We are currently looking for a GRC Analyst to join a leading organisation in Hong Kong. This role will focus on Information Security Governance, Risk and Compliance , working closely with technology and business stakeholders to identify and manage security risks and ensure compliance with relevant standards and regulatory requirements.
Key Responsibilities
- Support Information Security Governance, Risk and Compliance (GRC) activities across the organisation.
- Conduct IT and Information Security risk assessments , control assessments and gap analyses.
- Support the implementation and maintenance of ISO 27001 security controls and requirements.
- Assist in reviewing security policies, standards, procedures and control frameworks.
- Monitor security risks, exceptions and remediation actions, ensuring timely follow-up.
- Support internal and external audits , including audit preparation, evidence collection and remediation tracking.
- Assess applicable regulatory and compliance requirements and support their implementation within the organisation.
- Prepare risk, compliance and security reports for management and relevant stakeholders.
- Work closely with IT, cybersecurity and business teams to identify control gaps and recommend appropriate improvements.
- Support ongoing security governance initiatives and maintain relevant risk and compliance documentation.
Requirements
- Degree in Information Security, Cybersecurity, IT, Computer Science or a related discipline.
-
Min.2years of relevant experience in GRC, Information Security, IT Risk, Technology Risk, IT Compliance or Security Governance.
- Candidates with 8–10+ years of relevant Information Security / GRC / IT Risk experience are also welcome to apply for senior-level opportunities.
- Practical experience with ISO 27001 is highly preferred.
- Experience in risk assessment, control assessment, gap analysis or security compliance .
- Knowledge of security frameworks such as NIST CSF, ISO 27001, COBIT or CIS Controls is an advantage.
- Experience supporting security audits, regulatory assessments or compliance reviews .
- Strong analytical, documentation and stakeholder management skills.
- Good command of English and Cantonese ; Mandarin is an advantage.
#J-18808-Ljbffr