Join a reputable bank in Hong Kong as an IT Security Manager within the Operations & IT Division, overseeing day‑to‑day information security, cybersecurity and IT risk controls for the branch. This role suits an experienced cybersecurity practitioner who can manage local security operations while aligning with group policies, regulatory expectations and the HKMA’s Enhanced Competency Framework on Cybersecurity (ECF‑C). Key Responsibilities Oversee information security, cybersecurity and IT risk management programmes for the bank, implementing and enforcing IT security policies and standards. Provide help‑desk support and troubleshooting for security events and incidents, including investigation, escalation and follow‑up actions. Perform local system account administration and periodic access reviews to ensure appropriate access control and segregation of duties. Coordinate with Head Office security teams to define and roll out system security policies, tools and projects at branch level. Design, maintain and enhance security network infrastructure and controls (e.g. firewalls, IPS, content filtering, DLP) to safeguard banking systems and data. Liaise with internal and external auditors and regulators on IT security matters, helping to address findings and ensure compliance with relevant regulatory and industry requirements. Requirements Degree or Associate Degree in Computer Science, Information Technology or related disciplines, plus ECF‑C recognised certification such as CRISC, CISA, CISM, CISSP, CEH or CCSP. Minimum 5 years’ information security / cybersecurity experience, preferably gained in the banking or wider financial services sector. Hands‑on experience with IP networking and internet‑based systems, and solid knowledge of security technologies such as firewalls, IPS, content filtering and DLP. Good understanding of Hong Kong banking regulatory expectations on cybersecurity and technology risk (e.g. HKMA guidelines, ECF‑C framework). Strong communication, interpersonal and leadership skills, able to work with IT, business and audit stakeholders and influence good security practices. Good command of spoken and written Chinese (including Mandarin) and English.