jobs in Hong Kong Hospital Authority

Hong Kong Hospital Authority Hiring! Full Time Chief Information Security Officer in Hong Kong - Ricebowl

Chief Information Security Officer

Hong Kong Hospital Authority

Undisclosed

Hong Kong

Share
Save

Working Location

  • Hong Kong Hong Kong Hong Kong

Job Description

Responsibilities

Department / Cluster:

Information Technology and Health Informatics Division, HA Head Office

Pay:

HK$161,107 to HK$185,614 per month including Monthly Allowance

Up to 15% of total basic salary (after deducting the contribution of Mandatory Provident Fund by Hospital Authority) as end-of-contract gratuity may be offered to contract staff upon completion of the contract subject to satisfactory performance. 

Key Responsibilities:

Reporting to the Chief Systems Manager (Infrastructure Services), the incumbent will take up a leading role in the area of Corporate Cybersecurity and Information Technology (IT) Risk Management.  Through leading and coordinating the IT security professionals, cluster hospitals and business units within Hospital Authority (HA), the incumbent is expected to establish, implement and maintain corporate-wide cybersecurity and IT risk strategy and plans to ensure that HA IT assets are adequately managed and protected:

  1. Formulate HA’s cybersecurity and IT risk management strategy aligning with HA business strategy.

  2. Develop and maintain cybersecurity and IT risk management roadmap and implementation plans.

  3. Establish, communicate and ensure compliance with relevant regulations, policies, standards and guidelines.

  4. Manage the Security Operations Centre (SOC) to defend against emerging cyber risks.

  5. Advise HA management on a broad range of cybersecurity and IT risk standards and best practices.

  6. Manage the IT security products portfolio and cybersecurity architecture.

  7. Monitor and report progress of cybersecurity and IT risk programs to governance bodies.

  8. Coordinate and work with various business units on IT and IT risk management projects covering risk analysis, risk management processes, roles and responsibilities.

  9. Provide strategic and tactical security guidance for all IT projects, including the evaluation and recommendation of technical controls and coordinate security risk assessment and audit activities.

  10. Liaise with the Enterprise Architecture Office to ensure alignment between the cybersecurity and enterprise architectures.

  11. Drive the corporate-level cybersecurity awareness and culture for HA staff.

  12. Support the HA Corporate Information Security and Privacy Office to implement appropriate technical controls to strengthen the confidentiality and protection of sensitive personal data.

Entry Requirements:

  1. A Degree in Computer Science or relevant disciplines; or equivalent.

  2. Over 15 years' post qualification Information Technology (IT) related experience.

Preferable Attributes / Exposure:

  1. Possession of Certified Information Systems Security Professional (CISSP) or equivalent.

  2. Over 8 years' experience at a managerial position including a minimum of 4 years acting as a top leader in cybersecurity in a major corporation.

  3. Experience with international information security management standards (e.g. ISO27001) implementation.

  4. Significant experience and training in a combination of information security, cybersecurity and IT risk management. 

  5. Visionary leader with strong acumen in technology and business management.

  6. Hands-on knowledge of cybersecurity and IT risk management standards, frameworks and implementations with good understanding of modern IT technologies (i.e. Cloud, IoT, Big Data and AI) and healthcare IT applications.

  7. Excellent written and verbal communication skills with the ability to communicate cybersecurity and IT risk-related concepts to technical and non-technical audiences.

  8. Skills in project management, financial management, scheduling and resources management.

  9. Ability to lead and motivate cross-functional, interdisciplinary teams to achieve tactical and strategic goals.

Remarks

  1. Please refer to *************;for “Notes to Applicants” .

  2. For serving HA staff, relevant experience gained in HA may be considered as equivalent to post-qualification experience.

  3. Please submit application online on or before 7 August 2026 via website ************* (click Careers).  For enquiries, please telephone ************* or *************.

Important Information

Never provide your bank or credit card details when applying for jobs. Do not transfer any money or complete unrelated online surveys. If you see something suspicious, Report this Job ad.

Learn More