Manager, Information Security Office
Job Description:
Handling Information Security Management, addressing information security threats and incidents, and driving remediation.
In conjunction with the Legal team, identify information management and protection laws and regulations and implement actions to ensure compliance with relevant laws.
Identify, track, and oversee internal and external compliance and regulatory requirements (PCI, Data Privacy, etc.) for the organization including compliance with established policies, procedures, standards, baselines, and controls.
Maintain an information management and protection framework for an effective company-wide governance program.
Manage information security awareness programs and provide training to all staff.
Guide and support staff, and provide security training and awareness programs to promote a culture of security and best practices within the organization.
Manage day-to-day security activities, including conducting vendor security assessments and privacy security assessments, implementing company policies, and communicating related to the information security program.
Manage and Support the Information Security requirements across different BUs.
Support global projects as a regional ISO team member.
Work with security operations team to respond to security incidents (personal/confidential information, system hacking, local employee information leakage, information breach, store physical security, customer center security).
Job Requirements:
Degree holder in Management, Information Technology, Information Security, Computer Science, or related disciplines.
At least 6 years of experience in information security, cybersecurity, IT risk, or governance-related functions.
Strong knowledge of information security governance, risk assessment, compliance frameworks, and data privacy requirements.
Familiarity with cybersecurity standards, regulations, and best practices, with the ability to translate security requirements into practical business solutions.
Experience managing security controls across Microsoft 365, network, and enterprise technology environments.
Professional security certifications (e.g., CISSP, CISM, CISA, GIAC) are highly preferred.
Strong analytical thinking, business process improvement, and risk management capabilities.
Excellent communication and stakeholder management skills with the ability to influence and educate employees at all levels.
Proactive, adaptable, and highly accountable, with the ability to manage multiple projects and priorities independently.
Fluent in Cantonese , English and Mandarin.