Hong Kong Aircraft Engineering Company

Cybersecurity Risk & Governance Manager

Hong Kong Aircraft Engineering Company Hokitika, West Coast Region, New Zealand

Airlines and Aviation · 10,001+ employees

Yesterday
security Senior (5-10 yrs) Full-time New Zealand
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The manager is responsible for establishing and maintaining the IT risk management program to protect IT/OT systems and information assets. They will also develop security standards, facilitate risk assessments, and manage cybersecurity incidents.

What they look for

Information security Security operations Risk management Governance Compliance IT/OT security Threat intelligence Incident management Cybersecurity training NIST ITIL Project management

Requirements

Candidates must have at least 6 years of experience in information security and hold a bachelor's or master's degree in a relevant field. Professional certifications such as CISSP, CISM, CISA, or CRISC are required.

Benefits

Inclusive working environment Supportive working environment

Full description

The HAECO Group is an independent global provider of high-quality MRO services. We offer a broad range of aviation products and services that enable our customers to operate their aircraft, engines and components safely and efficiently. Headquartered in Hong Kong since 1950, our global reach has extended as we have grown. We now have operations throughout the Asia-Pacific region, Americas and other parts of the world.

Based at Hong Kong International Airport (HKIA), HAECO Hong Kong offer a full range of services including airframe services, line services, component services, engine services, freighter conversions, technical training and AOG support.

Position Description

The Cybersecurity Risk & Governance Manager is responsible for establishing and maintaining HAECO’s overall IT risk management program to ensure that HAECO’s IT/OT systems and information assets are adequately protected. He/She will identify, evaluate and report on IT/OT security risks; and advise HAECO entities on implementing practices that meet HAECO’s defined policies and standards for cybersecurity risk management.

What You'll Do

  • Develop appropriate standards and practices in relations to security governance & compliance.
  • Review, maintain and enhance security standards, procedures and guidelines to ensure they are current and adequate.
  • Facilitate cybersecurity risk assessment with Entities.
  • Monitor and report effective IT risk mitigating controls with application and infrastructure owners.
  • Analyse threat intelligence and recommend improvement on security controls for Entities to evaluate and implement
  • Manage cybersecurity incidents and participate in the cybersecurity crisis drill in order to minimize the damage/loss due to cybersecurity attacks.
  • Deploy cybersecurity training program to uplift business cybersecurity awareness.

What You'll Need

1. Functional and other Relevant Experience

  • A minimum of 6 years of combined experience in information security, security operations, security program and project management.

2. Qualifications and other Relevant Knowledge

  • Bachelor’s or master’s degree in Computer Science, Information Security or a related field or discipline.
  • Certified CISSP, CISM, CISA, CRISC or other similar credentials
  • Knowledge and understanding of NIST and ITIL.
  • In-depth knowledge of information security risk management and cybersecurity technologies.
  • Fluent in English, Mandarin is an advantage

HAECO Group is an equal opportunity employer. At HAECO, we are committed to creating an inclusive and supportive working environment for all our people regardless of their age, gender, gender identity, sexual orientation, relationship, family status, disability, race, ethnicity, nationality, religious or political beliefs. We believe in creating an environment where people feel comfortable at work and are able to realise their full potential.

Build your career with us and be part of something bigger at HAECO!

Reference ID: 1204

Candidates not contacted 4-6 weeks after submission of applications and/or interviews may consider their application unsuccessful.

All information provided by candidates will be treated in strict confidence and will be used for employment purpose only.

Similar roles