← Back to job listings
1C
Deputy Head of Information Security, IT
1899 CITIC Securities International Company Limited · Hong Kong
About The Role
Position Description
The Deputy Head of Information Security will be based in Hong Kong and report directly to the Head of Information Security. The role is responsible for leading and managing cybersecurity and data security governance, risk management, compliance, security operations, and strategic security initiatives across CSI. The successful candidate will play a key leadership role in protecting the organization's information assets, ensuring regulatory compliance, and strengthening cyber resilience while enabling business growth and innovation.
Key Areas of Responsibilities
Governance, Strategy and Risk Management
- Lead the development, maintenance, and continuous enhancement of CSI's cybersecurity and data security strategies, frameworks, policies, standards, and procedures.
- Establish, implement, and enforce an enterprise-wide governance framework covering data management, data lifecycle management, data protection, and data loss prevention.
- Identify, assess, prioritize, and report cybersecurity and data security risks, and drive effective risk mitigation strategies.
- Provide regular cybersecurity risk, governance, and compliance reporting to senior management and relevant governance committees.
- Establish and maintain cloud security governance frameworks supporting CSI's multi-cloud strategy across AWS, Azure, and Alibaba Cloud.
Regulatory Compliance and Audit
- Ensure CSI's infrastructure, systems, and applications comply with applicable laws, regulations, and industry standards, including ISO 27001, NIST, GDPR, PDPO, PIPL, MAS, and other relevant regulatory requirements.
- Maintain audit readiness and coordinate responses to regulatory examinations, compliance assessments, internal and external audits, client security questionnaires, and due diligence reviews.
- Act as a key security liaison with regulators, auditors, compliance teams, and external stakeholders.
Security Operations and Cyber Resilience
- Oversee Security Operations Centre (SOC) activities, threat monitoring, incident management, and Level 2 support for security technologies.
- Govern CSI's vulnerability management program in collaboration with Application, Platform, and Infrastructure teams.
Security Architecture and Technology Oversight
- Provide security oversight for enterprise architecture, cloud adoption, application security, infrastructure security, and technology transformation initiatives.
- Ensure security controls and monitoring capabilities are appropriately designed and implemented across on-premises and cloud environments.
- Evaluate emerging technologies and cybersecurity threats, providing recommendations to strengthen CSI's security posture.
Third-Party Risk Management
- Oversee third-party cybersecurity risk management processes and security assessments for vendors, service providers, and outsourcing arrangements.
- Ensure appropriate security controls and contractual requirements are embedded in third-party engagements.
Security Awareness and Stakeholder Management
- Oversee enterprise-wide security awareness, education, and training programs to strengthen the organization's security culture.
- Build strong relationships with business, technology, risk, compliance, legal, and operational stakeholders.
- Drive cross-functional initiatives to deliver secure, resilient, and compliant technology services.
Leadership and Team Management
- Support the Head of Information Security in developing and executing the overall security strategy and roadmap.
- Mentor, coach, and develop cybersecurity professionals and foster a high-performance security culture.
- Manage the information security project portfolio and ensure effective delivery of cybersecurity initiatives.
- Lead cybersecurity incident response, investigation, recovery, and lessons-learned activities.
- Ensure cyber resilience, disaster recovery, and business continuity capabilities are established, maintained, and regularly tested.
- Lead and coordinate cybersecurity tabletop exercises and crisis simulation exercises.
Requirements
- Bachelor’s degree or above in computer science, engineering or related domain discipline
- Minimum 15 years of relevant experience in IT, cyber, and data security
- Deep understanding of / Demonstrating familiarity with Cyber Security topics – Firewalls, WAF, Application security, Cloud security, web gateway, endpoint protection, SIEM, threat hunting, identity access management, application whitelisting, O365, data leakage protection, network security, email security, etc.
- Strong interpersonal, organizational and problem-solving skills as well as project management, client serving, multi-tasking
- Able to work independently, attention to details, result-driven
- Enthusiastic, self-motivated with proactive mindset
- Strong leadership skills and people management skills
- Able to drive projects involving multiple teams and knowledge domains
- Excellent command of / fluent in both reading, speaking and writing (English and Chinese (Putonghua is a must))
- Certification – required — CISSP, or CISM/CIS/ ISO 27001 Lead Implementer/ Auditor
- Stay informed on CITIC CLSA Job Opportunities
- Not the right fit? You can create a job alert to receive our latest job openings that meet your interest.
Similar roles you might like
See all →C
Senior Manager - Operational Technology Penetration Testing
CLP
Salary not disclosedPosted today
5V
Credit Intern
595 Vantage Capital Markets HK Limited
Salary not disclosedPosted today
AS
Manager / Senior Manager, Business Analysis
AIA Shared Services (Hong Kong) Limited
Salary not disclosedPosted today
2M
Senior Load Balancer Engineer - ETS
234 MS Hong Kong Limited
Salary not disclosedPosted 1 day ago
PS
Associate, Disputes
Peregrine Services Limited
Salary not disclosedPosted 7 days ago
M
Chief Information Officer, Hong Kong and Macau
Manulife
Salary not disclosedPosted 7 days ago
S
Global S&OP Manager
Sinclair
Salary not disclosedPosted 7 days ago
L(
Senior IT Engineer (Operations & Infrastructure)
lgt (workday)
Salary not disclosedPosted 8 days ago
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
