← Back to job listings

Cybersecurity and Information Security Analyst
nahc · Hong Kong
About The Role
Our client is a high-growth regional SaaS platform, seeking an experienced QA Lead (Automation & Manual) to direct its software quality strategy and testing ecosystem. In this role, you will partner closely with engineering leaders to establish testing standards and maintain high product excellence across fast-moving feature release cycles. This position is ideal for a hands-on QA leader who excels at bridging technical quality execution with business-critical outcomes.
What You Will Do
- Own end-to-end vulnerability management—scheduling automated scans, prioritizing SAST/DAST findings, and driving technical remediation across application and infrastructure layers.
- Lead the complete incident response lifecycle, managing security event monitoring, containment, forensic mitigation, and root-cause reporting for executive leadership.
- Direct internal and external IT audits, maintaining certification programs across ISO 27001, ISO 42001 standards and SOC compliance.
- Develop, implement, and maintain data governance and privacy frameworks (e.g., GDPR) across existing and expanding global operating regions.
- Conduct continuous threat hunting using updated threat intelligence to proactively strengthen controls and prevent security violations.
- Partner with engineering and operational squads to enforce security standards, evaluate risks in new initiatives, and conduct staff cybersecurity training.
What You Will Need
- 2+ years of hands-on experience in information security, IT compliance, or risk management within modern technology or cloud environments.
- Practical expertise with core compliance frameworks and standards, specifically ISO 27001, SOC reporting, and ISO 42001 (Artificial Intelligence Management Systems).
- Solid technical understanding of software development lifecycles, IT infrastructure, network architectures, vulnerability scanning, and structured incident response.
- Deep knowledge of global data privacy regulations (e.g., GDPR) and data governance frameworks.
- Industry security or compliance certifications (e.g., CISSP, CCEP, ISO Lead Implementer/Auditor, or equivalent professional credentials) are strongly preferred.
- Excellent analytical, problem-solving, and communication skills to effectively translate technical risks to cross-functional stakeholders.
Similar roles you might like
See all →DB
Senior Associate/ Associate, Technology Risk Management, Technology and Operations
DBS Bank (Hong Kong) Limited
Salary not disclosedPosted today
HM
Vice President – Cyber Broking
HK001 Marsh (Hong Kong) Limited
Salary not disclosedPosted today
W
Cybersecurity Management Consultant - Internship (5-6 months)
Wavestone
Salary not disclosedPosted 2 days ago
H
Internal Audit, Asset Management Audit, Associate, Hong Kong
Hdpc
Salary not disclosedPosted 3 days ago
JS
2027 Internship/Graduate - Security Engineer
Salary not disclosedPosted 9 days ago
S
Security Engineer
sig
Salary not disclosedPosted 10 days ago
B
Senior Security Engineer (AWS Cloud)
BTSE
Salary not disclosedPosted 16 days ago
HS
IDT Manager Mobility HongKong and Macau
HKHK SHKL - Hong Kong Ltd
Salary not disclosedPosted 17 days ago
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
