Job Description
Working Location: Kai Tak, Kowloon
Employment Duration: Permanent
The Assistant Manager - Security Compliance supports the implementation and ongoing management of security and cybersecurity compliance requirements across CLP Group and its supply chains. The role supports the provision of strategic and operational oversight to ensure that regulatory, contractual and internal security obligations and risk treatment actions are met consistently, supporting the protection of CLP’s people, its business lines, its critical infrastructure and the service it provides to its customers.
Responsibilities
Support and Develop Security Compliance Capability
Assist in building security compliance competencies across the CLP Group, building cross-Group security compliance knowledge and capability.
Security Compliance Execution
Carry out compliance activities across physical, IT, OT, and supply‑chain environments, ensuring that security compliance requirements are effectively managed in alignment with business objectives, regulatory obligations and Group Security’s Policy and Standards. Further, ensure that agreed risk mitigation measures are applied appropriately.
Guidance and Assurance
Provide expert guidance and assurance to business units and suppliers to help them operate within established compliance frameworks and maintain a strong control environment. Together with the Group Security Risk Team, help business units and suppliers understand how security risks can impact on CLP’s business and assist them to recognise the importance of selected mitigation measures.
Continuous Improvement
Support enhancements in compliance processes, reporting, and control effectiveness to drive continuous improvement to enhance organisational resilience and support the reliable operation of generation, transmission and customer services. Monitor emerging regulatory, industry and internal requirements, ensuring timely updates to compliance frameworks and associated controls.
Audit Coordination
Assist in preparing for and supporting internal and external audits, assessments and remediation activities to maintain a robust compliance posture, and to verify that risk mitigation measures are applied appropriately.
Operational Reporting and Stakeholder Support
Prepare compliance reports and coordinate the tracking of outputs from audits, including aspects of non-compliance and inconsistent or absent risk mitigation measures.
Requirements
- Bachelor's degree in a related discipline.
- At least 6 years’ experience in Cyber Security.
- Experience in a technical Cyber Security role.
- A Certified Information Systems Auditor or equivalent certification.
- Fluent in English and Cantonese, verbal and written.