Manager, Cybersecurity Governance & Risk
Anglo-Eastern Ship Management Hong Kong, Hong Kong Island, Hong Kong S.A.R.
Maritime Transportation · 10,001+ employees
About the role
The manager will lead the cybersecurity governance and risk team to implement strategies, policies, and control frameworks across shore, vessel, and cloud environments. They will also coordinate audits, manage third-party risk, and partner with internal stakeholders to embed security-by-design and resilience into operations.
What they look for
Requirements
Candidates must have a bachelor's degree in a relevant field and 8-12 years of experience in cybersecurity GRC or IT audit. Strong technical knowledge of infrastructure, cloud security, and risk frameworks like ISO 27001 or NIST is required, along with professional certifications such as CISM, CRISC, or CISSP.
Benefits
Full description
Governance, risk and regulatory obligations
- Turn the Group's cyber and technology risk strategy into a practical roadmap, policies and standards, built on a control framework aligned to ISO/IEC 27001, ISO 22301 and NIST CSF 2.0.
- Lead risk assessments across shore, vessel, cloud and OT environments; maintain the risk register and report clear KRI/KPI dashboards to senior management.
- Maintain an obligations register covering maritime cyber requirements, client commitments and the regulations applying across our operating jurisdictions, such as Hong Kong PDPO, Singapore PDPA and NIS2.
- Partner with QHSE, Fleet and Vessel IT to embed cybersecurity into the safety management system and strengthen vessel assurance.
- Run a risk-based third-party programme with Legal and Privacy, from due diligence and contract controls through to monitoring and exit.
Certification, audits and assurance
- Keep the organisation continuously certification-ready, rather than preparing for each audit in isolation.
- Coordinate internal, external, certification and client audits end to end, from scope and evidence through to management reporting.
- Handle security questionnaires, tenders and due diligence from clients and shipowners, and track corrective actions through to closure.
Technology, security-by-design and resilience
- Work hands-on with Infrastructure & Operations on the security of the underlying estate — network segmentation and perimeter controls, Windows Server and Active Directory hardening including Group Policy baselines, endpoint configuration, patch and vulnerability management, and privileged access
- Partner with Development and Digitalisation on security-by-design and DevSecOps across cloud, applications and data.
- Assess AI tools and use cases for data exposure, access and model risk, and set proportionate guardrails drawing on references such as the NIST AI RMF and ISO/IEC 42001.
- Lead crisis management, business continuity and disaster recovery exercises, and automate control monitoring where you can.
Leadership and stakeholder partnership
- Lead and develop the GRC team, and coordinate control owners across offices and vessels.
- Work with our shore and maritime training organizations to build cybersecurity and AI-risk content into training for seafarers and shore staff.
- Act as a trusted partner across IT, QHSE, Fleet, Legal and the business, translating technical and regulatory risk into clear options for senior leaders, clients and auditors
- Bachelor’s degree in information security, Computer Science, Engineering, Risk Management or a related discipline; equivalent professional experience will be considered.
- CISM, CRISC, CISA, CISSP, ISO/IEC 27001 or ISO 22301 Lead Implementer or Lead Auditor, or an equivalent GRC qualification, is strongly preferred.
- Approximately 8-12 years of experience in cybersecurity GRC, information security governance, technology risk, IT audit or security assurance, including leadership responsibility.
- Hands-on experience with ISO/IEC 27001, ISO 22301, NIST CSF or a comparable framework, including audits, control assessment, evidence and remediation.
- Strong understanding of risk registers, control design and testing, exceptions, risk acceptance, KRIs/KPIs and executive reporting.
- Broad technical grounding across infrastructure and operations — networks, Windows and Active Directory and endpoints — as well as cloud, identity and security operations.
- Experience supporting clients, external auditors, regulators or industry bodies in a complex, global or operationally intensive organisation.
- Exposure to AI risk management or enterprise AI governance; maritime cybersecurity or OT experience is advantageous but not essential.
- Strong written and spoken English. Cantonese and/or Mandarin is advantageous.
- Pragmatic, engineering-informed builder who creates governance that works in real operations and can follow a control from policy through to implementation, evidence and outcome.
- Structured, risk-based decision-maker who remains calm and accountable under pressure.
- Clear communicator who can write concise policies, audit responses and executive updates without unnecessary jargon.
- Genuinely curious and self-driven — owns their development and keeps looking for better ways to do things, including responsible use of AI.
- Gets things done through others — a strong team player who engages people well beyond their own reporting line and builds successful professional connections with colleagues and stakeholders.
About Anglo-Eastern
Anglo-Eastern is a global leader in independent ship management services. The Group manages over 700 vessels under full technical management, supports around 500 additional ships under crew management, and has overseen more than 1,000 newbuildings and conversions through its newbuilding supervision and project management divisions.
Headquartered in Hong Kong, Anglo-Eastern operates through a network of 30 offices across Asia, Europe, and the Americas, including wholly owned maritime training facilities. Our strength lies in our people: over 39,000 seafarers and 2,350 shore-based employees who work together to support clients across ship types while building trust, driving performance, and shaping a better maritime future.
Why join Anglo-Eastern?
- Join a globally respected company with a strong maritime heritage of over 50 years
- Work in an environment anchored in integrity, trust, and long-term relationships
- Access continuous learning and structured career development across a truly global network
- Be part of a team committed to delivering excellence and shaping a better maritime future
Join us today!
Similar roles
-
Security Engineer / Manager
Bowtie Life Insurance Company Limited Wan Chai, Hong Kong Island, Hong Kong S.A.R.
-
Information Security Engineer - Cloud Security
Ryanair Group Holdings Wrocław, Lower Silesian Voivodeship, Poland
- Nederlands Sprekende Klantadviseur Cybersecurity - Work Remote In Greece
-
Cybersecurity Expert
Inetum Lisbon, Portugal
-
Marketing Manager - Telecoms and Cybersecurity
Enea Dublin, Leinster, Ireland · €45K–€60K/yr
-
Sales Specialist Cybersecurity - H/F
Devoteam Levallois-Perret, Ile-de-France, France