

Assistant Manager - Information Protection (Security & Compliance) (MJ002391)
Job Description
- Manage information security audit, compliance review, and risk assessment tasks
- Maintain and review security policies, procedures & practices to ensure compliance with all applicable laws, regulations, business requirement and firm policies
- Consolidate, review, and analyze information from different parties and provide security consultation as a whole
- Deliver security advice and recommendation to balance the need of Information Security, operation, and business requirement
- Work closely with internal & external auditors, business units and IT/ technology specialists
- Dealing with Information Protection queries from authority and business units
- Participate in other ad hoc assignments
Requirement
- University degree holder in Information Technology, Computer Science, or related disciplines; 3 years relevant experience in IT industry with at least 1 years in information security/ compliance
- Hands on experience on ISO 27001, 27017 and MLPS 2.0 compliance and security framework management would be a plus
- Adapt to MNC working culture, capable to work with people from different background and eager to advance career in information security industry
- Strong communication skill in both written and spoken Mandarin and English
- Good time management and analytical skill, and work independently
- Good information consolidation and reporting skill
- Holder of CISM/ CISA/ CISSP certificate would be preferred
- 管理安全稽覈
- 審核合規政策
- 整合資料分析
- 提供安全諮詢