- Location
- Hong Kong
- Type
- Full-time
- Closing date
- Today
- Source
- CareersPage
Description
We are currently looking for a GRC Analyst to join a leading organisation in Hong Kong. This role will focus on Information Security Governance, Risk and Compliance, working closely with technology and business stakeholders to identify and manage security risks and ensure compliance with relevant standards and regulatory requirements.
Key Responsibilities
- Support Information Security Governance, Risk and Compliance (GRC) activities across the organisation.
- Conduct IT and Information Security risk assessments, control assessments and gap analyses.
- Support the implementation and maintenance of ISO 27001 security controls and requirements.
- Assist in reviewing security policies, standards, procedures and control frameworks.
- Monitor security risks, exceptions and remediation actions, ensuring timely follow-up.
- Support internal and external audits, including audit preparation, evidence collection and remediation tracking.
- Assess applicable regulatory and compliance requirements and support their implementation within the organisation.
- Prepare risk, compliance and security reports for management and relevant stakeholders.
- Work closely with IT, cybersecurity and business teams to identify control gaps and recommend appropriate improvements.
- Support ongoing security governance initiatives and maintain relevant risk and compliance documentation.
Requirements
- Degree in Information Security, Cybersecurity, IT, Computer Science or a related discipline.
- Min.2 years of relevant experience in GRC, Information Security, IT Risk, Technology Risk, IT Compliance or Security Governance.
- Candidates with 8–10+ years of relevant Information Security / GRC / IT Risk experience are also welcome to apply for senior-level opportunities.
- Practical experience with ISO 27001 is highly preferred.
- Experience in risk assessment, control assessment, gap analysis or security compliance.
- Knowledge of security frameworks such as NIST CSF, ISO 27001, COBIT or CIS Controls is an advantage.
- Experience supporting security audits, regulatory assessments or compliance reviews.
- Strong analytical, documentation and stakeholder management skills.
- Good command of English and Cantonese; Mandarin is an advantage.