Назад
Company hidden
1 месяц назад

Cybersecurity and Information Security Analyst (AI Governance)

Формат работы
onsite
Тип работы
fulltime
Грейд
junior
Английский
b2
Страна
China
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Cybersecurity and Information Security Analyst (AI Governance) (ISO 27001/ISO 42001, GDPR): Safeguarding digital infrastructure through vulnerability management, incident response, audit readiness, and data privacy frameworks with an accent on enterprise compliance, AI governance, and multi-region risk management. Focus on conducting threat hunting, leading forensic incident mitigation, and translating technical security risks into effective controls across engineering and operational teams.

Location: Hong Kong; on-site

Company

Expanding global technology company focused on safeguarding digital infrastructure and maintaining international compliance and information security standards.

What you will do

  • Own vulnerability management across application and infrastructure layers, including automated scans, SAST/DAST prioritization, and technical remediation.
  • Lead the incident response lifecycle, from security monitoring and containment through forensic mitigation and root-cause reporting.
  • Direct internal and external IT audits and maintain ISO 27001, ISO 42001, and SOC compliance programs.
  • Develop and maintain data governance and privacy frameworks, including GDPR requirements, across global operating regions.
  • Conduct threat hunting and use threat intelligence to strengthen security controls.
  • Partner with engineering and operations teams on security standards, risk evaluation, and cybersecurity training.

Requirements

  • At least 2 years of hands-on experience in information security, IT compliance, or risk management in technology or cloud environments.
  • Practical knowledge of ISO 27001, ISO 42001, and SOC reporting.
  • Understanding of software development lifecycles, IT infrastructure, network architecture, vulnerability scanning, and incident response.
  • Strong knowledge of global data privacy regulations, including GDPR, and data governance frameworks.
  • Analytical, problem-solving, and communication skills for explaining technical risks to cross-functional stakeholders.

Nice to have

  • Security or compliance certifications such as CISSP, CCEP, ISO Lead Implementer, or ISO Lead Auditor.

Culture & Benefits

  • Fast-paced environment with operations across multiple regions.
  • Opportunity to work on enterprise compliance, AI data governance, and proactive risk management.
  • Collaboration with engineering and operational squads.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →