systems and cyber environment Duties/Accountabilities Assist information security and cyber security risk assessment on security initiatives, compliance and improvements ...


  • Hong Kong, Hong Kong SAR China Crypto.com Full time

    The Cybersecurity and Data Privacy team reports directly under the office of the CISO headed by Chief Information Security Officer (CISO) Jason Lau () who has over 23+ years of experience in the cybersecurity space, awarded Global Top 100 CISO, and also serves on the World Economic Forum, International Association of Privacy Professionals and more. The team...


  • Hong Kong, Hong Kong SAR China Société Générale Assurances Full time

    Regional Cyber Governance Risk and Compliance Officer Permanent contract|Hong Kong|IT (Information Technology) Regional Cyber Governance Risk and Compliance Officer Hong Kong, Hong Kong Permanent contract IT (Information Technology) Responsibilities The Regional Cyber Governance, Risk, and Compliance (GRC) Officer is responsible...

  • Senior Associate

    1 week ago


    Hong Kong, Hong Kong SAR China Maxim Recruitment Ltd Full time

    Our client, an international consultancy with an office in Hong Kong, is looking to appoint an experienced Architect to take on the role of the Associate Director.


  • Hong Kong, Hong Kong SAR China China Life Franklin Asset Management Full time

    We are looking for an all-round caliber with 3+ years’ experience to assist in the IT function of the Operation Team – Your primary role is to maintain network, system and data security for the firm. Job responsibility - Engineer, implement and monitor security measures for the protection of IT systems, networks, and information. - Responding to...


  • Hong Kong, Hong Kong SAR China Sopra Steria I2S Full time

    Sopra Steria is a listed European tech leader specializes in Consulting, Digital Service, and Software. We have 50,000 employees worldwide located in different regions (Europe, North America and Asia), whereby Singapore is the HQ for APAC. EvaGroup Asia Pacific is part of Sopra Steria I2S APAC, in charge of Infrastructure, Cloud and Cybersecurity...