About iGears
iGears Technology Limited (科擎科技有限公司) has built software for Hong Kong organisations since 2004, including listed companies, public-sector bodies, NGOs, education organisations and churches. We develop and run 20 of our own SaaS products, and our MobPage division has published 200+ mobile apps. With offices in Hong Kong and Edmonton, Canada, we are now building an in-house cybersecurity team to deliver penetration testing, security risk assessments and privacy impact assessments for clients, and to secure our own platforms.
Work arrangements
Full-time and part-time arrangements are welcome. On-site or hybrid arrangements are welcome.
What you’ll do
- Lead security risk assessments and audits (SRAA) of client systems, aligned with the HKSAR Government’s IT security policy and guidelines (e.g. S17 and G3), ISO/IEC 27001/27002 and CIS Benchmarks
- Carry out Privacy Impact Assessments under the Personal Data (Privacy) Ordinance and PCPD guidance: map data flows, assess risks and recommend controls
- Review architecture, configurations, policies and technical evidence, and coordinate hands-on testing with our penetration testers
- Produce risk registers, remediation plans and reports that government departments, statutory bodies and auditors accept, and present results to clients
- Support iGears’ own ISO/IEC 27001 programme (certification in progress) and internal security policies
What you’ll bring
- At least one of CISA, CISSP, CISM or ISO/IEC 27001 Lead Auditor
- At least 3 years in IT audit, security risk assessment or security consulting
- Enough knowledge of network, operating system, cloud and application security to judge technical evidence
- Excellent written English
- The right to work in Hong Kong
Nice to have
- SRAA or PIA experience on Hong Kong public-sector projects
- A privacy certification such as CIPP/A, CIPP/E, CIPM or CDPSE
- Written Chinese, for bilingual deliverables
- Hands-on testing experience or OSCP
What we offer
- HK$30,000–45,000 a month, depending on experience and certifications
- Assessment work for public-sector, enterprise and NGO clients, plus our own 20 SaaS products
- A founding role in our new security team, reporting to our CTO
- MPF, 15 days’ annual leave, medical cover, and support for relevant training and certification exams
Explore our platforms before you apply
- AI: GenCMS (gen-cms.com), AskCore (askcore.org), HumanLevelUP (humanlevelup.org), PromoPilot (promo-pilot.org), Webetter (webetter.co), PhotoCen (photocen.com), Duckbot (duckbot.hk, preview)
- Business operations: fileEC (fileec.com), InsightBook (insightbook.org), HRFlowTech (hrflowtech.com), MemberSys (membersys.org), AppointSys (appointsys.org), Paperless.Cards (paperless.cards)
- Messaging and marketing: SendPromotion.Email (sendpromotion.email), SendSMS.click (sendsms.click), MarketHK (markethk.net)
- Education and community: LearnSys (learnsys.org), ITChurch (itchurch.online)
- Directories: E12 (e12.hk, e12.ca) and E12 Careers (jobs.e12.hk, jobs.e12.ca)
Full list: https://www.igears.com.hk/platforms/
How to apply
Email your CV to [email protected] with the subject “Security Consultant (Risk & Privacy) – Your Name”. Please include your certification numbers (e.g. ISACA or ISC2) and your expected salary and notice period. Only shortlisted candidates will be contacted.
iGears is an equal opportunity employer. This role is open to all qualified applicants.
Personal data you provide will be used by iGears Technology Limited only for recruitment. Providing it is voluntary, but we can’t consider your application without it. It may be shared with other iGears offices if you are considered for a role there. Data of unsuccessful applicants is destroyed within two years. To access or correct your data, or for our full Personal Information Collection Statement, email [email protected].
https://e12.hk/pages/company.php?slug=igears-technology-limited
iGears Technology Limited (科擎科技有限公司) has built software for Hong Kong organisations since 2004, including listed companies, public-sector bodies, NGOs, education organisations and churches. We develop and run 20 of our own SaaS products, and our MobPage division has published 200+ mobile apps. With offices in Hong Kong and Edmonton, Canada, we are now building an in-house cybersecurity team to deliver penetration testing, security risk assessments and privacy impact assessments for clients, and to secure our own platforms.