Cybersecurity and Information Security Analyst

Recruiternahc.ioHong KongJob.bopublished 09/03/2026
Must-have:CloudQA/TestSecurityLeadPrincipal

Overview

Our client is a high-growth regional SaaS platform, seeking an experienced QA Lead (Automation & Manual) to direct its software quality strategy and testing ecosystem.  In this role, you will partner closely with engineering leaders to establish testing standards and maintain high product excellence across fast-moving feature release cycles. This position is ideal for a hands-on QA leader who excels at bridging technical quality execution with business-critical outcomes.

What You Will Do Own end-to-end vulnerability management—scheduling automated scans, prioritizing SAST/DAST findings, and driving technical remediation across application and infrastructure layers.

Lead the complete incident response lifecycle, managing security event monitoring, containment, forensic mitigation, and root-cause reporting for executive leadership.

Direct internal and external IT audits, maintaining certification programs across ISO 27001, ISO 42001 standards and SOC compliance.

Develop, implement, and maintain data governance and privacy frameworks (e.g., GDPR) across existing and expanding global operating regions.

Conduct continuous threat hunting using updated threat intelligence to proactively strengthen controls and prevent security violations.

Partner with engineering and operational squads to enforce security standards, evaluate risks in new initiatives, and conduct staff cybersecurity training.

What You Will Need 2+ years of hands-on experience in information security, IT compliance, or risk management within modern technology or cloud environments.

Practical expertise with core compliance frameworks and standards, specifically ISO 27001, SOC reporting, and ISO 42001 (Artificial Intelligence Management Systems).

Solid technical understanding of software development lifecycles, IT infrastructure, network architectures, vulnerability scanning, and structured incident response.

Deep knowledge of global data privacy regulations (e.g., GDPR) and data governance frameworks.

Industry security or compliance certifications (e.g., CISSP, CCEP, ISO Lead Implementer/Auditor, or equivalent professional credentials) are strongly preferred.

Excellent analytical, problem-solving, and communication skills to effectively translate technical risks to cross-functional stakeholders.