- Perform end-to-end risk assessments for IT and OT systems, applications, networks, and infrastructure
- Assess security controls and identify gaps against regulatory, industry, and internal requirements
- Develop risk registers, assessment reports, and executive summaries with actionable recommendations
- Support remediation planning and track risk treatment activities
- Facilitate risk workshops and engage stakeholders to understand business processes, critical assets, and threat scenarios
- University degree in Computer Science, Information Technology, Information Security, Engineering, or a related discipline
- Minimum 3-4 years of hands-on experience conducting risk assessments for IT and/or OT environments
- Strong understanding of cybersecurity risk management principles and risk assessment methodologies
- Experience performing asset identification, threat analysis, vulnerability assessments, risk evaluation, and remediation planning
- Excellent verbal and written communication skills in Cantonese and English
