Skip to content

Open nowPosted 26 days ago

Manager, Cybersecurity Governance & Risk

Workable (global search)108,016 open roles

Where
Hong Kong, Hong Kong SAR China
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowManager, Cybersecurity Governance & RiskWorkable (global search) · Hong Kong, Hong Kong SAR China
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 26 days ago

Workable (global search) median: 7 days open

The posting

Governance, risk and regulatory obligations

  • Turn the Group's cyber and technology risk strategy into a practical roadmap, policies and standards, built on a control framework aligned to ISO/IEC 27001, ISO 22301 and NIST CSF 2.0.
  • Lead risk assessments across shore, vessel, cloud and OT environments; maintain the risk register and report clear KRI/KPI dashboards to senior management.
  • Maintain an obligations register covering maritime cyber requirements, client commitments and the regulations applying across our operating jurisdictions, such as Hong Kong PDPO, Singapore PDPA and NIS2.
  • Partner with QHSE, Fleet and Vessel IT to embed cybersecurity into the safety management system and strengthen vessel assurance.
  • Run a risk-based third-party programme with Legal and Privacy, from due diligence and contract controls through to monitoring and exit.

Certification, audits and assurance

  • Keep the organisation continuously certification-ready, rather than preparing for each audit in isolation.
  • Coordinate internal, external, certification and client audits end to end, from scope and evidence through to management reporting.
  • Handle security questionnaires, tenders and due diligence from clients and shipowners, and track corrective actions through to closure.

Technology, security-by-design and resilience

  • Work hands-on with Infrastructure & Operations on the security of the underlying estate — network segmentation and perimeter controls, Windows Server and Active Directory hardening including Group Policy baselines, endpoint configuration, patch and vulnerability management, and privileged access
  • Partner with Development and Digitalisation on security-by-design and DevSecOps across cloud, applications and data.
  • Assess AI tools and use cases for data exposure, access and model risk, and set proportionate guardrails drawing on references such as the NIST AI RMF and ISO/IEC 42001.
  • Lead crisis management, business continuity and disaster recovery exercises, and automate control monitoring where you can.

Leadership and stakeholder partnership

  • Lead and develop the GRC team, and coordinate control owners across offices and vessels.
  • Work with our shore and maritime training organizations to build cybersecurity and AI-risk content into training for seafarers and shore staff.
  • Act as a trusted partner across IT, QHSE, Fleet, Legal and the business, translating technical and regulatory risk into clear options for senior leaders, clients and auditors

Requirements

  • Bachelor’s degree in information security, Computer Science, Engineering, Risk Management or a related discipline; equivalent professional experience will be considered.
  • CISM, CRISC, CISA, CISSP, ISO/IEC 27001 or ISO 22301 Lead Implementer or Lead Auditor, or an equivalent GRC qualification, is strongly preferred.
  • Approximately 8-12 years of experience in cybersecurity GRC, information security governance, technology risk, IT audit or security assurance, including leadership responsibility.
  • Hands-on experience with ISO/IEC 27001, ISO 22301, NIST CSF or a comparable framework, including audits, control assessment, evidence and remediation.
  • Strong understanding of risk registers, control design and testing, exceptions, risk acceptance, KRIs/KPIs and executive reporting.
  • Broad technical grounding across infrastructure and operations — networks, Windows and Active Directory and endpoints — as well as cloud, identity and security operations.
  • Experience supporting clients, external auditors, regulators or industry bodies in a complex, global or operationally intensive organisation.
  • Exposure to AI risk management or enterprise AI governance; maritime cybersecurity or OT experience is advantageous but not essential.
  • Strong written and spoken English. Cantonese and/or Mandarin is advantageous.
  • Pragmatic, engineering-informed builder who creates governance that works in real operations and can follow a control from policy through to implementation, evidence and outcome.
  • Structured, risk-based decision-maker who remains calm and accountable under pressure.
  • Clear communicator who can write concise policies, audit responses and executive updates without unnecessary jargon.
  • Genuinely curious and self-driven — owns their development and keeps looking for better ways to do things, including responsible use of AI.
  • Gets things done through others — a strong team player who engages people well beyond their own reporting line and builds successful professional connections with colleagues and stakeholders.

Benefits

About Anglo-Eastern

Anglo-Eastern is a global leader in independent ship management services. The Group manages over 700 vessels under full technical management, supports around 500 additional ships under crew management, and has overseen more than 1,000 newbuildings and conversions through its newbuilding supervision and project management divisions.

Headquartered in Hong Kong, Anglo-Eastern operates through a network of 30 offices across Asia, Europe, and the Americas, including wholly owned maritime training facilities. Our strength lies in our people: over 39,000 seafarers and 2,350 shore-based employees who work together to support clients across ship types while building trust, driving performance, and shaping a better maritime future.

Why join Anglo-Eastern?

  • Join a globally respected company with a strong maritime heritage of over 50 years
  • Work in an environment anchored in integrity, trust, and long-term relationships
  • Access continuous learning and structured career development across a truly global network
  • Be part of a team committed to delivering excellence and shaping a better maritime future

Join us today!

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.