Cybersecurity and Information Security Analyst
nahc.io Hong Kong, China
Human Resources Services · 11-50 employees
About the role
The analyst will manage end-to-end vulnerability assessments, incident response lifecycles, and internal/external IT audits. They are also responsible for implementing data privacy frameworks and conducting proactive threat hunting to strengthen security controls.
What they look for
Requirements
Candidates must have at least 2 years of experience in information security, IT compliance, or risk management within modern technology environments. Proficiency in global data privacy regulations, core compliance frameworks like ISO 27001/SOC, and technical security infrastructure is required.
Full description
Overview
Our client is an expanding global technology company, seeking an experienced Compliance and Information Security Analyst to safeguard its digital infrastructure and maintain top-tier international standards. You will oversee corporate compliance, audit readiness, data privacy frameworks, and threat mitigation across multi-region operating markets. This position is ideal for a detail-oriented security professional looking to drive enterprise compliance, AI data governance, and proactive risk management in a fast-paced environment.
\n
What You Will Do
- Own end-to-end vulnerability management—scheduling automated scans, prioritizing SAST/DAST findings, and driving technical remediation across application and infrastructure layers.
- Lead the complete incident response lifecycle, managing security event monitoring, containment, forensic mitigation, and root-cause reporting for executive leadership.
- Direct internal and external IT audits, maintaining certification programs across ISO 27001, ISO 42001 standards and SOC compliance.
- Develop, implement, and maintain data governance and privacy frameworks (e.g., GDPR) across existing and expanding global operating regions.
- Conduct continuous threat hunting using updated threat intelligence to proactively strengthen controls and prevent security violations.
- Partner with engineering and operational squads to enforce security standards, evaluate risks in new initiatives, and conduct staff cybersecurity training.
What You Will Need
- 2+ years of hands-on experience in information security, IT compliance, or risk management within modern technology or cloud environments.
- Practical expertise with core compliance frameworks and standards, specifically ISO 27001, SOC reporting, and ISO 42001 (Artificial Intelligence Management Systems).
- Solid technical understanding of software development lifecycles, IT infrastructure, network architectures, vulnerability scanning, and structured incident response.
- Deep knowledge of global data privacy regulations (e.g., GDPR) and data governance frameworks.
- Industry security or compliance certifications (e.g., CISSP, CCEP, ISO Lead Implementer/Auditor, or equivalent professional credentials) are strongly preferred.
- Excellent analytical, problem-solving, and communication skills to effectively translate technical risks to cross-functional stakeholders.
\n
Similar roles
-
Senior Security Engineer (m/w/d)
Yoummday GmbH Sofia, Sofia-City, Bulgaria
-
Senior Cybersecurity Engineer | Cyber Threat Intelligence & Response
Xplor Atlanta, Georgia, United States
-
Principal Cloud Security Engineer
LastPass Canada
-
Senior Network Security Engineer (m/f/d)
We One Łódź, Łódź Voivodeship, Poland · PLN 92K–PLN 146K/yr
-
Data Privacy and Protection - Cyber GRC Professional - Cybersecurity
EY Greece Patras, Peloponnese, Western Greece and the Ionian, Greece
- Italian Speaking Cybersecurity Customer Experts - Work In Athens, Greece