
Assistant Manager – Technology Risk Management (Ref: 260000SM)
ResponsibilitiesManage the critical system security compliance program, maintain a comprehensive register of requirements and deliverables (e.g. security policies and standards, risk and audit reports, training and control tasks), track obligations and escalate compliance risks to ensure regulatory deadlines are metEnsure cybersecurity policies, standards, and procedures align with security requirements, regulatory mandates, and the policies and standards, with clear mapping to internal controlsCoordinate security assessments and audits of critical systems. Act as the key liaison for auditors/ assessors, and track audit findings and remediation actions to closureMaintain compliance evidence and documentation (e.g. risk assessments, test results, training logs, and incident records) to support audits and regulatory inspectionsPartner with information security leaders, cybersecurity leads, system owners, and internal control functions (Risk, Internal Audit, Legal) to monitor compliance status, address gaps, and embed security requirements into business operations
RequirementsBachelor in Computer Science, Information Security, or a related disciplineA minimum of 5 years' experience in IT security governance, compliance management, or technology audit roles, preferably in a regulated or critical infrastructure environment. Experience in managing compliance programs or audits is highly preferredPossession of relevant certifications such as CISA, CISM, CISSP, CISP or equivalent is strongly preferredPossession of solid understanding of information security policies and risk management processes, and familiarity with cybersecurity regulations and standards (e.g., ISO 27001/ 27002, NIST CSF). Experience in security audits, evidence management and knowledge of Protection of Critical Infrastructures (Computer Systems) Ordinance (Cap. 653) and the associated Code of Practice will be an advantageExceptional organizational skills, with the ability to manage multiple compliance tasks and deadlines. Strong communication skills to coordinate across departments and auditors, and produce clear compliance documentationApplicationsYou are invited to apply online via http://www.mtr.com.hk/mtr_job_en or send in your CV stating the position (with reference number) you are applying for by mail to Human Resource Management Department, MTR Corporation, G.P.O. Box 9916, Hong Kong on or before 24 September 2026.
For other job openings, please visit MTR Corporation's website for more details.
All information provided by applicants will be treated in strict confidence and used for recruitment purpose only. All personal data of unsuccessful applicants will be retained for 12 months for future recruitment purpose and will then be destroyed.
: Hong Kong
: Full-time
: 10/Sep/26, 9:59:05 AM
: 24/Sep/26, 3:59:00 PM
260000SM

Established in 1963, Ricoh (Hong Kong) Limited focuses on digital services and office solutions. Entering the era of digital transformation, Ricoh's Four Areas of Expertise includes Hybrid Workplace, Workflow & Automation, Cloud & IT Infrastructure, and Cybersecurity. Ricoh has been actively advocating corporate evolution in recent years, accompanied by digital services and four customer values: Simplifying Complexity, Uncovering Hidden Opportunities, Overcoming Obstacles, and Embracing Diversity, bringing people and technology together, so companies can focus on forward.