About this role
ABOUT CLP
CLP was founded in Hong Kong in 1901, at a time when electricity was still a novelty worldwide. Today we power millions of homes and businesses across the Asia-Pacific region with over 8,000 employees. In Hong Kong, we operate a vertically integrated electricity business providing a highly reliable supply of electricity to over 80% of the city’s population. Outside Hong Kong, we invest in the energy sector on the Chinese Mainland, in Australia, India, Taiwan Region and Thailand. Our business spans the electricity value chain ranging from power generation, transmission and distribution to retail and smart energy services. We have a diversified portfolio of generating assets that uses a wide range of fuels sources including nuclear, renewables, gas and coal. To meet the evolving needs of energy users in a world being reshaped by decarbonisation and digitalisation, we strive to embrace new opportunities and expand our horizons as we fulfil our purpose to Power Brighter Tomorrows.
Working Location: Kai Tak, Hong Kong
Employment Duration: Permanent
Responsibilities
• Deliver technical guidance and leadership in the areas of cyber security primarily in IT & OT domains, including system security, design development for both hardware and software projects. • Act as the Subject Matter Expert for OT security architecture, leading security architecture reviews of proposed OT solutions to ensure alignment with industry standards, regulatory requirements and CLP’s cyber security standards. • Provide technical expertise in the development and maintenance of CLP’s cyber security policies, standards and guidelines. • Take a key role to ensure CLP implement IT & OT secure architecture designs including the configuration of the security settings. • Strengthen the business case review process by ensuring conformance to a secure architecture from both infrastructure and network perspectives. • Lead evaluation teams comprising of both CLP and external parties to identify fit-for-purpose cyber security technologies to ensure CLP’s successful implementation of cyber security solutions. • Develop security baseline requirements aligned with the CLP’s cyber security standards and adapt requirements as new technology and infrastructures emerge. • Provide coaching and mentoring support to other security architects and Group Security team members in the field of IT & OT cyber security. • Direct and monitor the implementation of security initiatives within Group Security. • Provide specialist support to the Cyber Security Operations team in the event of cyber security incidents, both IT and OT. • Provide Management of vendors for project deliverables and technical support activities.
Requirements
• Educated to a university degree level or above. • At least 6 years’ experience in OT and OT cyber security with at least 5 years of cybersecurity experience in infrastructure design and implementation. • A Certified Information Systems Security Professional (CISSP). • SABSA Chartered Foundation (SCF) Certificate (or other suitable qualification). • Global Industrial Cyber Security Professional (SANS) or equivalent OT-cyber security qualification. • Practical experience in cyber security architecture and demonstrable experience developing IT, OT and IT/OT convergence architectures. • Experience with evaluating security vulnerabilities and developing mitigation strategies for networking systems. • Experience using recognised industry security frameworks (NIST, ISO, etc.). • Experience with supporting and executing cyber risk management. • Experience of security architecture requirements engineering. • Solid vendor management experience with considerable focus on outcome-based scenarios. • Strong leadership and influencing skills to both internal and external parties. • Trust-worthy and self-motivated, able to work under pressure and with minimal supervision. • The ability to explain technical security requirements in a non-technical manner. • Fluent in English and Chinese, verbal and written.