This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Forvis Mazars is a leader in audit, tax and advisory services worldwide, operating across 100+ countries and territories. Join us to grow your career through global opportunities, diverse projects, and continuous learning. Belong to a supportive environment where your unique perspective is valued, and success comes from teamwork. Impact with your bold ideas and help drive us forward. As the financial services consulting team in Hong Kong, we provide integrated solutions to financial institutions to help them anticipating change in a complex and volatile environment and meeting challenges of increasingly stringent regulations. We are seeking a Cybersecurity Specialist who is passionate about cybersecurity within the financial services sector. Working with our financial services clients you will gain significant exposure to clients operating in complex environments. With the support of partners, directors, and managers, you will be expected to support to an increasing in demand for our FS consulting services.
Job Responsibility
Provide expert advice on security frameworks and best practices
Develop and implement cybersecurity strategies tailored to financial institutes and collaborate with clients to enhance their cyber security posture and compliance with regulations
Monitor and respond to security incidents, ensuring rapid remediation
Stay updated on emerging threats, technologies, and regulatory changes
Conduct training and awareness programs for clients and internal teams
Prepare and present reports on cyber security status and improvements
Conduct detailed penetration tests and vulnerability assessments across various IT systems within financial institutions, including but not limited to systems handling virtual assets
Develop security testing plans that are tailored not only to traditional financial systems but also to emerging technologies associated with virtual assets, such as blockchain
Collaborate with clients to assess and enhance their cybersecurity measures, with a particular focus on technologies involved in the management and transaction of virtual assets
Perform IT and security assessments based on regulatory requirements from bodies such as HKMA, SFC etc., ensuring compliance while addressing specific security concerns
Engage directly with client stakeholders, providing clear communication regarding security vulnerabilities, implications, and strategic recommendations
Maintain up-to-date knowledge of the latest cybersecurity threats, regulatory changes, and advancements in technology impacting both traditional financial services and the virtual assets sector
Requirements
A bachelor’s degree in Information Systems, Computer Science, Engineering, or a related field
2-5 years of experience in cybersecurity, advantage with specific expertise in penetration testing and/ or simulation attacks. Candidate with more experiences will be considered for a senior role
Experience with Big4 or similar consulting firms. Experience in virtual assets, blockchain technology, or related fields is highly preferred
Relevant industry certification such as CISM, CISSP. Additional certifications in cybersecurity or blockchain technology, such as OSCP, OSCE, OSEE, GPEN, CREST, are advantageous
Demonstrated ability to think analytically and solve complex problems
Excellent interpersonal and communication skills, capable of engaging effectively with both technical and non-technical stakeholders
Proficiency in English
fluency in Cantonese and Putonghua is highly preferred
Advanced skills in report writing and the creation of professional, insightful presentations and reports
Familiar with security standard references such as OWASP, SANS, NIST
Knowledge and experience of security testing methods and techniques, including network, operating system and application system configuration review and internal/external penetration testing
Knowledge and experience in web and mobile application security review and testing are desirable
Nice to have
Experience with virtual assets, blockchain technology, or related fields is highly preferred
Additional certifications in cybersecurity or blockchain technology, such as OSCP, OSCE, OSEE, GPEN, CREST, are advantageous
Fluency in Cantonese and Putonghua is highly preferred
Knowledge and experience in web and mobile application security review and testing are desirable