Director - Data and Security Governance

Our client is a leading financial‑sector organisation who is seeking a seasoned professional to spearhead its data and cybersecurity governance agenda. This strategic leadership role sits within the IT Security function and reports directly to the organisation's global Information Security head. The position is based in Hong Kong and plays a critical part in shaping enterprise‑wide cyber and data governance frameworks. The successful candidate will serve as the primary owner of cybersecurity and

Sanderson-iKas - Hong Kong - Full time

Salary: Negotiable

Our client is a leading financial‑sector organisation who is seeking a seasoned professional to spearhead its data and cybersecurity governance agenda. This strategic leadership role sits within the IT Security function and reports directly to the organisation's global Information Security head. The position is based in Hong Kong and plays a critical part in shaping enterprise‑wide cyber and data governance frameworks.

The successful candidate will serve as the primary owner of cybersecurity and data‑governance programmes. You will drive the design, enhancement, and execution of governance structures, policiesnand standards.

Key Responsibilities

  • Strengthen and enhance the company's cybersecurity and data‑governance framework
  • Ensure compliance with global and regional regulations and industry standards
  • Lead audit preparation and handle regulatory or client security assessments
  • Oversee cyber‑risk identification and drive mitigation initiatives
  • Guide vulnerability‑management activities with technical teams
  • Develop governance for multi‑cloud environments (AWS, Azure, Alibaba Cloud)
  • Provide clear reporting on security posture and compliance status
  • Support and prioritize key IT security projects across the organisation

Requirements

  • 15+ years in cybersecurity, IT governance, or data‑security disciplines
  • Hands‑on understanding of enterprise security technologies: firewalls, WAF, cloud security, SIEM, DLP, IAM, endpoint security, email & network security
  • Solid experience in data security governance, data protection, etc.
  • Proven capability to influence senior stakeholders and drive cross‑team projects
  • Strong leadership presence, proactive mindset, and ability to operate independently
  • Excellent communication skills in English and Chinese (Mandarin is a MUST)
  • Highly preferred certifications: CISSP, CISM, CISP, ISO 27001 Lead Implementer/Auditor

"Sanderson-iKas" is the brand name for the following companies incorporated in Hong Kong: Sanderson Solutions International (Hong Kong) Limited (Business Registration no.53741924) and iKas International (Asia) Limited (Business Registration no.39818987)

Website: www.sanderson-ikas.hk

23990344
Ad