jobs in Nahc.io

全职 Cybersecurity and Information Security Analyst 工作, 薪水, Nahc.io Hong Kong 公司招聘中 - Ricebowl

Cybersecurity and Information Security Analyst

Nahc.io

Hong Kong

分享
保存

工作地点

  • Hong Kong Hong Kong

职位描述

岗位职责

Overview
Our client is an expanding global technology company, seeking an experienced Compliance and Information Security Analyst to safeguard its digital infrastructure and maintain top-tier international standards. You will oversee corporate compliance, audit readiness, data privacy frameworks, and threat mitigation across multi-region operating markets. This position is ideal for a detail-oriented security professional looking to drive enterprise compliance, AI data governance, and proactive risk management in a fast-paced environment.

What You Will Do

  • Own end-to-end vulnerability management—scheduling automated scans, prioritizing SAST/DAST findings, and driving technical remediation across application and infrastructure layers.
  • Lead the complete incident response lifecycle, managing security event monitoring, containment, forensic mitigation, and root-cause reporting for executive leadership.
  • Direct internal and external IT audits, maintaining certification programs across ISO 27001, ISO 42001 standards and SOC compliance.
  • Develop, implement, and maintain data governance and privacy frameworks (e.g., GDPR) across existing and expanding global operating regions.
  • Conduct continuous threat hunting using updated threat intelligence to proactively strengthen controls and prevent security violations.
  • Partner with engineering and operational squads to enforce security standards, evaluate risks in new initiatives, and conduct staff cybersecurity training.

What You Will Need

  • 2+ years of hands-on experience in information security, IT compliance, or risk management within modern technology or cloud environments.
  • Practical expertise with core compliance frameworks and standards, specifically ISO 27001, SOC reporting, and ISO 42001 (Artificial Intelligence Management Systems).
  • Solid technical understanding of software development lifecycles, IT infrastructure, network architectures, vulnerability scanning, and structured incident response.
  • Deep knowledge of global data privacy regulations (e.g., GDPR) and data governance frameworks.
  • Industry security or compliance certifications (e.g., CISSP, CCEP, ISO Lead Implementer/Auditor, or equivalent professional credentials) are strongly preferred.
  • Excellent analytical, problem-solving, and communication skills to effectively translate technical risks to cross-functional stakeholders.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

重要安全守则

申请工作时,切勿提供您的银行或信用卡详细资料。不要转账或完成无关的在线调查问卷。如果您发现可疑内容,请举报此招聘广告。

了解更多