Cyber Security Consultant
Remoly · Hong Kong SAR
Apply & track with Apply EdgeJob ResponsibilitiesDeliver cybersecurity consulting and security assessment projects for clients across Hong Kong and Mainland China, with a focus on the Greater Bay Area.Independently handle cybersecurity projects from planning and assessment through reporting and client follow-up, including:Security risk assessments and risk analysisSecurity and compliance control reviewsVulnerability assessments and scanningConfiguration and infrastructure security reviewsPrivacy and data protection assessmentsPenetration testingCloud and web application security assessmentsReview clients’ remediation plans, validate corrective actions, maintain risk registers and supporting evidence, and ensure high-quality project delivery.Prepare clear and professional assessment reports, findings, recommendations, and supporting documentation for clients.Support pre-sales activities, including understanding client requirements, estimating project effort, preparing technical proposals and solutions, and participating in client meetings.Stay up to date with emerging cybersecurity risks, particularly AI security, AI governance, and security risks related to AI Agent applications.Job Requirements3+ years of relevant experience in cybersecurity consulting, information security, IT audit, penetration testing, privacy compliance, security assessment, or a related field.Solid understanding of the methodology, delivery process, and documentation requirements of security audit and security assessment projects.Familiarity with Hong Kong cybersecurity and data privacy requirements, including S17, G3, ISPG-SM01, PDPO, PCPD guidelines, and related standards or regulatory requirements.Good understanding of cybersecurity risks and controls across areas such as infrastructure, applications, cloud environments, network security, and data protection.Knowledge of AI security, AI governance, and security risks associated with AI Agent applications.Fluent in both Cantonese and Mandarin; strong English communication skills are an advantage.Strong client-facing and communication skills, with the ability to independently manage tasks, solve problems, analyze risks, and produce professional documentation.Willingness to travel between Hong Kong and Mainland China when required.Preferred QualificationsExperience delivering cybersecurity assessment or audit projects for Hong Kong Government departments, public institutions, financial institutions, technology companies, or large enterprises.Relevant professional certifications, such as CISSP, CISA, CISM, CEH, OSCP, ISO 27001 LA/LI, are highly desirable.Experience in AI security assessment, AI governance, cloud security, penetration testing, or privacy/data protection consulting is a strong advantage.