Deputy Head of Information Security, IT

citicclsa· 1899 CITIC Securities International Company Limited
Apply Now ↗
📍 Hong KongFull time

About this role

Position Description
The Deputy Head of Information Security will be based in Hong Kong and report directly to the Head of Information Security. The role is responsible for leading and managing cybersecurity and data security governance, risk management, compliance, security operations, and strategic security initiatives across CSI. The successful candidate will play a key leadership role in protecting the organization's information assets, ensuring regulatory compliance, and strengthening cyber resilience while enabling business growth and innovation.

Key Areas of Responsibilities

Governance, Strategy and Risk Management

  • Lead the development, maintenance, and continuous enhancement of CSI's cybersecurity and data security strategies, frameworks, policies, standards, and procedures.

  • Establish, implement, and enforce an enterprise-wide governance framework covering data management, data lifecycle management, data protection, and data loss prevention.

  • Identify, assess, prioritize, and report cybersecurity and data security risks, and drive effective risk mitigation strategies.

  • Provide regular cybersecurity risk, governance, and compliance reporting to senior management and relevant governance committees.

  • Establish and maintain cloud security governance frameworks supporting CSI's multi-cloud strategy across AWS, Azure, and Alibaba Cloud.

Regulatory Compliance and Audit

  • Ensure CSI's infrastructure, systems, and applications comply with applicable laws, regulations, and industry standards, including ISO 27001, NIST, GDPR, PDPO, PIPL, MAS, and other relevant regulatory requirements.

  • Maintain audit readiness and coordinate responses to regulatory examinations, compliance assessments, internal and external audits, client security questionnaires, and due diligence reviews.

  • Act as a key security liaison with regulators, auditors, compliance teams, and external stakeholders.

Security Operations and Cyber Resilience

  • Oversee Security Operations Centre (SOC) activities, threat monitoring, incident management, and Level 2 support for security technologies.

  • Govern CSI's vulnerability management program in collaboration with Application, Platform, and Infrastructure teams.

Security Architecture and Technology Oversight

  • Provide security oversight for enterprise architecture, cloud adoption, application security, infrastructure security, and technology transformation initiatives.

  • Ensure security controls and monitoring capabilities are appropriately designed and implemented across on-premises and cloud environments.

  • Evaluate emerging technologies and cybersecurity threats, providing recommendations to strengthen CSI's security posture.
     

Third-Party Risk Management

  • Oversee third-party cybersecurity risk management processes and security assessments for vendors, service providers, and outsourcing arrangements.

  • Ensure appropriate security controls and contractual requirements are embedded in third-party engagements.

Security Awareness and Stakeholder Management

  • Oversee enterprise-wide security awareness, education, and training programs to strengthen the organization's security culture.

  • Build strong relationships with business, technology, risk, compliance, legal, and operational stakeholders.

  • Drive cross-functional initiatives to deliver secure, resilient, and compliant technology services.
     

Leadership and Team Management

  • Support the Head of Information Security in developing and executing the overall security strategy and roadmap.

  • Mentor, coach, and develop cybersecurity professionals and foster a high-performance security culture.

  • Manage the information security project portfolio and ensure effective delivery of cybersecurity initiatives.

  • Lead cybersecurity incident response, investigation, recovery, and lessons-learned activities.

  • Ensure cyber resilience, disaster recovery, and business continuity capabilities are established, maintained, and regularly tested.

  • Lead and coordinate cybersecurity tabletop exercises and crisis simulation exercises.

     

Requirements

  • Bachelor’s degree or above in computer science, engineering or related domain discipline

  • Minimum 15 years of relevant experience in IT, cyber, and data security

  • Deep understanding of / Demonstrating familiarity with Cyber Security topics – Firewalls, WAF, Application security, Cloud security, web gateway, endpoint protection, SIEM, threat hunting, identity access management, application whitelisting, O365, data leakage protection, network security, email security, etc.

  • Strong interpersonal, organizational and problem-solving skills as well as project management, client serving, multi-tasking

  • Able to work independently, attention to details, result-driven

  • Enthusiastic, self-motivated with proactive mindset

  • Strong leadership skills and people management skills

  • Able to drive projects involving multiple teams and knowledge domains

  • Excellent command of / fluent in both reading, speaking and writing (English and Chinese (Putonghua is a must))

  • Certification – required — CISSP, or CISM/CIS/ ISO 27001 Lead  Implementer/ Auditor

Stay informed on CITIC CLSA Job Opportunities

Not the right fit? You can create a job alert to receive our latest job openings that meet your interest.

Frequently Asked Questions

Is the salary disclosed for the Deputy Head of Information Security, IT position at citicclsa?
The salary for this Deputy Head of Information Security, IT role at citicclsa is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the Deputy Head of Information Security, IT position at citicclsa located?
This Deputy Head of Information Security, IT role at citicclsa is based in Hong Kong. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Is the Deputy Head of Information Security, IT role at citicclsa full-time or part-time?
This is listed as a Full time position. It is posted as a Deputy Head of Information Security, IT role in the 1899 CITIC Securities International Company Limited department at citicclsa.
Which team or department does the Deputy Head of Information Security, IT at citicclsa belong to?
This Deputy Head of Information Security, IT position is part of the 1899 CITIC Securities International Company Limited department at citicclsa. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Deputy Head of Information Security, IT position at citicclsa?
Click the "Apply Now" button on this page. You will be redirected to citicclsa's official application portal hosted on workday where you can submit your application directly.
When was the Deputy Head of Information Security, IT job at citicclsa posted?
This Deputy Head of Information Security, IT position at citicclsa was posted on Aug 26, 2026. Apply as soon as possible — early applications are often reviewed first.
Deputy Head of Information Security, IT
citicclsa
Apply for this role ↗

You'll be redirected to citicclsa's official application page on Workday.