Associate Director/Senior Manager, Information Risk Management

7 days ago


WorkFromHome, Hong Kong SAR China Manulife Full time

Position Responsibilities Security Testing: Execute security testing using methodologies such as SAST, SCA, and DAST to identify vulnerabilities. Leverage tools like Snyk for open-source dependency and container image security Information Risk Assessments: Conduct risk assessments for IT initiatives prior to go-live, review release evidence, and ensure compliance with internal and industry standards Third-Party Risk Management: Oversee vendor onboarding and governance, ensuring procurement aligns with security requirements and contractual clauses Vulnerability Management: Apply OWASP Top 10 and NIST guidelines to prevent common vulnerabilities such as injection flaws and broken access controls Secure Development: Embed security practices into SDLC and DevOps workflows, ensuring integration with CI/CD pipelines and version control systems Cloud Security: Assess and validate security controls for cloud platforms (e.g., Microsoft Azure, Alibaba Cloud) and cloud-native services such as Kubernetes and microservices GenAI Security Evaluation: Evaluate security risks in Generative AI projects, ensuring responsible use and compliance with data privacy and integrity standards Communication & Compliance: Translate technical risks into actionable insights for technical and non-technical stakeholders, including presenting security concerns and posture to all levels—from developers to senior executives, and providing regular updates to C-level leadership. Reviewing penetration testing reports and automated scans (Snyk, GitGuardian). Developing automated security reports using Power BI, Python, or Power Automate. Leading security audits and implementing remediation plans. Acting as product owner for enterprise SCA & SAST solutions, driving migration strategies and improving DevSecOps maturity. Managing penetration testing programs and refining methodologies based on stakeholder feedback. Enhancing AppSec risk metrics for accurate visualization and remediation guidance. Required Qualifications Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience) Proven experience in information security and compliance monitoring, preferably in cloud environments Strong analytical skills and ability to interpret complex security reports. Familiarity with penetration testing and DevOps tools (BurpSuite, Snyk, GitHub, GitGuardian) Knowledge of OWASP trends and Generative AI risk considerations Programming proficiency in Python or experience with Microsoft Power Automate Experience with Power BI or similar visualization tools Excellent communication and collaboration skills Relevant certifications (CISSP, CISM, CEH) preferred Understanding of IT control frameworks and regulatory requirements (ISO 27001, NIST, COBIT, PDPO, GDPR) When You Join Our Team We’ll empower you to learn and grow the career you want. We’ll recognize and support you in a flexible environment where well-being and inclusion are more than just words. As part of our global team, we’ll support you in shaping the future you want to see. About Manulife And John Hancock Manulife Financial Corporation is a leading international financial services provider, helping people make their decisions easier and lives better. To learn more about us, visit Manulife is an Equal Opportunity Employer At Manulife/John Hancock, we embrace our diversity. We strive to attract, develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals. We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy and pregnancy-related conditions), sexual orientation, genetic characteristics, veteran status, gender identity, gender expression, age, marital status, family status, disability, or any other ground protected by applicable law. It is our priority to remove barriers to provide equal access to employment. A Human Resources representative will work with applicants who request a reasonable accommodation during the application process. All information shared during the accommodation request process will be stored and used in a manner that is consistent with applicable laws and Manulife/John Hancock policies. To request a reasonable accommodation in the application process, contact Working Arrangement Hybrid Seniority level Mid-Senior level Employment type Full-time Job function Other Industries Insurance Referrals increase your chances of interviewing at Manulife by 2x Get notified about new Information Risk Manager jobs in Hong Kong, Hong Kong SAR . #J-18808-Ljbffr



  • WorkFromHome, Hong Kong SAR China Manulife Full time

    Director/ Associate Director, Group Operations Transformation Join to apply for the Director/ Associate Director, Group Operations Transformation role at Manulife . This position is responsible for the success of strategic outcomes through the direct oversight, leadership and delivery of multi‑year strategic programs aligned with segment goals. The role...

  • Information Risk

    7 days ago


    WorkFromHome, Hong Kong SAR China Manulife Full time

    A leading financial services provider in Hong Kong is looking for an Information Risk Manager. The ideal candidate will execute various security testing methodologies, conduct risk assessments, and manage vendor security compliance. A bachelor’s degree in Computer Science or a related field is required, along with strong analytical and communication...

  • Associate Director

    2 weeks ago


    WorkFromHome, Hong Kong SAR China Manulife Full time

    Associate Director / Senior Manager, Health Proposition Join to apply for the Associate Director / Senior Manager, Health Proposition role at Manulife This is an exciting opportunity to help Manulife become the health partner of choice by redefining the next generation of customer‑centric health insurance propositions. This role will lead the...


  • WorkFromHome, Hong Kong SAR China Manulife Full time

    Records & Information Management (RIM) and Operations Risk & Control Governance This role combines strategic leadership in Records & Information Management (RIM) and Operations Risk & Control Governance across the Asia Segment. The incumbent will be responsible for developing and maintaining a robust RIM program while driving effective risk and control...


  • WorkFromHome, Hong Kong SAR China Standard Chartered Bank (Hong Kong) Ltd Full time

    Associate Director, Country Project Management In this role you will be part of the Hong Kong Programme Delivery Team, in the department Technology and Operations ("T&O"). You will be primarily responsible for the successful delivery of projects and other technology related initiatives to improve system stability and operational resilience in the country....


  • WorkFromHome, Hong Kong SAR China Standard Chartered Full time

    Associate Director, Country Project Management In this role you will be part of the Hong Kong Programme Delivery Team, in the department Technology and Operations (“T&O”). You will be primarily responsible for the successful delivery of projects and other technology related initiatives to improve system stability and operational resilience in the...


  • WorkFromHome, Hong Kong SAR China Standard Chartered Bank (Hong Kong) Ltd Full time

    A major international bank is seeking an Associate Director, Strategy to enhance its strategic agenda. This role requires a strong background in banking consulting and financial services, with at least 5 years of experience. You will work closely with senior leadership to analyse key industry trends and implement strategic initiatives. The candidate should...


  • WorkFromHome, Hong Kong SAR China Canonical Full time

    Join to apply for the Security Risk Management Specialist role at Canonical Join to apply for the Security Risk Management Specialist role at Canonical In security risk management we're looking to harness the power of industry best practice combined with driving new innovation on how we do security risk assessments and modelling. Our security risk management...


  • WorkFromHome, Hong Kong SAR China Standard Chartered Bank (Hong Kong) Ltd Full time

    Associate Director, Strategy (HK, SGP or UK) Add expected salary to your profile for insights This role could be based in UK, Hong Kong or Singapore. When you start the application process you will be presented with a drop‑down menu showing all countries; please ensure that you select a country where the role is based. Structuring issue‑based work plans,...


  • WorkFromHome, Hong Kong SAR China ERM-Hong Kong, Limited Full time

    Consulting Senior Associate, Technical Risk & Safety ERM in Hong Kong is seeking candidates to help grow the business in the field of Process Safety, Data Analysis, Risk and Reliability Assessment and Safety Management with the potential to become one of our top consultants. The successful candidate will provide technical expertise in data analysis, hazard...