Assistant Vice President (AVP), Information Security Governance
Hong Kong Exchanges and Clearing Limited
Hong Kong
Full time
Permanent
On-site
Competitive
About the job
Company Introduction:
We're home to Asia's most dynamic and vibrant capital markets.
Connecting capital, ideas, inspiration and innovation for deeper, more diverse and liquid global capital markets; providing greater choice and opportunity for our customers, each and every day.
HKEX is a purpose-driven company. Our commitment to the long-term development of our business and our markets is articulated in our purpose: "To Connect, Promote and Progress our Markets and the Communities they support for the prosperity of all."
Job Summary:
Job Duties:
Security Configuration
Technical & Professional Skills
Location:
HKEX - TKO
Shift:
Standard - 40 Hours (Hong Kong SAR)
Scheduled Weekly Hours:
40
Worker Type:
Permanent
We're home to Asia's most dynamic and vibrant capital markets.
Connecting capital, ideas, inspiration and innovation for deeper, more diverse and liquid global capital markets; providing greater choice and opportunity for our customers, each and every day.
HKEX is a purpose-driven company. Our commitment to the long-term development of our business and our markets is articulated in our purpose: "To Connect, Promote and Progress our Markets and the Communities they support for the prosperity of all."
Job Summary:
Job Duties:
Security Configuration
- Manage and maintain enterprise security configuration standards and baselines.
- Review and adopt the latest Center for Internet Security (CIS) Benchmarks , ensuring alignment with HKEX security requirements.
- Oversee updates to security configuration scanning tools to incorporate the latest CIS Benchmarks and security checks.
- Develop, review, and maintain Generic Security Baselines ( GSBs ) for technologies and platforms not covered by CIS Benchmarks.
- Ensure security configuration standards remain current, effective, and aligned with industry best practices and regulatory requirements.
- Administer the security exception management process for security findings.
- Review and validate exception requests to confirm that appropriate business justification, risk assessment, compensating controls, and management approvals are in place.
- Assess and validate potential false - positive findings identified through security configuration scans.
- Maintain accurate records of approved exceptions and monitor their validity periods and expiry dates .
- Perform governance and approval activities to ensure security standards and operational requirements are met.
- Review and approve website, file upload and email whitelisting requests in accordance with established security policies and risk management requirements.
- Review and approve encryption key management requests and related activities a ccording to cryptographic standards and key management requirements.
- Review and approve requests related to internal Certificate Authority (CA) certificates and e nsure proper issuance, renewal, usage, and management of digital certificates.
- Review and approve SUDO registration and privileged escalation and e nsure requests is granted with least-privilege and security governance principles.
- Conduct Security Acc eptance C hecklist (SAC) reviews and approvals as part of the SDLC process control .
- Assess and approve SSR requests stating security requirements are not applicable, ensuring adequate justification and risk assessment are documented.
- Review and approve requests for installation of non-standard software , with e valuat ion of associated operational, security, compliance, and technology risks. Ensure appropriate mitigating controls are established before approval
Technical & Professional Skills
- Minimum 10 years of relevant experience in in information security governance , information security, technology risk management , compliance, or IT audit functions, preferably within financial services or a regulated environment.
- Good understanding of information security governance, risk, and control concepts.
- Strong understanding of CIS Benchmarks, control principles, and security governance processes.
- Excellent analytical, communication, and stakeholder management skills.
- Ability to analyse processes and identify gaps or improvement opportunities.
- Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, or related discipline.
- Relevant professional certifications such as CISSP, CISM, ISO 27001 Lead Implementer/Auditor, CCSP or equivalent are preferred.
Location:
HKEX - TKO
Shift:
Standard - 40 Hours (Hong Kong SAR)
Scheduled Weekly Hours:
40
Worker Type:
Permanent