Manager, IT Risk

7 days ago


Hong Kong, Central and Western District, Hong Kong SAR China HK Express Full time

Job no: 497740
Work type: Full time
Location: Hong Kong SAR
Department: IT and Digital

HK Express is Hong Kong's first and only low-cost carrier, always offering great value, affordable fares on one of the youngest and most modern aircraft fleets in the world.

Like you, and just like many people across Asia, we love to travel and discover new places across the world's most diverse and dynamic region; and at HK Express, we're opening up new travel experiences that inspire and invigorate millions of people across the region we're proud to call home. Everything we do is focused on encouraging the spirit of adventure. Our routes provide the inspiration and spontaneity to try somewhere new, disrupting monotonous modern life. As we continue to open up new routes, often in secondary and emerging destinations, our passengers will gain access to an incredible range of places, exploring hidden gems and experiencing local cultures.

We have a diverse and vibrant team that embodies the adventurous spirit of our customers, and loves to travel too. Join us in this journey to make your career even more fulfilling and rewarding.

Role Purpose

  • Lead a team of cybersecurity professionals to safeguard IT environment.
  • Conduct a security risk assessment for every new business application initiative and solutions; enhance current practices to mitigate cyber risks and establishment of a risk framework.
  • Support and define IT security framework to guard against security risk.
  • Cross-team collaboration with Security Operations and Security Governance on developing new security testing process to enhance the company's security assurance level.
  • Collaborate with IT and business stakeholders and play a multi-faceted support role to identify any risks or gaps for improvement.
  • Provide information security advisory to business units where required, through participation on advisory engagements.
  • Regular review and approve security guidelines and procedures to strengthen current security framework.
  • Perform threat management, threat modelling, identify threat vectors and develop use cases for security monitoring.
  • Responsible for reviewing security incident reports.
  • Formulate and direct incident response efforts, prioritize those response efforts.
  • Design and conduct a cyber-attack simulation to evaluate the effectiveness of cyber defences across different technology layers.
  • Enhance the company's cybersecurity maturity and situational awareness.
  • Create reports, dashboards, metrics for SOC operations and present to Senior Management.
  • Manage all aspects of outsourced Security Operation Centre.
  • Support 7/24 on-call for emergency support.

Qualifications

  • Bachelor's Degree in computer science or IT-related discipline.
  • Minimum 8 years' working experience, with minimum 3 years hands-on experience in Information Security, Internal Control or Operations Risk.
  • Experience in Security Operations, SOC, SIEM, Incident Response, and Threat Intelligence is preferred.
  • Experience in Penetration testing and common vulnerability assessment tools, as well as, using MITRE ATT&CK or similar frameworks.
  • Passion for cybersecurity and staying up to date with current threats, tools and techniques.
  • Familiar with various IT governance frameworks such as CobiT, PCI-DSS, NIST, ISO27001, ISO20000, ITIL.
  • Practical experience of technical and security configuration, operation and administration in Windows OS, Active Directory, Intune Policy, Networking, security devices (firewall, NAS, etc.) are essential.
  • Knowledge of Cloud environments such as AWS, AliCloud, Azure and GCP.
  • Possess CISSP, CISA, CISM or other information systems security certifications preferred.
  • Ability to communicate about various IT security measures with a non-technical audience.
  • Demonstrated ability to prioritize and meet scheduled deliverables and commitments while managing multiple tasks.
  • Good command of written and spoken English & Chinese.
  • Good analytical and problem-solving skills with strong self-motivation.
  • Proven ability to coach team members.
  • Excellent communication skills in English and Chinese (Cantonese and Mandarin), both written and verbal.
  • Able to work under pressure and meet tight work schedules.
  • Working knowledge and experience with M365.

Your Future Work Life

  • Fly anywhere we fly for free with your friends and family to explore the world.
  • Hybrid working with flexibility in workplace and working hours to foster work-life harmony.
  • Open office to collaborate, connect and share great ideas.
  • Energetic and multicultural teammates from up to 50 nationalities
  • Company-organized shuttle buses connecting the workplace with major locations in the HK Island, Kowloon and N.T.

Advertised: 17 Feb 2025 Hong Kong Standard Time
Applications close:

#J-18808-Ljbffr
  • Risk Manager

    4 weeks ago


    Hong Kong, Central and Western District, Hong Kong SAR China ConnectedGroup Limited Full time

    Our client is one of the well performed companies in the financial service. They are currently seeking a skilled Tech Risk Manager to join our team. This role will focus on enhancing our risk management framework, specifically within the 1st and 1.5 lines of defense. The ideal candidate will possess a strong technical background, excellent analytical skills,...

  • Risk Manager

    5 days ago


    Hong Kong, Central and Western District, Hong Kong SAR China Bond West Consultants Full time

    2 days ago Be among the first 25 applicants Direct message the job poster from Bond West Consultants Professional Recruiter / / 2957 8166 Our client, a listed company is now looking for a high caliber candidate for the following position: Responsibilities: Working with different risk stakeholders to develop and maintain the Enterprise Risk Management...

  • Risk Manager

    4 days ago


    Hong Kong, Central and Western District, Hong Kong SAR China ConnectedGroup Limited Full time

    Our client is a multi-funder platform providing digital solutions and services to Multinational Corporations around the globe. They are now looking for a Risk Underwriting experts to lead the risk management process implementation and streamlining. Key ResponsibilitiesSupport to establish overall firmwide credit risk management framework and on-going monitor...


  • Hong Kong, Central and Western District, Hong Kong SAR China The Profile Group (HK) Ltd (a Wilson Company) Full time

    Responsibilities: Maintain the operational risk management framework for the organization Support the development and implementation of risk management policies and procedures Maintain operational risk documentation and procedures Assist in implementing risk mitigation strategies Monitor key risk indicators and risk metrics Assist in identifying potential...


  • Hong Kong, Central and Western District, Hong Kong SAR China Bond West Consultants Full time

    Job OverviewBond West Consultants is seeking a high-caliber Risk Manager to join their team.Key Responsibilities:Develop and maintain the Enterprise Risk Management Framework, including its infrastructure, and conduct research on specific risk issues.Maintain the risk register and develop/managing an analytical framework.Develop and compile any...


  • Hong Kong, Central and Western District, Hong Kong SAR China Bond West Consultants Full time

    Job Summary:We are seeking an experienced Compliance and Risk Manager to join our team at Bond West Consultants.In this role, you will be responsible for maintaining the company's risk management framework and conducting research on specific risk issues.You will work closely with various stakeholders to ensure that our risk management practices are aligned...


  • Hong Kong, Central and Western District, Hong Kong SAR China The Asian Banker Full time

    Job OverviewThe Asian Banker is seeking a seasoned risk management professional to lead our market and liquidity risk management efforts. This role requires a strategic thinker with expertise in market risk, liquidity risk, and risk governance.Key ResponsibilitiesLead Market and Liquidity Risk Management: Develop and implement effective risk management...


  • Hong Kong, Central and Western District, Hong Kong SAR China DBS Bank (Hong Kong) Limited Full time

    Business Function Risk Management Group (RMG) is responsible for the development and maintenance of risk management and internal control frameworks. We provide independent review and challenge to business to ensure that appropriate balance is considered in risk/return decisions. In addition, RMG is responsible for the monitoring and reporting on key risk...


  • Hong Kong, Central and Western District, Hong Kong SAR China CITIC CLSA Full time

    Job Summary:CITIC CLSA is seeking a seasoned Market Risk Manager to lead our FICC trading desk risk management efforts. As a key member of our team, you will be responsible for monitoring and managing risk limits, producing risk reports, and collaborating with various stakeholders to identify and mitigate risks.About Us:CITIC CLSA is a leading investment...


  • Hong Kong, Central and Western District, Hong Kong SAR China KOS International Limited Full time

    About KOS International LimitedWe are a renowned conglomerate seeking a seasoned Risk Management Lead to spearhead the establishment and enhancement of our Enterprise Risk Management (ERM) framework for our investment portfolio.Role OverviewThis role involves identifying and evaluating risks associated with our investment portfolio, encompassing market,...


  • Hong Kong, Central and Western District, Hong Kong SAR China Bond West Consultants Full time

    Job DescriptionWe are seeking a high-caliber Risk Management Expert to join our team at Bond West Consultants. In this role, you will work closely with various risk stakeholders to develop and maintain the Enterprise Risk Management Framework. Your responsibilities will include conducting research on specific risk issues, maintaining the risk register, and...


  • Hong Kong, Central and Western District, Hong Kong SAR China Hang Seng Bank Limited Full time

    About Hang Seng BankHang Seng Bank Limited is a leading financial institution in Hong Kong, committed to delivering service excellence and creating value for our customers. Our people are our most important asset, and we strive to attract high-calibre talent by offering a dynamic working environment, good career development opportunities, and competitive...


  • Hong Kong, Central and Western District, Hong Kong SAR China The Profile Group (HK) Ltd (a Wilson Company) Full time

    Responsibilities: Maintain the risk management framework in line with the firm's and local policies and procedures Lead the identification, communication, measurement, and management of office-wide risks Conduct regular risk assessments to identify current and emerging risks Monitor and record operational incidents Evaluate, recommend, and implement...


  • Hong Kong, Central and Western District, Hong Kong SAR China Hong Kong Exchanges and Clearing Limited Full time

    Company OverviewHong Kong Exchanges and Clearing Limited (HKEX) is a global leader in securities, derivatives, and commodities trading. As a purpose-driven company, our mission is to connect, promote, and progress our markets and the communities they support for the prosperity of all.Job SummaryThe Quantitative Risk Management team at HKEX is seeking a...


  • Hong Kong, Central and Western District, Hong Kong SAR China Ashford Benjamin Ltd Full time

    Responsibilities:Monitor risk-related solutions for the platform's crypto asset trading products, focusing on market risk and portfolio risk. Identify potential market risks, analyze performance and suggest optimizations to risk control parameters to minimize losses from abnormal events, including but not limited to hit rate, liquidity, concentration,...


  • Hong Kong, Central and Western District, Hong Kong SAR China SGS Société Générale de Surveillance SA Full time

    Job DescriptionThe Compliance Risk Manager will play a critical role in ensuring the bank's compliance with regulatory requirements and internal policies. This involves developing and implementing effective risk management strategies to mitigate potential risks and ensure the bank's operations are aligned with best practices.Key Responsibilities:Develop and...


  • Hong Kong, Central and Western District, Hong Kong SAR China Hang Seng Bank Limited Full time

    Job description A Career with Hang Seng Bank Hang Seng is committed to service excellence. Our people are our most important asset and play a vital role in our efforts to continually enhance our performance for customers and provide best-in-class products and services. We seek to attract high-calibre talent by offering a dynamic working environment, good...


  • Hong Kong, Central and Western District, Hong Kong SAR China Marks Sattin Full time

    Are you a seasoned professional looking for a new challenge in the field of quantitative risk management? Do you have a passion for analyzing complex financial data and developing innovative risk analysis tools?We are seeking a highly skilled and motivated Quantitative Risk Consultant to join our team at Marks Sattin. Working closely with a Senior Risk...


  • Hong Kong, Central and Western District, Hong Kong SAR China China Construction Bank (Asia) Corporation Limited Full time

    About UsChina Construction Bank (Asia) Corporation Limited is a leading financial institution dedicated to serving our customers and contributing to the growth of the region.Role OverviewWe are seeking a skilled Climate Risk Management Professional to join our team. As a key member, you will play a crucial role in managing our Climate Risk exposure and...


  • Hong Kong, Central and Western District, Hong Kong SAR China PrimePeak Group Full time

    Cyber Security Director OpportunityAt PrimePeak Group, we are seeking an experienced Cyber Security Director to lead our technology risk management efforts. This critical role ensures the alignment of our IT infrastructure, cybersecurity frameworks, and digital transformation initiatives with regulatory standards and best practices.Key...