
Senior Technology Risk Analyst / Lead
Lalamove
ðŸ‡ðŸ‡° Hong Kong
On-site
Staff / Principal
1 day ago
- Vulnerability Management
- Incident Response
- Network Security
- AI
- ISO 27001
- PCI DSS
- Risk Management
- DevSecOps
- CI/CD
- CRISC
- CISA
- CISM
1 day ago
We are seeking an experienced Senior Network and Security Analyst/Lead to deploy, optimize, and maintain robust cybersecurity solutions and network infrastructure across our enterprise environment. In this role, you will lead vulnerability management operations, strengthen defense and incident response capabilities, and ensure network security systems are optimized to mitigate risks.
What you will do:
- Risk Assessment & Tracking: Maintain the enterprise risk register and conduct comprehensive risk assessments across IT infrastructure, cloud environments, and the System Development Life Cycle (SDLC) for various organizational projects and technical assets.
- Remediation Coordination: Coordinate risk remediation plans across different teams and meticulously track risk acceptance decisions.
- Reporting & Visibility: Develop and maintain risk dashboards, generating clear, high-level executive summaries for management review.
- Emerging Tech Governance: Champion and drive AI security governance initiatives to ensure the safe and compliant adoption of artificial intelligence technologies
- Audit & Compliance: Actively support internal audit initiatives and facilitate robust security control testing. Maintain and continuously improve the Information Security Management System (ISMS) in compliance with ISO 27001 standards. Conduct regular PCI DSS assessments.
What you will need:
- Education: Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, Business Administration, or a related field.
- Experience: 5+ years of experience in IT Risk Management, Information Security, Compliance, or IT Audit.
- Technical Skills:
- Strong understanding of risk assessment methodologies and frameworks (e.g., NIST CSF, ISO 27001, PCI DSS).
- Experience maintaining risk registers and tracking remediation lifecycles.
- Solid knowledge of IT infrastructure (networks, databases, cloud architecture) and secure system development practices (e.g., DevSecOps, CI/CD pipelines, secure architecture) to accurately identify and evaluate technical vulnerabilities.
- Familiarity with privacy regulations and emerging AI governance standards.
- Soft Skills: Exceptional communication skills with the ability to translate complex technical risks into business terms for management and stakeholders.
- Certifications (Preferred): CRISC, CISA, CISM, ISO 27001 Lead Auditor or similar industry-recognized risk and audit certifications.
Senior Technology Risk Analyst / Lead · Lalamove