
Assistant Vice President (AVP), Information Security Governance
- Shopify Liquid
- CIS Benchmarks
- Risk Management
- CISSP
- CISM
- ISO 27001
Company Introduction:
We’re home to Asia's most dynamic and vibrant capital markets.
Connecting capital, ideas, inspiration and innovation for deeper, more diverse and liquid global capital markets; providing greater choice and opportunity for our customers, each and every day.
HKEX is a purpose-driven company. Our commitment to the long-term development of our business and our markets is articulated in our purpose:"To Connect, Promote and Progress our Markets and the Communities they support for the prosperity of all."
Job Summary:
Job Duties:
Security Configuration
- Manage and maintain enterprise security configuration standards and baselines.
- Review and adopt the latestCenter for Internet Security (CIS) Benchmarks, ensuring alignment withHKEX security requirements.
- Overseeupdates to securityconfiguration scanning tools to incorporate the latest CISBenchmarks and security checks.
- Develop, review, and maintain Generic Security Baselines (GSBs) for technologies and platforms not covered by CIS Benchmarks.
- Ensure security configuration standards remain current, effective, and aligned with industry best practices and regulatory requirements.
Security Exception Management
- Administer the security exception management process forsecurityfindings.
- Review and validate exception requests toconfirm that appropriate business justification, risk assessment, compensating controls, and management approvals are in place.
- Assess and validatepotentialfalse-positive findings identified through securityconfiguration scans.
- Maintain accurate records of approved exceptions and monitor their validityperiodsand expiry dates.
Security Governance Operations and Approval
- Perform governance and approvalactivitiesto ensure securitystandards and operational requirements are met.
Whitelisting
- Review and approve website, file upload and email whitelisting requests in accordance with established security policies and risk management requirements.
Encryption and Key Management
- Review and approve encryption key management requests and related activities according tocryptographic standards and key management requirements.
Internal Certificate Authority (CA) Governance
- Review and approve requests related to internal Certificate Authority (CA) certificatesandensure proper issuance, renewal, usage, and management of digital certificates.
Privileged Elevation Governance
- Review and approve SUDO registration and privilegedescalation and ensure requestsis granted with least-privilege and security governance principles.
Security Acceptance Review
- Conduct Security AcceptanceChecklist (SAC) reviews and approvals as part of the SDLC process control.
- Assess and approve SSR requestsstating security requirements are not applicable, ensuring adequate justification and riskassessment are documented.
Non-Standard Software Assessment
- Review and approve requests forinstallation ofnon-standard software, with evaluation of associated operational, security, compliance, and technology risks.Ensure appropriate mitigating controls are established before approval
Job Requirement:
Technical & Professional Skills
- Minimum10 years of relevant experience inin information security governance, information security, technology risk management, compliance, or IT audit functions, preferably within financial services or a regulated environment.
- Good understanding ofinformation security governance, risk, and control concepts.
- Strong understanding of CIS Benchmarks, control principles, and security governance processes.
- Excellent analytical, communication, and stakeholder management skills.
- Ability toanalyse processes and identify gaps or improvement opportunities.
Qualifications
- Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, or related discipline.
- Relevant professional certifications such as CISSP, CISM, ISO 27001 Lead Implementer/Auditor,CCSPor equivalent are preferred.
HKEX is committed as an Equal Opportunity Employer. Diversity is one of our core values and we look to support, respect diverse perspectives, abilities, culture and experiences within our workplace.
Location:
HKEX - TKOShift:
Standard - 40 Hours (Hong Kong SAR)Scheduled Weekly Hours:
40Worker Type:
PermanentAssistant Vice President (AVP), Information Security Governance · Hong Kong Exchanges and Clearing Limited