1 месяц назад
Cybersecurity and Information Security Analyst (AI Governance)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Cybersecurity and Information Security Analyst (AI Governance) (ISO 27001/ISO 42001, GDPR): Safeguarding digital infrastructure through vulnerability management, incident response, audit readiness, and data privacy frameworks with an accent on enterprise compliance, AI governance, and multi-region risk management. Focus on conducting threat hunting, leading forensic incident mitigation, and translating technical security risks into effective controls across engineering and operational teams.
Location: Hong Kong; on-site
Company
Expanding global technology company focused on safeguarding digital infrastructure and maintaining international compliance and information security standards.
What you will do
- Own vulnerability management across application and infrastructure layers, including automated scans, SAST/DAST prioritization, and technical remediation.
- Lead the incident response lifecycle, from security monitoring and containment through forensic mitigation and root-cause reporting.
- Direct internal and external IT audits and maintain ISO 27001, ISO 42001, and SOC compliance programs.
- Develop and maintain data governance and privacy frameworks, including GDPR requirements, across global operating regions.
- Conduct threat hunting and use threat intelligence to strengthen security controls.
- Partner with engineering and operations teams on security standards, risk evaluation, and cybersecurity training.
Requirements
- At least 2 years of hands-on experience in information security, IT compliance, or risk management in technology or cloud environments.
- Practical knowledge of ISO 27001, ISO 42001, and SOC reporting.
- Understanding of software development lifecycles, IT infrastructure, network architecture, vulnerability scanning, and incident response.
- Strong knowledge of global data privacy regulations, including GDPR, and data governance frameworks.
- Analytical, problem-solving, and communication skills for explaining technical risks to cross-functional stakeholders.
Nice to have
- Security or compliance certifications such as CISSP, CCEP, ISO Lead Implementer, or ISO Lead Auditor.
Culture & Benefits
- Fast-paced environment with operations across multiple regions.
- Opportunity to work on enterprise compliance, AI data governance, and proactive risk management.
- Collaboration with engineering and operational squads.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
11 дней назад
Chief Information Security Officer (Digital Assets)
10 дней назад
Cloud Security & DWP Consultant (Cybersecurity)
10 дней назад
Consultant - Cloud Security & DWP (Cybersecurity)
Crypto
13 дней назад
Digital Trust and Resilience Engineer (Security Governance)
13 дней назад