HKEX
Assistant Vice President (AVP), Information Security Governance
HK-TKO 5/F
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.5M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Seniority
- Executive
- Country
- HK
- Work mode
- On-site / unstated
- First seen by hirly
- 7 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Company Introduction:
- We’re home to Asia's most dynamic and vibrant capital markets.
- Connecting capital, ideas, inspiration and innovation for deeper, more diverse and liquid global capital markets; providing greater choice and opportunity for our customers, each and every day.
HKEX is a purpose-driven company. Our commitment to the long-term development of our business and our markets is articulated in our purpose: "To Connect, Promote and Progress our Markets and the Communities they support for the prosperity of all."
Job Summary:
Job Duties:
Security Configuration
Manage and maintain enterprise security configuration standards and baselines.
Review and adopt the latest Center for Internet Security (CIS) Benchmarks , ensuring alignment with HKEX security requirements.
Oversee updates to security configuration scanning tools to incorporate the latest CIS Benchmarks and security checks.
Develop, review, and maintain Generic Security Baselines ( GSBs ) for technologies and platforms not covered by CIS Benchmarks.
Ensure security configuration standards remain current, effective, and aligned with industry best practices and regulatory requirements.
Security Exception Management
Administer the security exception management process for security findings.
Review and validate exception requests to confirm that appropriate business justification, risk assessment, compensating controls, and management approvals are in place.
Assess and validate potential false - positive findings identified through security configuration scans.
Maintain accurate records of approved exceptions and monitor their validity periods and expiry dates .
Security Governance Operations and Approval
Perform governance and approval activities to ensure security standards and operational requirements are met.
Whitelisting
Review and approve website, file upload and email whitelisting requests in accordance with established security policies and risk management requirements.
Encryption and Key Management
Review and approve encryption key management requests and related activities a ccording to cryptographic standards and key management requirements.
Internal Certificate Authority (CA) Governance
Review and approve requests related to internal Certificate Authority (CA) certificates and e nsure proper issuance, renewal, usage, and management of digital certificates.
Privileged Elevation Governance
Review and approve SUDO registration and privileged escalation and e nsure requests is granted with least-privilege and security governance principles.
Security Acceptance Review
Conduct Security Acc eptance C hecklist (SAC) reviews and approvals as part of the SDLC process control .
Assess and approve SSR requests stating security requirements are not applicable, ensuring adequate justification and risk assessment are documented.
Non-Standard Software Assessment
Review and approve requests for installation of non-standard software , with e valuat ion of associated operational, security, compliance, and technology risks. Ensure appropriate mitigating controls are established before approval
Job Requirement:
Technical & Professional Skills
- Minimum 10 years of relevant experience in in information security governance , information security, technology risk management , compliance, or IT audit functions, preferably within financial services or a regulated environment.
- Good understanding of information security governance, risk, and control concepts.
Strong understanding of CIS Benchmarks, control principles, and security governance processes.
Excellent analytical, communication, and stakeholder management skills.
Ability to analyse processes and identify gaps or improvement opportunities.
Qualifications
Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, or related discipline.
Relevant professional certifications such as CISSP, CISM, ISO 27001 Lead Implementer/Auditor, CCSP or equivalent are preferred.
HKEX is committed as an Equal Opportunity Employer. Diversity is one of our core values and we look to support, respect diverse perspectives, abilities, culture and experiences within our workplace.
Location:
HKEX - TKO
Shift:
Standard - 40 Hours (Hong Kong SAR)
Scheduled Weekly Hours:
40
Worker Type:
Permanent
Similar jobs
- First Vice President, Talent Acquisition, Human ResourcesUobgroup · Hong Kong (City Area)First seen today
- Vice President, Credit CardsCncbinternationalFirst seen yesterday
- Assistant Vice President / Vice President, Product Management, Securities ServicesCncbinternationalFirst seen 2d ago
- Client Executive - Senior Vice PresidentCiti · Hong Kong Hong KongFirst seen 3d ago
- Assistant Vice President/ Senior Associate, Technology & Operations - Institutional Banking Group OperationsDbs · Kwun TongFirst seen 3d ago
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job