Technology Risk / GRC Specialist (PERM)
IO Tech Solutions
Hong Kong
Full time
Permanent
On-site
Basic Salary + discretionary bonus
About the job
Key Responsibilities:
Security Governance
- Develop, implement, and maintain cybersecurity policies, standards, and procedures aligned with industrial best practices and regulatory requirements.
- Prepare reports and dashboards for senior management on risk posture, compliance status, and audit findings.
- Arrange and deliver training on cyber and information security topics to stakeholders.
Risk Oversight & Assessment
- Own the central risk registry, ensuring all identified vulnerabilities and treatment action plans are actively tracked and updated.
- Perform periodic risk evaluations and control testing to uncover system gaps, providing actionable, prioritized mitigation roadmaps.
- Keep a pulse on the evolving threat landscape, new regulatory updates, and shifting sector trends to proactively adjust defense strategies.
Audit & Compliance Management
- Orchestrate end-to-end coordination for internal and external audits across multiple regulatory mandates (including PCI-DSS and ISO 27001).
- Oversee ongoing compliance health checks, monitoring remediation efforts and liaising with various stakeholders to close out findings promptly.
- Gather and organize audit evidence, conduct root-cause gap analysis, and ensure corrective measures are implemented on schedule.
- Partner seamlessly with cross-functional technology and business teams to weave security controls into daily operations and project rollouts.
What We Are Looking For:
- Education: Bachelor's degree in Cybersecurity, IT, Risk, Computer Science, or a related discipline.
- Experience: 1 to 3 years of practical experience in security governance, IT audit, compliance, or risk management.
- Technical Know-How: Solid grasp of established security frameworks (specifically PCI-DSS and ISO 27001); familiarity with modern security tooling such as vulnerability scanners, XDR platforms, and SIEM solutions is a plus.
- Soft Skills: Exceptional problem-solving capabilities, strong written/verbal communication, and meticulous attention to detail.
- Organizational Fit: Comfortable juggling multiple concurrent projects, prioritizing competing demands, and operating autonomously while remaining a strong cross-functional collaborator.
- Certifications (Nice-to-Have): Credentials like CISSP, CISM, CISA, CRISC, CGRC, or SSCP will give you a distinct advantage.