hirly

Citic Clsa

Deputy Head of Information Security, IT

Hong Kong

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Citic Clsa first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.6M live jobs from 190,000+ employers in 200+ countries.

Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Seniority
Lead / management
Country
HK
Work mode
On-site / unstated
First seen by hirly
27 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

  • Position Description
  • The Deputy Head of Information Security will be based in Hong Kong and report directly to the Head of Information Security. The role is responsible for leading and managing cybersecurity and data security governance, risk management, compliance, security operations, and strategic security initiatives across CSI. The successful candidate will play a key leadership role in protecting the organization's information assets, ensuring regulatory compliance, and strengthening cyber resilience while enabling business growth and innovation.

Key Areas of Responsibilities

Governance, Strategy and Risk Management

Lead the development, maintenance, and continuous enhancement of CSI's cybersecurity and data security strategies, frameworks, policies, standards, and procedures.

Establish, implement, and enforce an enterprise-wide governance framework covering data management, data lifecycle management, data protection, and data loss prevention.

Identify, assess, prioritize, and report cybersecurity and data security risks, and drive effective risk mitigation strategies.

Provide regular cybersecurity risk, governance, and compliance reporting to senior management and relevant governance committees.

Establish and maintain cloud security governance frameworks supporting CSI's multi-cloud strategy across AWS, Azure, and Alibaba Cloud.

Regulatory Compliance and Audit

Ensure CSI's infrastructure, systems, and applications comply with applicable laws, regulations, and industry standards, including ISO 27001, NIST, GDPR, PDPO, PIPL, MAS, and other relevant regulatory requirements.

Maintain audit readiness and coordinate responses to regulatory examinations, compliance assessments, internal and external audits, client security questionnaires, and due diligence reviews.

Act as a key security liaison with regulators, auditors, compliance teams, and external stakeholders.

Security Operations and Cyber Resilience

Oversee Security Operations Centre (SOC) activities, threat monitoring, incident management, and Level 2 support for security technologies.

Govern CSI's vulnerability management program in collaboration with Application, Platform, and Infrastructure teams.

Security Architecture and Technology Oversight

Provide security oversight for enterprise architecture, cloud adoption, application security, infrastructure security, and technology transformation initiatives.

Ensure security controls and monitoring capabilities are appropriately designed and implemented across on-premises and cloud environments.

Evaluate emerging technologies and cybersecurity threats, providing recommendations to strengthen CSI's security posture.

Third-Party Risk Management

Oversee third-party cybersecurity risk management processes and security assessments for vendors, service providers, and outsourcing arrangements.

Ensure appropriate security controls and contractual requirements are embedded in third-party engagements.

Security Awareness and Stakeholder Management

Oversee enterprise-wide security awareness, education, and training programs to strengthen the organization's security culture.

Build strong relationships with business, technology, risk, compliance, legal, and operational stakeholders.

Drive cross-functional initiatives to deliver secure, resilient, and compliant technology services.

Leadership and Team Management

Support the Head of Information Security in developing and executing the overall security strategy and roadmap.

Mentor, coach, and develop cybersecurity professionals and foster a high-performance security culture.

Manage the information security project portfolio and ensure effective delivery of cybersecurity initiatives.

Lead cybersecurity incident response, investigation, recovery, and lessons-learned activities.

Ensure cyber resilience, disaster recovery, and business continuity capabilities are established, maintained, and regularly tested.

Lead and coordinate cybersecurity tabletop exercises and crisis simulation exercises.

Requirements

Bachelor’s degree or above in computer science, engineering or related domain discipline

Minimum 15 years of relevant experience in IT, cyber, and data security

Deep understanding of / Demonstrating familiarity with Cyber Security topics – Firewalls, WAF, Application security, Cloud security, web gateway, endpoint protection, SIEM, threat hunting, identity access management, application whitelisting, O365, data leakage protection, network security, email security, etc.

Strong interpersonal, organizational and problem-solving skills as well as project management, client serving, multi-tasking

Able to work independently, attention to details, result-driven

Enthusiastic, self-motivated with proactive mindset

Strong leadership skills and people management skills

Able to drive projects involving multiple teams and knowledge domains

Excellent command of / fluent in both reading, speaking and writing (English and Chinese (Putonghua is a must))

Certification – required — CISSP, or CISM/CIS/ ISO 27001 Lead Implementer/ Auditor

Stay informed on CITIC CLSA Job Opportunities

Not the right fit? You can create a job alert to receive our latest job openings that meet your interest.

Original posting on Citic Clsa's site ↗

Listed on hirly, a job board. hirly is not the employer: Citic Clsa is hiring for this role.

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job