Senior/Junior Information Security Consultant

5 days ago


Hong Kong Island, Hong Kong SAR China wizlynx group Full time

Senior/Junior Information Security Consultant (Governance, Risk and Compliance) Location: Hong Kong Job Summary and Mission This position contributes to the success of wizlynx group by performing the following: Responsible for development and operational activities across the entire scope of our clients Security Governance, Risk and Compliance programs. The job encompasses leading and participating in the assessment of security, risks, and control effectiveness for applications, infrastructure, and technology projects. The Specialist will identify, classify, and document control issues in our clients computing environment by documenting assessment results, recommending corrective action, tracking remediation, evaluating policy and control standard exceptions, and regularly reporting to our clients IT management. Serve as the primary contact point for issue escalation. Manage service support requirements and ensure that quality plan, KPIs/SLAs are met. Draft support SOP and documentation. Models and acts in accordance with wizlynx group guiding principles. With this position, you will also have the opportunity to get introduced to different areas of information and cyber security such as Offensive Security & Penetration Testing. Summary of Key Responsibilities Leads IT control assessments for our clients to ensure effective IT controls are in place to meet operational and compliance requirements. Works with our clients IT, Internal Audit, Compliance and other key stakeholders to create an IT GRC strategy that complies with professional standards and addresses the IT risks inherent in our client’s operations and industry. Develops Vendor Risk Management policies and supports client’s risk profile assessment for vendor onboarding process and conducts annual review of critical vendors. Performs ongoing logical access reviews and recommends updates to access control privileges to ensure proper Segregation of Duties based on user access reviews. Effectively reports and communicates testing results to client’s IT management for corrective action, where required. Conducts information security awareness training. Performs evidence collection and project management assistance of our clients annual compliance (e.g. CREST, PCI DSS) certification program. Track and monitor risk exceptions to ensure control deviations are identified and mitigating controls are in place. Assist our clients with drafting and maintaining information security policies. Provides mentoring for other team members. Demonstrates excellent project management skills, inspires teamwork and responsibility with engagement team members, and uses current technology/tools to enhance the effectiveness of deliverables and services. Facilitates the performance and testing of our client’s annual disaster recovery tests and business continuity plans. Summary of Ideal Experience, Skills, Knowledge, and Abilities Ideal Experience a) Senior GRC role: A minimum of five years of experience in information security audit or in a technology-related audit or compliance field, and strong knowledge base in operations, enterprise networking, system evaluation/architecture and consulting experience preferred. b) Junior GRC role: One to two years of experience in information security audit or in a technology-related audit or compliance field, and strong knowledge base in operations, enterprise networking, system evaluation/architecture and consulting experience preferred. Strong understanding of and ability to provide security configuration and testing of networking and operating systems including TCP/IP, WAN/LAN routing, VLAN architecture, and a wide array of large-scale environments including various major web application servers. Strong understanding of information security principles such as ISO 27001, HKMA CFI, CRAF, HK SFC, HKIA Guideline on Cybersecurity (GL20), PCI-DSS, PDPO, and other regulatory compliance. Language Skills Fluent technical English (speech and writing). Ability to communicate clearly and concisely, both orally and in writing, in local language. Soft Skills Excellent team leadership, team oriented and team player who takes ownership. Flexible attitude, reliable, action oriented. Customer friendly approach and appearance. Willingness to travel. Innovative to push new ideas, dynamic and forward looking with clear management principle towards the team. Able to work independently, critical thinking and be able to communicate effectively with the support team and customers. Enjoys working in global team with different cultures. Technical Skills and Abilities Microsoft OS and Office knowledge. Technical document writing. Experience in Project Management in IT. Knowledge in perimeter firewall infrastructure and VPN remote access. Summary of Education Bachelor's degree from an accredited college/university in an appropriate field. Certifications / Training CISM, CISA, CRISC, CISSP certified. KEY PERFORMANCE INDICATORS / MEASURES OF SUCCESS Achieve agreed targets/SLA/KPI in terms of quality, time and cost. Lead team members to achieve team/organizational goals. Improve and retain high customer satisfaction. POTENTIAL CAREER DEVELOPMENT Advance to higher business development tiers or geographic reach. APPLY NOW Your Full Name Your Email Upload Resume I grant wizlynx group my consent to the processing of my personal information for the job application purposes. #J-18808-Ljbffr


  • Security Consultant

    2 weeks ago


    Hong Kong Island, Hong Kong SAR China Pentastic Security Limited Full time

    ️‍♂️ Join Our Team at Pentastic Security Limited as a SECURITY CONSULTANT! Are you passionate about cybersecurity and eager to develop a career in this dynamic field? Pentastic Security is looking for dedicated individuals to join our expanding team as Security Consultant. If you're ready to embark on an exciting journey in Cybersecurity, we want to...

  • Security Consultant

    2 weeks ago


    Hong Kong Island, Hong Kong SAR China Security Research Labs Full time

    About us: SRLabs is home to knowledge leaders securing critical infrastructures in finance, energy, and telecommunications. We focus on hands-on hacking resilience – not compliance –, which we shape by combining our hacking research with impactful consulting work for innovation leaders that have a natural thrive for cutting‑edge technologies.We come...


  • Hong Kong Island, Hong Kong SAR China NTT Full time

    Job Responsibilities Assists in conducting security assessments, vulnerability scans, and penetration tests to identify weaknesses in client systems. Analyzes security data, logs, and reports to detect and investigate security incidents or anomalies. Prepares and maintains documentation, including security assessment reports, findings, and recommendations....


  • hong kong, Hong Kong SAR China ioTech Solutions Full time

    IT Security Specialist - Junior to Senior levels Job Description: My client, a leader in Hong Kong's financial services sector is seeking an experienced Security Engineer to join as a IT Security Specialist and support the firms cybersecurity ecosystem including data protection, identity, access management, solution implementation, but not limited to. Key...


  • hong kong, Hong Kong SAR China Evolution Security Consulting Limited Full time

    A global information security consultancy is seeking a talented Senior Consultant/Auditor to join their Security Audit and Compliance team in Hong Kong. The ideal candidate will possess a strong background in IT security consultancy and auditing, with at least 2 years of relevant experience. Responsibilities include delivering security risk assessments,...


  • hong kong, Hong Kong SAR China Ambition Full time

    Senior Consultant | Recruiting Talents In Technology Sector | Information Technology | Cyber Security | Infrastructure | Software Development | Data… Central & Western District, Hong Kong SAR Job Responsibilities Implement and manage information protection tools including Data Loss Prevention (DLP) with policies enforcement, detection rules fine-tuning and...

  • Senior Consultant

    2 weeks ago


    Hong Kong Island, Hong Kong SAR China Evolution Security Consulting Limited Full time

    Senior Consultant / Auditor (Cybersecurity / SRAA) Evolution Security Consulting, a global information security consultation firm, is seeking a talented candidate to join our Security Audit and Compliance team. The ideal candidate will have a strong background in IT security consultancy and/or audit, and be able to work with global and regional clients...


  • Hong Kong Island, Hong Kong SAR China Second Talent Full time

    A leading international law firm with a strong Asia‑Pacific presence is looking for an experienced Information Security Engineer to join its regional IT Security team in Hong Kong. Senior Information Security Engineer – Global Law Firm (Hong Kong) A leading international law firm with a strong Asia‑Pacific presence is looking for an experienced...


  • Hong Kong Island, Hong Kong SAR China Security Research Labs Full time

    A leading cybersecurity company in Hong Kong is looking for a Security Consultant to drive security evolution through ethical hacking, research, and consulting. The role involves providing security consulting services, conducting penetration testing, and collaborating with teams to solve complex IT security challenges. Ideal candidates have over four years...


  • Hong Kong Island, Hong Kong SAR China SmartHire by SEEK Full time

    Senior Security Consultant / Security Consultant Our client "HGC Global Communications Limited (HGC)" is seeking a Senior Security Consultant to join their team! What you’ll be doing? Master security technologies: Develop extensive expertise in installing, configuring, and managing network security products such as Firewalls, Application Security, and...