Deputy Head of Information Security, IT
at CLSA LimitedCE AAB893
View & apply on the employer's site
Firm profile
Applications happen on the employer's own page - we link you straight there.
Job description
Position Description
The Deputy Head of Information Security will be based in Hong Kong and report directly to the Head of Information Security. The role is responsible for leading and managing cybersecurity and data security governance, risk management, compliance, security operations, and strategic security initiatives across CSI. The successful candidate will play a key leadership role in protecting the organization's information assets, ensuring regulatory compliance, and strengthening cyber resilience while enabling business growth and innovation.
Key Areas of Responsibilities
Governance, Strategy and Risk Management
Lead the development, maintenance, and continuous enhancement of CSI's cybersecurity and data security strategies, frameworks, policies, standards, and procedures.
Establish, implement, and enforce an enterprise-wide governance framework covering data management, data lifecycle management, data protection, and data loss prevention.
Identify, assess, prioritize, and report cybersecurity and data security risks, and drive effective risk mitigation strategies.
Provide regular cybersecurity risk, governance, and compliance reporting to senior management and relevant governance committees.
Establish and maintain cloud security governance frameworks supporting CSI's multi-cloud strategy across AWS, Azure, and Alibaba Cloud.
Regulatory Compliance and Audit
Ensure CSI's infrastructure, systems, and applications comply with applicable laws, regulations, and industry standards, including ISO 27001, NIST, GDPR, PDPO, PIPL, MAS, and other relevant regulatory requirements.
Maintain audit readiness and coordinate responses to regulatory examinations, compliance assessments, internal and external audits, client security questionnaires, and due diligence reviews.
Act as a key security liaison with regulators, auditors, compliance teams, and external stakeholders.
Security Operations and Cyber Resilience
Oversee Security Operations Centre (SOC) activities, threat monitoring, incident management, and Level 2 support for security technologies.
Govern CSI's vulnerability management program in collaboration with Application, Platform, and Infrastructure teams.
Security Architecture and Technology Oversight
Provide security oversight for enterprise architecture, cloud adoption, application security, infrastructure security, and technology transformation initiatives.
Ensure security controls and monitoring capabilities are appropriately designed and implemented across on-premises and cloud environments.
Evaluate emerging technologies and cybersecurity threats, providing recommendations to strengthen CSI's security posture.
Third-Party Risk Management
Oversee third-party cybersecurity risk management processes and security assessments for vendors, service providers, and outsourcing arrangements.
Ensure appropriate security controls and contractual requirements are embedded in third-party engagements.
Security Awareness and Stakeholder Management
Oversee enterprise-wide security awareness, education, and training programs to strengthen the organization's security culture.
Build strong relationships with business, technology, risk, compliance, legal, and operational stakeholders.
Drive cross-functional initiatives to deliver secure, resilient, and compliant technology services.
Leadership and Team Management
Support the Head of Information Security in developing and executing the overall security strategy and roadmap.
Mentor, coach, and develop cybersecurity professionals and foster a high-performance security culture.
Manage the information security project portfolio and ensure effective delivery of cybersecurity initiatives.
Lead cybersecurity incident response, investigation, recovery, and lessons-learned activities.
Ensure cyber resilience, disaster recovery, and business continuity capabilities are established, maintained, and regularly tested.
Lead and coordinate cybersecurity tabletop exercises and crisis simulation exercises.
Requirements
Bachelor’s degree or above in computer science, engineering or related domain discipline
Minimum 15 years of relevant experience in IT, cyber, and data security
Deep understanding of / Demonstrating familiarity with Cyber Security topics – Firewalls, WAF, Application security, Cloud security, web gateway, endpoint protection, SIEM, threat hunting, identity access management, application whitelisting, O365, data leakage protection, network security, email security, etc.
Strong interpersonal, organizational and problem-solving skills as well as project management, client serving, multi-tasking
Able to work independently, attention to details, result-driven
Enthusiastic, self-motivated with proactive mindset
Strong leadership skills and people management skills
Able to drive projects involving multiple teams and knowledge domains
Excellent command of / fluent in both reading, speaking and writing (English and Chinese (Putonghua is a must))
Certification – required — CISSP, or CISM/CIS/ ISO 27001 Lead Implementer/ Auditor
Stay informed on CITIC CLSA Job Opportunities
Not the right fit? You can create a job alert to receive our latest job openings that meet your interest.
Licensed entities behind this employer
-
CLSA LimitedCE AAB8931370 licensed staffLicence types 1, 4, 7
-
CITIC Securities (Hong Kong) LimitedCE AAK249950 licensed staffLicence types 4, 6
Check the firm's licence types, headcount trend and where its people come from and go before you apply.
More openings at this employer
- Associate, Quality Control, Investment Banking AssociateFront office2026-09-01
- Sr. Business Analyst, Asset Management IT, IT AnalystFront office
- Lead Support Analyst, FICC and EQD Applications Analyst2026-08-28
- Manager, Research Data, IT Research2026-08-28
- Sr. Business Analyst, Research Data/AI, IT AnalystResearch2026-08-28
- Senior Finance Manager – FICC & EQD, Finance Finance / Accounting2026-08-27
More jobs at this firm (187)
Similar jobs at other firms
- IT Institutional Analyst and Support Rui Da International Finance Holding LimitedAnalyst
- Network Engineer Phillip Securities (Hong Kong) LimitedAnalyst
- Software Engineer / Senior Software Engineer Phillip Securities (Hong Kong) LimitedAnalyst
- Vice President, Algo Trading / SOR – Developer Galaxy Digital HK LimitedVice President
- Vice President, Trading Systems Developer Galaxy Digital HK LimitedVice President
- Quantitative Developer Intern (Data) Y-Intercept (Hong Kong) LimitedIntern / Graduate
Aggregated from the employer's official careers page. Listing data refreshes daily; the employer's page is authoritative. Employers: to correct or remove a listing, see about our jobs crawler.