Job Description - Senior Information Security Manager
About Dah Sing Group The Dah Sing Group is a leading financial services group in Hong Kong offering banking, insurance, financial and other related services through its growing network of over 70 branches in Hong Kong, Macau and Mainland China. Our currency is caring, teamwork and progressiveness. We accept that everyone is unique and different in talent, but alike in the capacity for growth. Our task is to shape a culture that creates a sense of pride in achieving something beyond just a job, and an environment where you can be your true and authentic self, like at home.
Position Overview The Security Architect is responsible for designing, enhancing, and governing the bank's security architecture across applications, infrastructure, cloud, data, and emerging technologies. The role ensures that security controls are embedded into technology designs, aligned with HKMA regulatory requirements, and capable of supporting the bank's long term cyber resilience strategy. This position partners closely with IT, business units, project teams, and senior management to provide expert guidance on secure design and risk mitigation.
Key Responsibilities Security Architecture Design & Governance • Develop and maintain enterprise security architecture frameworks, reference architectures, and security design patterns. • Define security principles, standards, and guardrails for applications, infrastructure, cloud, APIs, and data platforms. • Review solution architectures, technical designs, and integration models to ensure alignment with security requirements. • Provide expert guidance on secure network segmentation, identity architecture, encryption, key management, and zero trust principles. • Ensure architecture decisions support scalability, resilience, and operational feasibility. • Serve as the security architect for new projects, system enhancements, and technology initiatives. • Conduct threat modelling, architecture risk assessments, and design reviews. • Identify security gaps and recommend pragmatic, risk based mitigation measures. • Collaborate with project managers, developers, infrastructure teams, and vendors to embed security early in the lifecycle. • Define cloud security architecture for IaaS, PaaS, SaaS, and hybrid environments. • Guide secure adoption of containers, Kubernetes, CI/CD pipelines, and DevSecOps practices. • Evaluate emerging technologies (AI/ML, APIs, microservices, mobile, fintech integrations) for security implications. • Ensure secure configuration baselines, identity models, and monitoring capabilities for cloud workloads. • Provide architectural oversight for key security technologies such as IAM, PAM, SIEM, SOAR, EDR, DLP, WAF, and network security platforms. • Ensure security tools integrate effectively with enterprise systems and support detection, response, and governance needs. • Recommend enhancements to monitoring, logging, and incident response capabilities. • Support the definition of security requirements for vendor solutions and third party integrations. • Develop architecture documentation, security standards, and design guidelines. • Present architecture decisions, risks, and recommendations to senior management and governance committees. • Support regulatory inspections, internal audits, and external assessments. • Act as a trusted advisor to IT and business stakeholders, promoting a culture of secure by design.
Qualifications & Experience • Bachelor's degree in Information Security, Computer Science, or related field. • 8-12+ years of experience in security architecture, solution architecture, or senior security engineering roles. • Strong knowledge of application security, network security, cloud security, identity architecture, and data protection. • Hands on experience with cloud platforms (Azure, AWS), IAM/PAM, SIEM, EDR, WAF, and encryption technologies. • Possession of relevant HKMA ECF Certifications in Cybersecurity.
Key Competencies • Strategic thinker with strong technical depth. • Ability to translate complex security concepts into clear, actionable guidance. • Excellent communication and stakeholder management skills. • Strong analytical, problem solving, and decision making capabilities. • Proactive, collaborative, and committed to continuous improvement.
Please note that only shortlisted candidates will be notified.
All Job Ads are subject to GrabJobs’s Terms of Service. We allow users to flag postings that may be in violation of those terms. Job Ads may also be flagged by GrabJobs moderation team. However, no moderation system is perfect, and flagging a posting does not ensure that it will be removed.
Be the first to receive the latest Others Full-Time Jobs in Hong Kong.
Setup your job alert:
By activating job alerts, I agree to GrabJobs Terms & Privacy Policy. I can unsubscribe to job alerts anytime.
Skip
GrabJobs is the no1 job portal in Hong Kong, connecting you to thousands of jobs fast!
Find the best jobs in Hong Kong, apply in 1 click and get a job today!