CyberSecurity Risk Manager

  • Develop and maintain the organisation’s cybersecurity risk management strategy
  • Conduct cybersecurity risk assessments and analyses to identify threats, categorise assets, assess vulnerabilities, and recommend risk treatment options
  • Identify and assess cybersecurity-related threats and vulnerabilities of ICT systems and maintain awareness of the evolving threat landscape
  • Perform Business Impact Assessments and support cybersecurity risk-based decision making
  • Design, implement, monitor, and evaluate cybersecurity controls to ensure risks remain at acceptable levels
  • Implement and maintain cybersecurity risk management frameworks, methodologies, standards, and best practices
  • Support compliance with security, risk, governance, and regulatory requirements
  • Enable business stakeholders, asset owners, and executives to make risk-informed decisions
  • Promote a cybersecurity risk-aware culture across the organisation
  • Develop and maintain cybersecurity risk registers, reports, metrics, and documentation
  • Support threat modelling activities for systems, applications, and DevOps environments
  • Contribute to the design of Zero Trust Architecture and security controls for critical enterprise services, including Directory Services
  • Support personal data protection and information security governance initiatives
  • Communicate risk management activities, findings, and recommendations to relevant stakeholders
  • Minimum 9 years of relevant IT professional experience, with at least 6 years in a cybersecurity risk management, information security governance, cybersecurity architecture, or similar role.
  • Minimum education level: Level 7 (Master's degree or equivalent) in an ICT-relevant field.
  • At least 4 of the following certifications:
    • CISA (Certified Information Systems Auditor)
    • CISM (Certified Information Security Manager)
    • CRISC (Certified in Risk and Information Systems Control)
    • CISSP (Certified Information Systems Security Professional)
    • CGRC (Certified in Governance, Risk and Compliance)
    • CSSLP (Certified Secure Software Lifecycle Professional)
    • CCSP (Certified Cloud Security Professional)
    • CISSP-ISSMP (Certified Information Systems Security Management Professional)
    • GSNA (GIAC Certified Systems and Network Auditor)
    • GCCC (GIAC Certified Critical Controls)
    • GIAC Certified ISO-27000 Specialist
    • ISO 27001 Lead Implementer
    • ISO 27001 Lead Auditor
    • ISO 27005 Risk Manager
    • or equivalent, internationally recognized certification
  • Excellent verbal and written communication in English, C1+ certificate desirable
  • Advanced knowledge of cybersecurity risk management frameworks, methodologies, standards, regulatory requirements, tools, best practices, cyber threats, threat taxonomies, vulnerabilities, risk assessment methodologies, risk treatment strategies, and security controls.
  • Experience performing cybersecurity risk assessments, cyber risk analysis, Business Impact Assessments, threat modelling activities, and monitoring the effectiveness of security controls within enterprise environments.
  • Experience implementing cybersecurity governance, risk and compliance processes, including ServiceNow GRC, personal data protection documentation, and organisational risk management practices.
  • Experience designing and assessing security architectures and controls, including Zero Trust Architecture, Secure Software Development Lifecycle (Secure SDLC), threat modelling for DevOps environments, and security controls for Directory Services.
  • Ability to analyse and consolidate organisational risk management and quality management practices, propose and manage risk treatment, risk mitigation and risk-sharing strategies, and communicate recommendations to technical and non-technical stakeholders, including senior management.
  • Excellent communication, documentation, analytical, problem-solving, and stakeholder management skills, with the ability to work independently and provide expert guidance on cybersecurity risk management matters.

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available