About this role
Job Description:
• Handling Information Security Management, addressing information security threats and incidents, and driving remediation.
• In conjunction with the Legal team, identify information management and protection laws and regulations and implement actions to ensure compliance with relevant laws.
• Identify, track, and oversee internal and external compliance and regulatory requirements (PCI, Data Privacy, etc.) for the organization including compliance with established policies, procedures, standards, baselines, and controls.
• Maintain an information management and protection framework for an effective company-wide governance program.
• Manage information security awareness programs and provide training to all staff.
• Guide and support staff, and provide security training and awareness programs to promote a culture of security and best practices within the organization.
• Manage day-to-day security activities, including conducting vendor security assessments and privacy security assessments, implementing company policies, and communicating related to the information security program.
• Manage and Support the Information Security requirements across different BUs.
• Support global projects as a regional ISO team member.
• Work with security operations team to respond to security incidents (personal/confidential information, system hacking, local employee information leakage, information breach, store physical security, customer center security).
Job Requirements:
• Degree holder in Management, Information Technology, Information Security, Computer Science, or related disciplines.
• At least 6 years of experience in information security, cybersecurity, IT risk, or governance-related functions.
• Strong knowledge of information security governance, risk assessment, compliance frameworks, and data privacy requirements.
• Familiarity with cybersecurity standards, regulations, and best practices, with the ability to translate security requirements into practical business solutions.
• Experience managing security controls across Microsoft 365, network, and enterprise technology environments.
• Professional security certifications (e.g., CISSP, CISM, CISA, GIAC) are highly preferred.
• Strong analytical thinking, business process improvement, and risk management capabilities.
• Excellent communication and stakeholder management skills with the ability to influence and educate employees at all levels.
• Proactive, adaptable, and highly accountable, with the ability to manage multiple projects and priorities independently.
• Fluent in Cantonese , English and Mandarin.