
Senior Staff - Information Technology Services-Cybersecurity Services(106749)内部服务部门
发布于 大约 14 小时前普通员工/个人贡献者
AI 估算 · 45k–65k
Senior cybersecurity role in HK; high demand, market pay is strong. Estimated monthly CNY.
职位详情
关于这个职位
This is a senior cybersecurity position based in Hong Kong, responsible for daily security operations, governance, compliance, incident response, and client assurance. You will work with enterprise security tools and regulatory frameworks such as ISO 27001 and PDPO, serving as a key security resource for the Hong Kong and Macau practices. This role requires deep expertise in both technical operations and risk management, making it ideal for experienced security professionals seeking a challenging and rewarding career.
最低要求
Bachelor's degree or above in Computer Science, Information Security, Information Systems, or a related discipline.
工作职责
Security Operations:
AI 洞察
优缺点分析
优点
- Work at a top professional services firm with global resources and a strong brand.
- High exposure to regulatory and client environments, enhancing your professional credibility.
- Opportunity to develop both technical and governance skills, making you a well-rounded security leader.
- Deloitte's people-oriented culture and investment in learning platforms support continuous growth.
- High accountability and responsibility in a small local team
- you will need to work independently.
- The role combines operational and compliance duties, requiring flexibility across domains.
- Hong Kong market demanding
- may involve intense work during audits or incidents.
- This role suits experienced security professionals who thrive on variety, enjoy working with regulations, and want to grow in a prestigious professional services environment.
缺点 / 挑战
暂无明显挑战项
角色解读
- With clear career development paths at Deloitte, you can progress to regional security leadership roles.
- Opportunities to deepen expertise in cloud security and emerging tech like AI-driven security.
- Potential to move into broader risk advisory or consulting roles leveraging your technical and governance skills.
- Run daily security operations for Hong Kong and Macau, including vulnerability management, PAM, and phishing response.
- Own and maintain the information security and business continuity management systems, ensuring ISO 27001/22301 compliance and audit readiness.
- Serve as the primary incident responder and support client and regulatory security assurance activities.
- Perform risk assessments and deliver security awareness programs.
- Deep expertise in security operations tools (PAM, IAM, email security gateways, vulnerability management).
- Strong knowledge of ISO 27001/22301 and Hong Kong regulations (PDPO, HKMA/SFC).
- Incident response and crisis management experience.
- Excellent communication and stakeholder management, with fluency in English and ideally Cantonese/Mandarin.
申请策略
- Tailor your CV to show both operational and governance/compliance capabilities.
- Demonstrate your ability to communicate with senior non-technical stakeholders, since this is critical for the role.
- Highlight hands-on experience with security tooling like PAM, IAM, and vulnerability management platforms.
- Showcase your track record in ISO 27001 implementation or auditing and any involvement in ISO 22301.
- Emphasize incident response scenarios where you coordinated cross-functional teams.
- List relevant certifications (CISSP, CISM, CISA, CRISC) prominently.
- If not yet familiar, study the Hong Kong PDPO and HKMA/SFC technology risk requirements.
- Gain familiarity with Microsoft 365 and Azure security controls to meet cloud security expectations.
面试指南
- Use the STAR method (Situation, Task, Action, Result) to structure answers about incidents and audits.
- For regulatory questions, show awareness of specific frameworks and describe how you translate them into internal policies.
- For stakeholder communication questions, demonstrate clear simplification of technical risks for non-technical audiences.
- Describe a time you managed a security incident end-to-end. What was your role?
- How would you ensure ISO 27001 certification is maintained in a dynamic environment?
- Explain how you would handle a client's security due diligence questionnaire under a tight deadline.
- What is your experience with Hong Kong regulations like PDPO? Can you give an example of applying them?
- How do you prioritize security tasks when working independently in a small team?
职位点评
A senior cybersecurity role in Hong Kong with strong development potential, competitive but unspecified pay, and demanding on-site work.
从薪资福利、成长空间、工作节奏和岗位方向综合评估,方便横向比较。
薪资福利
The compensation is not disclosed, but Deloitte's scale and Hong Kong's market generally offer competitive packages. No explicit benefits are mentioned in the JD.
成长发展
The role provides excellent opportunities for skill development in security operations, governance, and cloud security, with clear career paths at Deloitte.
工作生活
This is an on-site role in Hong Kong with no explicit work-life balance provisions. The high-accountability nature may require flexibility.
使命价值
Cybersecurity has positive social impact, and Deloitte emphasizes its purpose of making an impact that matters. The role supports client and regulator assurance, adding meaning.
德勤 的其他在招职位
Staff - Information Technology Services-Cybersecurity Services(106748)内部服务部门
德勤 · 重庆市AI 估算 · 15k-25kAssociate - Quantitative Analysis and Valuation (AI enabled) - Audit & Assurance - BJ
德勤 · 北京市AI 估算 · 15k-25kManager - Information Technology Services-Cybersecurity Services(106742)内部服务部门
德勤 · 上海市AI 估算 · 40k-60kAssociate - Indirect Tax - Customs & Global Trade - Beijing (106741)税务与商务咨询
德勤 · 北京市AI 估算 · 12k-20kAnalyst/Consultant (Data Analytics) - AI & Data - Shenzhen(10675)技术与转型
德勤 · 广州市AI 估算 · 18k-30k