Deloitte logo
德勤
Senior Staff - Information Technology Services-Cybersecurity Services(106749)内部服务部门

Senior Staff - Information Technology Services-Cybersecurity Services(106749)内部服务部门

发布于 大约 14 小时前

普通员工/个人贡献者

香港
高级经验
全职员工
仅现场办公
本科
网络安全
Iam
Iso 22301
Iso/Iec 27001
Pam
Pdpo

AI 估算 · 45k–65k

Senior cybersecurity role in HK; high demand, market pay is strong. Estimated monthly CNY.

职位详情

关于这个职位

This is a senior cybersecurity position based in Hong Kong, responsible for daily security operations, governance, compliance, incident response, and client assurance. You will work with enterprise security tools and regulatory frameworks such as ISO 27001 and PDPO, serving as a key security resource for the Hong Kong and Macau practices. This role requires deep expertise in both technical operations and risk management, making it ideal for experienced security professionals seeking a challenging and rewarding career.

最低要求

Bachelor's degree or above in Computer Science, Information Security, Information Systems, or a related discipline.

Minimum 5 years of experience in information security, spanning security operations and security governance/compliance in a regulated or professional services environment.
Hands-on experience with enterprise security operations tooling, such as vulnerability management platforms, PAM, IAM, and email security gateways.
Experience operating or auditing an ISO/IEC 27001 ISMS; exposure to ISO 22301 and certification cycles strongly preferred.
Working knowledge of the Hong Kong regulatory landscape, including PDPO and HKMA/SFC technology risk and outsourcing requirements.
Experience handling security incidents and coordinating cross-functional response.
One or more recognized certifications: CISSP, CISM, CISA, CRISC, or ISO/IEC 27001 Lead Auditor/Lead Implementer.
Excellent written and spoken English; Cantonese and/or Mandarin strongly preferred for client and regulator engagement.
Strong stakeholder management and the ability to communicate risk clearly to senior, non-technical audiences.
Prior experience in a Big Four, financial services, or other highly regulated organization in Hong Kong.
Familiarity with the Protection of Critical Infrastructures (Computer Systems) Ordinance and its implications for service providers.
Understanding of cloud security and data protection controls (Microsoft 365, Azure) in an enterprise environment.
Ability to work independently as part of a small, high-accountability local team.

工作职责

Security Operations:

Run daily security operations for the Hong Kong and Macau practices, including vulnerability management, privileged account management (PAM), and phishing/email threat response.
Operate and maintain the local security tooling stack (PAM, IAM, email security gateway, vulnerability management platforms) and ensure locally generated, audit-ready operational logs and evidence.
Review security monitoring output, manage exceptions, and drive remediation with infrastructure and application teams.
Security Governance & Compliance:
Own and maintain the Hong Kong information security and business continuity management systems, including ISO/IEC 27001 and ISO 22301 certification, policies, standards, and control documentation.
Plan and coordinate internal and external security audits; track and drive remediation of findings to closure.
Monitor Hong Kong regulatory and legal developments (e.g., PDPO, Protection of Critical Infrastructures (Computer Systems) Ordinance, HKMA/SFC supervisory expectations) and translate them into firm requirements.
Client & Regulatory Assurance:
Respond to client security due diligence questionnaires, third-party risk assessments, and regulator-driven inquiries within required timelines.
Support engagement teams on information security requirements in client contracts and outsourcing arrangements.
Represent the Hong Kong firm in client security reviews, on-site assessments, and industry/regulator forums.
Incident Response & Resilience:
Serve as a primary responder for security incidents affecting the Hong Kong and Macau practices, covering triage, containment, escalation, evidence preservation, and post-incident review.
Maintain and exercise business continuity and incident response plans in line with ISO 22301.
Provide backup coverage for the application security function to ensure continuous local capability (A/B role arrangement).
Risk Management & Awareness:
Conduct security risk assessments for new technology, vendors, and business initiatives.
Deliver security awareness programs and phishing simulations for the Hong Kong practice.
Report on security posture, risks, and compliance status to ITS leadership and firm management.

AI 洞察

优缺点分析

优点

  • Work at a top professional services firm with global resources and a strong brand.
  • High exposure to regulatory and client environments, enhancing your professional credibility.
  • Opportunity to develop both technical and governance skills, making you a well-rounded security leader.
  • Deloitte's people-oriented culture and investment in learning platforms support continuous growth.
  • High accountability and responsibility in a small local team
  • you will need to work independently.
  • The role combines operational and compliance duties, requiring flexibility across domains.
  • Hong Kong market demanding
  • may involve intense work during audits or incidents.
  • This role suits experienced security professionals who thrive on variety, enjoy working with regulations, and want to grow in a prestigious professional services environment.

缺点 / 挑战

暂无明显挑战项

角色解读

  • With clear career development paths at Deloitte, you can progress to regional security leadership roles.
  • Opportunities to deepen expertise in cloud security and emerging tech like AI-driven security.
  • Potential to move into broader risk advisory or consulting roles leveraging your technical and governance skills.
  • Run daily security operations for Hong Kong and Macau, including vulnerability management, PAM, and phishing response.
  • Own and maintain the information security and business continuity management systems, ensuring ISO 27001/22301 compliance and audit readiness.
  • Serve as the primary incident responder and support client and regulatory security assurance activities.
  • Perform risk assessments and deliver security awareness programs.
  • Deep expertise in security operations tools (PAM, IAM, email security gateways, vulnerability management).
  • Strong knowledge of ISO 27001/22301 and Hong Kong regulations (PDPO, HKMA/SFC).
  • Incident response and crisis management experience.
  • Excellent communication and stakeholder management, with fluency in English and ideally Cantonese/Mandarin.

申请策略

  • Tailor your CV to show both operational and governance/compliance capabilities.
  • Demonstrate your ability to communicate with senior non-technical stakeholders, since this is critical for the role.
  • Highlight hands-on experience with security tooling like PAM, IAM, and vulnerability management platforms.
  • Showcase your track record in ISO 27001 implementation or auditing and any involvement in ISO 22301.
  • Emphasize incident response scenarios where you coordinated cross-functional teams.
  • List relevant certifications (CISSP, CISM, CISA, CRISC) prominently.
  • If not yet familiar, study the Hong Kong PDPO and HKMA/SFC technology risk requirements.
  • Gain familiarity with Microsoft 365 and Azure security controls to meet cloud security expectations.

面试指南

  • Use the STAR method (Situation, Task, Action, Result) to structure answers about incidents and audits.
  • For regulatory questions, show awareness of specific frameworks and describe how you translate them into internal policies.
  • For stakeholder communication questions, demonstrate clear simplification of technical risks for non-technical audiences.
  • Describe a time you managed a security incident end-to-end. What was your role?
  • How would you ensure ISO 27001 certification is maintained in a dynamic environment?
  • Explain how you would handle a client's security due diligence questionnaire under a tight deadline.
  • What is your experience with Hong Kong regulations like PDPO? Can you give an example of applying them?
  • How do you prioritize security tasks when working independently in a small team?

职位点评

68
综合评分

A senior cybersecurity role in Hong Kong with strong development potential, competitive but unspecified pay, and demanding on-site work.

从薪资福利、成长空间、工作节奏和岗位方向综合评估,方便横向比较。

更适合这类人
This role is best for professionals who prioritize professional growth, learning, and meaningful work over work-life balance.
表现最好
成长发展
相对薄弱
工作生活
薪资福利60
成长发展85
工作生活55
使命价值70

薪资福利

60中等

The compensation is not disclosed, but Deloitte's scale and Hong Kong's market generally offer competitive packages. No explicit benefits are mentioned in the JD.

薪资信号未披露(AI估算:45K-65K/月)

成长发展

85较高

The role provides excellent opportunities for skill development in security operations, governance, and cloud security, with clear career paths at Deloitte.

技术前沿主流现代技术
技术栈Cybersecurity、ISO/IEC 27001、ISO 22301、PAM、IAM、Vulnerability Management、Cloud Security、Azure、Microsoft 365、Incident Response
成长机会career development paths、learning platform、counseling system、global mobility
业务类型cost_center

工作生活

55较低

This is an on-site role in Hong Kong with no explicit work-life balance provisions. The high-accountability nature may require flexibility.

工作模式仅现场办公
办公地点市区核心地段
加班情况未提及(无法判断)

使命价值

70中等

Cybersecurity has positive social impact, and Deloitte emphasizes its purpose of making an impact that matters. The role supports client and regulator assurance, adding meaning.

行业发展高速增长赛道
社会影响中性/一般
使命信号making an impact that matters
创新程度积极采用新技术
Watch Jobs