HKEX logo

Assistant Vice President, Information Security Governance

HKEX

On-site
Tseung Kwan O, Hong Kong
Full-time
Manager
10+ yrs
Salary not listedPosted 1w ago

Real job — pulled straight from HKEX’s careers page · Verified September 12, 2026 · No reposts.

Job description

HKEX is hiring a Assistant Vice President, Information Security Governance — a full-time, based in Tseung Kwan O, Hong Kong role. Apply directly on HKEX's careers page below.

Assistant Vice President (AVP), Information Security Governance

Location: HK-TKO 5/F

Time Type: Full time

Job Description

Company Introduction:

We’re home to Asia's most dynamic and vibrant capital markets.
Connecting capital, ideas, inspiration and innovation for deeper, more diverse and liquid global capital markets; providing greater choice and opportunity for our customers, each and every day.


HKEX is a purpose-driven company. Our commitment to the long-term development of our business and our markets is articulated in our purpose: "To Connect, Promote and Progress our Markets and the Communities they support for the prosperity of all."

Job Summary:

Job Duties:

Security Configuration

  • Manage and maintain enterprise security configuration standards and baselines. 
  • Review and adopt the latest Center for Internet Security (CIS) Benchmarks, ensuring alignment with HKEX security requirements. 
  • Oversee updates to security configuration scanning tools to incorporate the latest CIS Benchmarks and security checks. 
  • Develop, review, and maintain Generic Security Baselines (GSBs) for technologies and platforms not covered by CIS Benchmarks. 
  • Ensure security configuration standards remain current, effective, and aligned with industry best practices and regulatory requirements. 

Security Exception Management

  • Administer the security exception management process for security findings. 
  • Review and validate exception requests to confirm that appropriate business justification, risk assessment, compensating controls, and management approvals are in place. 
  • Assess and validate potential false-positive findings identified through security configuration scans. 
  • Maintain accurate records of approved exceptions and monitor their validity periods and expiry dates. 

Security Governance Operations and Approval

  • Perform governance and approval activities to ensure security standards and operational requirements are met. 

Whitelisting

  • Review and approve website, file upload and email whitelisting requests in accordance with established security policies and risk management requirements. 

Encryption and Key Management

  • Review and approve encryption key management requests and related activities according to cryptographic standards and key management requirements. 

Internal Certificate Authority (CA) Governance

  • Review and approve requests related to internal Certificate Authority (CA) certificates and ensure proper issuance, renewal, usage, and management of digital certificates. 

 Privileged Elevation Governance

  • Review and approve SUDO registration and privileged escalation and ensure requests is granted with least-privilege and security governance principles. 

Security Acceptance Review

  • Conduct Security Acceptance Checklist (SAC) reviews and approvals as part of the SDLC process control. 
  • Assess and approve SSR requests stating security requirements are not applicable, ensuring adequate justification and risk assessment are documented. 

Non-Standard Software Assessment

  • Review and approve requests for installation of non-standard software, with evaluation of associated operational, security, compliance, and technology risks. Ensure appropriate mitigating controls are established before approval

Job Requirement:

Technical & Professional Skills

  • Minimum 10 years of relevant experience in in information security governance, information security, technology risk management, compliance, or IT audit functions, preferably within financial services or a regulated environment. 
  • Good understanding of information security governance, risk, and control concepts. 
  • Strong understanding of CIS Benchmarks, control principles, and security governance processes. 
  • Excellent analytical, communication, and stakeholder management skills. 
  • Ability to analyse processes and identify gaps or improvement opportunities. 

Qualifications

  • Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, or related discipline. 
  • Relevant professional certifications such as CISSP, CISM, ISO 27001 Lead Implementer/Auditor, CCSP or equivalent are preferred. 

HKEX is committed as an Equal Opportunity Employer. Diversity is one of our core values and we look to support, respect diverse perspectives, abilities, culture and experiences within our workplace.

Location:

HKEX - TKO

Shift:

Standard - 40 Hours (Hong Kong SAR)

Scheduled Weekly Hours:

40

Worker Type:

Permanent

Get Assistant Vice President, Information Security Governance jobs like this→

New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.

Email me new jobs
Starling Bank logo

Quantum Cryptography Architect

London, England
✓ From careers page· 10h ago
Starling Bank logo

Senior Cloud Security Engineer, GCP

London, England, United Kingdom
✓ From careers page· 10h ago
Starling Bank logo

Staff Cloud Security Engineer, GCP

London, England
✓ From careers page· 10h ago
Blumira logo

Solution Engineer, Post-Sales

$106k–$135kRemote · US-eligible
✓ From careers page· 10h ago

Frequently asked questions

What skills are required for Assistant Vice President, Information Security Governance at HKEX?

The required skills for Assistant Vice President, Information Security Governance at HKEX include: CISSP, CISM, ISO 27001.

What is the seniority level for Assistant Vice President, Information Security Governance at HKEX?

Assistant Vice President, Information Security Governance at HKEX is a Manager level position.

How do I apply for Assistant Vice President, Information Security Governance at HKEX?

You can view the full description and apply for Assistant Vice President, Information Security Governance at HKEX on EchoJobs: https://echojobs.io/job/hkex-assistant-vice-president-avp-information-security-governance-pcy2a.