All jobs
PCCW

Vice President, IT Security & Platform

PCCW

Hong Kong, HK, HK, Hong KongDirectorFull-timeSoftware Engineering Sign in for match

About the role

Key Responsibilities


Cybersecurity Leadership & Governance

  • Develop and execute the enterprise cybersecurity strategy and roadmap

  • Establish security governance, policies, and control frameworks.

  • Lead cybersecurity transformation initiatives and continuous improvement programs.

  • Provide strategic direction for security technologies, and cybersecurity capabilities.

  • Establish and promote a cybersecurity awareness program across the organisation, including security training, phishing simulations, and awareness campaigns.

  • Present cybersecurity strategy, risk posture, and key initiatives to senior management, risk committees, and the Board where applicable.

Technology Risk Management

  • Establish and maintain the technology risk management framework.

  • Oversee technology risk and control assessments

  • Manage technology risk committees, risk reporting and Key Risk Indicators (KRIs).

  • Oversee IT exemption management and risk acceptance processes.

  • Manage IT audits, regulatory reviews, and other assessment engagements, and oversee the implementation of remediation programs.

  • Drive continuous improvement initiatives to enhance technology risk management and governance practices.

  • Lead and coordinate security drills and cyber resilience exercises.

Security Operations & Incident Response

  • Provide executive oversight of Security Operations Centre (SOC) functions.
  • Ensure effective 24x7 monitoring, threat detection, investigation, and incident response.
  • Oversee security incident management, forensic investigations, root cause analysis, containment, and recovery activities.
  • Direct threat intelligence, threat hunting, alert management, and use case development activities.
  • Ensure timely management reporting on security events and operational effectiveness.

Security Engineering

  • Lead the implementation of security engineering to deploy new security tools and processes.

  • Ensure secure implementation of infrastructure security controls including firewalls, VPNs, endpoint security, and network security.

  • Conduct the security assessment for new initiatives

  • Oversee the operation of application security including DevSecOps, API security, container security, and CI/CD security.

  • Govern security tool implementation and optimization including SIEM, EDR, SOAR, DLP, and vulnerability management technologies.

  • Drive security automation, orchestration, and hardening initiatives.

  • Oversee vulnerability assessment, penetration testing and security validation

  • Provide security advisory


Identity & Access Management (IAM)

  • Establish IAM governance, strategy, and operational controls.

  • Oversee identity lifecycle management, authentication services, privileged access management, and access recertification programs.

  • Manage the administration of privileged accounts to ensure they’re secured.

  • Conduct day-to-day operation for user accounts including provisioning/deprovisioning, recertification, dormant ID management, etc

  • Ensure segregation of duties controls are effectively implemented and monitored.

  • Oversee key and certificate management operations.

  • Lead IAM transformation and integration initiatives across the enterprise.


Third-Party Security Management

  • Conduct the third-party cybersecurity assessment for key service providers.
  • Oversee security assessments of vendors and external service providers.
  • Monitor third-party security risks and remediation activities

Secured Room Management

  • Manage the operation and administration of physical access controls for secured rooms.
  • Conduct periodic security reviews to verify compliance with physical security requirements for secured rooms.
  • Develop and enhance automated workflow for physical access request, approval, provisioning, and revocation processes.

Qualifications & Experience


Education

  • Degree in Computer Science, Information Systems and Technology, or related discipline.

Experience

  • 8+ years of information security and technology risk management experience.
  • 10+ years in a senior leadership role managing multi-disciplinary technology teams.
  • Proven experience leading Security Operations, Security Engineering, IAM, and Technology Risk functions.
  • Experience reporting cybersecurity risk posture to senior executives and risk committees.
  • Proven track record in cybersecurity transformation and security program leadership.
  • Experience within financial services, government, or highly regulated environments is highly desirable.