nahc.io

Cybersecurity and Information Security Analyst

nahc.io Hong Kong, China

Human Resources Services · 11-50 employees

13 h ago
security Mid (2-5 yrs) Full-time China
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The analyst will manage end-to-end vulnerability assessments, incident response lifecycles, and internal/external IT audits. They are also responsible for implementing data privacy frameworks and conducting proactive threat hunting to strengthen security controls.

What they look for

Vulnerability management Incident response ISO 27001 ISO 42001 SOC compliance Data governance GDPR Threat hunting Risk management IT auditing SAST DAST Network architecture Cloud security Cybersecurity training

Requirements

Candidates must have at least 2 years of experience in information security, IT compliance, or risk management within modern technology environments. Proficiency in global data privacy regulations, core compliance frameworks like ISO 27001/SOC, and technical security infrastructure is required.

Full description

Overview

Our client is an expanding global technology company, seeking an experienced Compliance and Information Security Analyst to safeguard its digital infrastructure and maintain top-tier international standards. You will oversee corporate compliance, audit readiness, data privacy frameworks, and threat mitigation across multi-region operating markets. This position is ideal for a detail-oriented security professional looking to drive enterprise compliance, AI data governance, and proactive risk management in a fast-paced environment.

\n

What You Will Do

  • Own end-to-end vulnerability management—scheduling automated scans, prioritizing SAST/DAST findings, and driving technical remediation across application and infrastructure layers.
  • Lead the complete incident response lifecycle, managing security event monitoring, containment, forensic mitigation, and root-cause reporting for executive leadership.
  • Direct internal and external IT audits, maintaining certification programs across ISO 27001, ISO 42001 standards and SOC compliance.
  • Develop, implement, and maintain data governance and privacy frameworks (e.g., GDPR) across existing and expanding global operating regions.
  • Conduct continuous threat hunting using updated threat intelligence to proactively strengthen controls and prevent security violations.
  • Partner with engineering and operational squads to enforce security standards, evaluate risks in new initiatives, and conduct staff cybersecurity training.

What You Will Need

  • 2+ years of hands-on experience in information security, IT compliance, or risk management within modern technology or cloud environments.
  • Practical expertise with core compliance frameworks and standards, specifically ISO 27001, SOC reporting, and ISO 42001 (Artificial Intelligence Management Systems).
  • Solid technical understanding of software development lifecycles, IT infrastructure, network architectures, vulnerability scanning, and structured incident response.
  • Deep knowledge of global data privacy regulations (e.g., GDPR) and data governance frameworks.
  • Industry security or compliance certifications (e.g., CISSP, CCEP, ISO Lead Implementer/Auditor, or equivalent professional credentials) are strongly preferred.
  • Excellent analytical, problem-solving, and communication skills to effectively translate technical risks to cross-functional stakeholders.

\n

Similar roles