Cybersecurity Risk & Governance Manager
Hong Kong Aircraft Engineering Company Hokitika, West Coast Region, New Zealand
Airlines and Aviation · 10,001+ employees
About the role
The manager is responsible for establishing and maintaining the IT risk management program to protect IT/OT systems and information assets. They will also develop security standards, facilitate risk assessments, and manage cybersecurity incidents.
What they look for
Requirements
Candidates must have at least 6 years of experience in information security and hold a bachelor's or master's degree in a relevant field. Professional certifications such as CISSP, CISM, CISA, or CRISC are required.
Benefits
Full description
The HAECO Group is an independent global provider of high-quality MRO services. We offer a broad range of aviation products and services that enable our customers to operate their aircraft, engines and components safely and efficiently. Headquartered in Hong Kong since 1950, our global reach has extended as we have grown. We now have operations throughout the Asia-Pacific region, Americas and other parts of the world.
Based at Hong Kong International Airport (HKIA), HAECO Hong Kong offer a full range of services including airframe services, line services, component services, engine services, freighter conversions, technical training and AOG support.
Position Description
The Cybersecurity Risk & Governance Manager is responsible for establishing and maintaining HAECO’s overall IT risk management program to ensure that HAECO’s IT/OT systems and information assets are adequately protected. He/She will identify, evaluate and report on IT/OT security risks; and advise HAECO entities on implementing practices that meet HAECO’s defined policies and standards for cybersecurity risk management.
What You'll Do
- Develop appropriate standards and practices in relations to security governance & compliance.
- Review, maintain and enhance security standards, procedures and guidelines to ensure they are current and adequate.
- Facilitate cybersecurity risk assessment with Entities.
- Monitor and report effective IT risk mitigating controls with application and infrastructure owners.
- Analyse threat intelligence and recommend improvement on security controls for Entities to evaluate and implement
- Manage cybersecurity incidents and participate in the cybersecurity crisis drill in order to minimize the damage/loss due to cybersecurity attacks.
- Deploy cybersecurity training program to uplift business cybersecurity awareness.
What You'll Need
1. Functional and other Relevant Experience
- A minimum of 6 years of combined experience in information security, security operations, security program and project management.
2. Qualifications and other Relevant Knowledge
- Bachelor’s or master’s degree in Computer Science, Information Security or a related field or discipline.
- Certified CISSP, CISM, CISA, CRISC or other similar credentials
- Knowledge and understanding of NIST and ITIL.
- In-depth knowledge of information security risk management and cybersecurity technologies.
- Fluent in English, Mandarin is an advantage
HAECO Group is an equal opportunity employer. At HAECO, we are committed to creating an inclusive and supportive working environment for all our people regardless of their age, gender, gender identity, sexual orientation, relationship, family status, disability, race, ethnicity, nationality, religious or political beliefs. We believe in creating an environment where people feel comfortable at work and are able to realise their full potential.
Build your career with us and be part of something bigger at HAECO!
Reference ID: 1204
Candidates not contacted 4-6 weeks after submission of applications and/or interviews may consider their application unsuccessful.
All information provided by candidates will be treated in strict confidence and will be used for employment purpose only.
Similar roles
-
Senior Security Engineer - DevSecOps
carsales Sydney, New South Wales, Australia
-
Lead Cloud Security Engineer (DevSecOps)
Bilue Taguig, National Capital District, Philippines
-
Senior Security Engineer - Detection Engineering
LinkedIn United States · $129K–$212K/yr
-
Security Engineer
AlertMedia Austin, Texas, United States
-
F-35 Air Systems Information System Security Engineer | Active Secret clearance
General Dynamics Information Technology Eglin AFB, Florida, United States · $128K–$172K/yr
-
Full-Stack Engineers (Cybersecurity): Feedback On CI/CD Workflows
Terac United States · $218K/yr