Cybersecurity Risk Advisor
ECI Hong Kong, China
Information Technology & Services · 501-1,000 employees
About the role
The Cybersecurity Risk Advisor will develop and implement risk management strategies while conducting security assessments and audits for financial services clients. They will act as a trusted advisor to client leadership, ensuring alignment with regional regulatory frameworks and global security standards.
What they look for
Requirements
Candidates must have at least 4 years of experience in information security or IT operations and a bachelor's degree in a relevant field. A strong understanding of APAC-specific regulatory frameworks and global security standards is essential for this role.
Benefits
Full description
ECI is the leading global provider of managed services, cybersecurity, and business transformation for mid-market financial services organizations across the globe. From its unmatched range of services, ECI provides stability, security and improved business performance, freeing clients from technology concerns and enabling them to focus on running their businesses. More than 1,000 customers worldwide with over $3 trillion of assets under management put their trust in ECI.
At ECI, we believe success is driven by passion and purpose. Our passion for technology is only surpassed by our commitment to empowering our employees around the world.
The Opportunity:
ECI has an exciting opportunity for an experienced Cybersecurity Risk Advisor to join our Hong Kong team. In this role, you will have the opportunity to work with cutting edge technology and industry leaders in the financial space. This role will play a crucial role in bolstering our clients' defenses against cyber threats, conducting security audits/assessments and working closely with client leadership teams to drive the completion of security-based initiatives. You will be expected to stay abreast of the latest trends and changes in the cyber landscape and act as a security centric technical leader amongst your peers. You will be a part of a strong international team that supports clients across the globe. You will be deeply familiar with leading compliance and security frameworks such as HITRUST,
CMMC, NIST and more. You should also have a strong ability to assess risk to an organization based on their operations. In this role, you can’t be afraid to get your hands dirty and help the leadership team build an ever-evolving program.
This is a remote role with a strong preference for candidates to be based in the Hong Kong area.
What you will do:
- Create a relationship with clients as a trusted cybersecurity advisor.
- Develop and implement cybersecurity risk management strategies tailored to the needs of financial services clients in APAC.
- Advise clients on compliance with regional regulatory frameworks such as MAS TRM, HKMA, APRA, and FSC Korea, as well as global standards like ISO 27001, NIST, and CIS.
- Conduct security assessments, audits, and gap analyses to identify vulnerabilities and recommend actionable improvements.
- Collaborate with client stakeholders, including CISOs and IT leadership, to align cybersecurity initiatives with business objectives.
- Stay current with evolving cyber threats, regulatory updates, and industry trends across the APAC region.
- Support clients during internal and external audits, including preparation of documentation and remediation planning.
- Collaborate with team members and contribute to the continuous improvement of internal methodologies and knowledge sharing.
- Respond to ad hoc client queries related to cybersecurity, risk, and compliance.
- Travel within the APAC region up to 10% as required.
- Other duties as assigned.
Who you are:
- Excellent communication and presentation skills, with the ability to engage senior stakeholders and explain complex topics in business terms.
- Strong understanding of APAC-specific regulatory frameworks (e.g., MAS TRM, HKMA, APRA CPS 234, FSC, etc.).
- Familiarity with global standards such as ISO 27001, NIST CSF, CIS Controls, and COBIT.
- Proven experience conducting security assessments, audits, and risk analyses.
- Self-motivated, adaptable, and capable of working independently in a fast-paced, multicultural environment.
- Bachelor’s degree in a relevant field such as Computer Science, Information Technology, Cybersecurity or equivalent combination of education and professional experience, typically 4+ years in information security, IT operations, or a related technical role.
Bonus points if you have:
- Experience in cybersecurity, IT risk, or compliance, preferably within the financial services sector.
- Industry certifications such as CISSP, CISM, CRISC, or CCSP
- Previous MSP/MSSP experience.
- Technical knowledge of IT systems and security controls (e.g., Microsoft, Cisco, endpoint protection, IAM, etc.).
- Strong familiarity with and understanding of O365 admin center.
ECI’s culture is all about connection - connection with our clients, our technology and most importantly with each other. In addition to working with an amazing team around the world, ECI also offers a competitive compensation package and so much more! If you believe you’d be a great fit and are ready for your best job ever, we’d like to hear from you!
Love Your Job, Share Your Technology Passion, Create Your Future Here!
#LI-Remote
Similar roles
-
Security Engineer
Applied Network Solutions Inc Linthicum, Maryland, United States · $100K–$200K/yr
-
Security Engineer with Akamai WAF
Syncreon Consulting New York, New York, United States
-
Cyber Security Engineer
UL Solutions Northbrook, Illinois, United States · $96K–$130K/yr
-
OT Network & Security Engineer
Vulcan Elements Research Triangle Park, North Carolina, United States
-
Senior Security Engineer, Access Security
Google New York, New York, United States · $174K–$252K/yr
-
Senior Security Engineer
Zepz United Kingdom