Senior Staff

Il y a 3 semaines

Brussels, Brussels-Capital, Belgique Deloitte Temps plein
About The Business Information Technology Services is a closely collaborative national team that provides IT-related procurement and implementation, infrastructure and operational support, application solutions and systems project management services, evaluating and promoting new systems and software to improve productivity and ensure information security. Work you'll do Security Operations Run daily security operations for the Hong Kong and Macau practices, including vulnerability management, privileged account management (PAM), and phishing/email threat response. Operate and maintain the local security tooling stack (PAM, IAM, email security gateway, vulnerability management platforms) and ensure locally generated, audit-ready operational logs and evidence. Review security monitoring output, manage exceptions, and drive remediation with infrastructure and application teams. Security Governance & Compliance Own and maintain the Hong Kong information security and business continuity management systems, including ISO/IEC 27001 and ISO 22301 certification, policies, standards, and control documentation. Plan and coordinate internal and external security audits; track and drive remediation of findings to closure. Monitor Hong Kong regulatory and legal developments (e.g., PDPO, Protection of Critical Infrastructures (Computer Systems) Ordinance, HKMA/SFC supervisory expectations) and translate them into firm requirements. Client & Regulatory Assurance Respond to client security due diligence questionnaires, third-party risk assessments, and regulator-driven inquiries within required timelines. Support engagement teams on information security requirements in client contracts and outsourcing arrangements. Represent the Hong Kong firm in client security reviews, on-site assessments, and industry/regulator forums. Incident Response & Resilience Serve as a primary responder for security incidents affecting the Hong Kong and Macau practices, covering triage, containment, escalation, evidence preservation, and post-incident review. Maintain and exercise business continuity and incident response plans in line with ISO 22301. Provide backup coverage for the application security function to ensure continuous local capability (A/B role arrangement). Risk Management & Awareness Conduct security risk assessments for new technology, vendors, and business initiatives. Deliver security awareness programs and phishing simulations for the Hong Kong practice. Report on security posture, risks, and compliance status to ITS leadership and firm management. During your tenure with us, you will demonstrate and develop your leadership and professional capabilities in the following areas: Inspiring, Creating purpose, Driving agility, Building diverse capability, Influencing, Collaborating, Delivering value, Building the business, Analytical acumen, Effective communication, Engagement management/delivery excellence, Managing change, Managing quality & risk, Strategic thinking and problem solving, and Tech savviness. We are looking for someone with To be considered for this position, you must demonstrate skills and experience in the following areas: Bachelor's degree or above in Computer Science, Information Security, Information Systems, or a related discipline. Minimum 5 years of experience in information security, spanning security operations and security governance/compliance in a regulated or professional services environment. Hands-on experience with enterprise security operations tooling, such as vulnerability management platforms, PAM, IAM, and email security gateways. Experience operating or auditing an ISO/IEC 27001 ISMS; exposure to ISO 22301 and certification cycles strongly preferred. Working knowledge of the Hong Kong regulatory landscape, including PDPO and HKMA/SFC technology risk and outsourcing requirements. Experience handling security incidents and coordinating cross-functional response. One or more recognized certifications: CISSP, CISM, CISA, CRISC, or ISO/IEC 27001 Lead Auditor/Lead Implementer. Excellent written and spoken English; Cantonese and/or Mandarin strongly preferred for client and regulator engagement. Strong stakeholder management and the ability to communicate risk clearly to senior, non-technical audiences. Prior experience in a Big Four, financial services, or other highly regulated organization in Hong Kong. Familiarity with the Protection of Critical Infrastructures (Computer Systems) Ordinance and its implications for service providers. Understanding of cloud security and data protection controls (Microsoft 365, Azure) in an enterprise environment. Ability to work independently as part of a small, high-accountability local team. About Deloitte China Deloitte China provides integrated professional services, with our long-term commitment to be a leading contributor to China’s reform, opening-up and economic development. We are a globally connected firm with deep roots locally, owned by our partners in China. With over 20,000 professionals across 31 Chinese cities, we provide our clients with a one-stop shop offering world-leading audit, tax and consulting services. We provide comprehensive, end-to-end, and integrated services to address clients’ core issues, empowering them with our multidisciplinary service model. Deloitte is an undisputed leader in professional services in China with strong responsibility and capabilities in digitalization and multidisciplinary services. Deloitte China has been honored as 'China Top Employers 2026' for the 20th consecutive year. Leap Forward, Bloom Beyond To deepen its long-term commitment to the Hong Kong market, Deloitte China launched the HK LEAP strategy, focusing on fintech, capital markets, and AI to enhance professional service capabilities and talent development. It aims to strengthen the city's position as an international financial centre, accelerate its transformation into a global innovation and technology hub, and drive economic transformation. Shaping future talent through impact that matters Throughout over 180 years of development, Deloitte is committed to making an impact that matters to clients, people, and society. Deloitte China practices “4+1” culture – Courage, Innovation, Inclusion, Wellbeing, + Integrity, which is rooted in our service purpose and lays the foundation for sustainable growth and prosperity. Deloitte is a people-oriented professional services firm, empowering every Deloitter to unlock their intrinsic motivation and limitless potential. We are committed to cultivating high-caliber and diversified talent, providing continuous momentum for the development of the firm and China. Deloitte China has established clear career development paths, covering different industries, professional areas, and levels. Through six mechanisms of DU AP China Project, global mobility, counseling system, learning platform, project engagement, and innovation incentives, we provide all-around support on upskilling and career development for our people to upgrade professional service capabilities, enhance innovative thinking and pursue the career success. A world of opportunities awaits. Start your adventure and journey with us Accessibility assistance If you need assistance or an accommodation during the recruitment process for accessibility reasons, there will be an opportunity for you to let us know what you need once you begin your application. Ready to take on new challenges? Apply now Stay connected for the latest career opportunities, follow us on Deloitte China Social Media.