Hong Kong [Change Country] Hong Kong JobsHong Kong Information Technology (IT) JobsHong Kong IT Management Jobs Employers / Post Job
[ Log On ]

Senior Manager - Cyber Security - Risk Assurance - HK


  • Company Industries:Accounting / Audit / Tax Services

Job Information

  • Post Date:2018-12-24
  • Career Level:Senior
  • Location:Not Specified
  • Yr(s) of Exp:8 years
  • Qualification:Degree
  • Salary:Salary provided
  • Employment Type:Full Time
  • Job Function:IT Project Management / Team Lead  IT Management  Security  

Job Description

Key responsibilities include:

  • Designing and conducting cyber-attack simulation to evaluate the effectiveness of cyber defences across different technology layers, such as network, operating systems, applications,devices, database and process. In addition, such simulation would also cover “People” aspect such as evaluating their cybersecurity maturity and situational awareness;
  • Designing, assessing and implementing technology risk and cyber security management framework, policies, standards, procedures and solutions such as Enterprise-wide Identity & Access Management (IAM),  Privileged Access Management (PAM), Endpoitn Protection, Data Loss Prevention (DLP), Security Information & Event Management (SIEM) / Security Analytics & Intelligence, and other solutions; integrate 3rd party services such as Threat Intelligence and Managed Security Services; help our clients build / transform Security Operations Centers (SOC); etc., and, using NIST, ISO27001, ISO20000 and CoBIT and other internationally recognized cyber security and IT service management standards;
  • Supporting project management or managing hands-on complex systems integration projects involving multiple vendors, team members and client staff;
  • Analyzing complex client server systems and multi-platform infrastructure and application systems (including operating system, database, web server, firewall and router, electronic trading / banking systems, etc.);
  • Providing assurance over the operations and approach of management service providers in any outsourcing of the IT function;
  • Establishing risk governance recommendations on emerging policies to support development of new procedures and methodologies to minimize risks;
  • Conveying pragmatic solutions to our client's complex business problems through the use of written reports and presentations;
  • Supervising, coaching, developing and leading teams and individual team members;
  • You will be expected to take a consultative approach to the attest / assurance process of a client's operations utilising our practice methodology to assess our client's operations. 



  • University degree majoring in information security, information systems,  computer science, engineering, accounting, business administrationstatistics;
  • Professional qualifications:  CISA, CISM, CISSP, CEH, CISP, GWAPT, OSCP, OSCE, GPEN, GXPN, or other security related qualifications (including certifications issued by CREST);
  • System design / implementation and / or security assessment / IT audit experience with a reputable professional / consulting firm or multi-national corporations; (Candidate with less years of experience will be considered for Senior Associate or Associate positions);
  • Practical experience and working knowledge in two or more of the following - business & system processes review, IT auditing, cyber security management, IT / technology risk management, design and implementation of security solutions such as IAM, DLP, PAM and SIEM/SOC, network and system penetration testing, application security testing and code review;
  • Hands-on security operations, threat intelligence, incident response, malware reverse engineering and other related experience would be beneficial;
  • Familiar with security and control for technologies / enterprise applications: Unix, Windows, Firewall, Routers, SAP, Oracle, Hyperion and/ or evaluating and implementing cyber security management, IT service management and IT governance framework using NIST, ISO27001, ISO20000, ITIL and COBIT respectively;
  • Strong fluency in information technology general controls concepts in the areas of systems development, change management, computer operations and access to programs and data; ability to identify and assess business process controls and linkage to IT systems;
  • Familiar with security and control for technologies: Unix, Windows, database, Firewall, Router, mobile technologies (e.g., iOS, Android), etc.;
  • Excellent communication skills in both oral and written English and Chinese;
  • Flexible, self-starter possessing intellectual curiosity;
  • Ability to interact with executive levels of client and firm management;
  • Effective project management, interpersonal and influencing skills are essential;
  • Flexibility to travel to out-of-town engagements. 


Company Info

PwC - Mainland China, Hong Kong and Macau

PwC ChinaHong Kong and Macau work together on a collaborative basis, subject to local applicable laws. Collectively, we have over 600 partners and over 17,000 people in total. 
We provide organisations with the professional service they need, wherever they may be located. Our highly qualified, experienced professionals listen to different points of view to help organisations solve their business issues and identify and maximise the opportunities they seek. Our industry specialisation allows us to help co-create solutions with our clients for their sector of interest.
We are located in these cities: Beijing, Shanghai, Hong Kong, Shenyang, Tianjin, Dalian, Jinan, Qingdao, Zhengzhou, Xi’an, Nanjing, Hefei, Suzhou, Wuhan, Chengdu, Hangzhou, Ningbo, Chongqing, Changsha, Kunming, Xiamen, Guangzhou, Shenzhen, Macau, Haikou.

Position Company Location Update