JobConnect

Assistant Manager – Technology Risk Management

Responsibilities

  • Manage the critical system security compliance program, maintain a comprehensive register of requirements and deliverables (e.g. security policies and standards, risk and audit reports, training and control tasks), track obligations and escalate compliance risks to ensure regulatory deadlines are met
  • Ensure cybersecurity policies, standards, and procedures align with security requirements, regulatory mandates, and the policies and standards, with clear mapping to internal controls
  • Coordinate security assessments and audits of critical systems. Act as the key liaison for auditors/ assessors, and track audit findings and remediation actions to closure
  • Maintain compliance evidence and documentation (e.g. risk assessments, test results, training logs, and incident records) to support audits and regulatory inspections
  • Partner with information security leaders, cybersecurity leads, system owners, and internal control functions (Risk, Internal Audit, Legal) to monitor compliance status, address gaps, and embed security requirements into business operations

Requirements

  • Bachelor in Computer Science, Information Security, or a related discipline
  • A minimum of 5 years' experience in IT security governance, compliance management, or technology audit roles, preferably in a regulated or critical infrastructure environment. Experience in managing compliance programs or audits is highly preferred
  • Possession of relevant certifications such as CISA, CISM, CISSP, CISP or equivalent is strongly preferred
  • Possession of solid understanding of information security policies and risk management processes, and familiarity with cybersecurity regulations and standards (e.g., ISO 27001/ 27002, NIST CSF). Experience in security audits, evidence management and knowledge of Protection of Critical Infrastructures (Computer Systems) Ordinance (Cap. 653) and the associated Code of Practice will be an advantage
  • Exceptional organizational skills, with the ability to manage multiple compliance tasks and deadlines. Strong communication skills to coordinate across departments and auditors, and produce clear compliance documentation

Applications

You are invited to apply online via http://www.mtr.com.hk/mtr\_job\_en or send in your CV stating the position (with reference number) you are applying for by mail to Human Resource Management Department, MTR Corporation, G.P.O. Box 9916, Hong Kong on or before 24 September 2026.
For other job openings, please visit MTR Corporation's website for more details.
All information provided by applicants will be treated in strict confidence and used for recruitment purpose only. All personal data of unsuccessful applicants will be retained for 12 months for future recruitment purpose and will then be destroyed.

Primary Location

Hong Kong

Schedule

Full-time

Job Posting

10/Sep/26, 9:59:05 AM

Closing Date

24/Sep/26, 3:59:00 PM

Job Number:

260000SM

Skills

  • Cybersecurity Compliance
  • Security Risk Assessment
  • Audit Management
  • Control Mapping
  • Regulatory Knowledge
  • Stakeholder Coordination
  • Documentation Management

Related jobs

MTR Corporation Limited 香港鐵路有限公司Apply for this job