Role Introduction
Drive the security assurance and testing practices that help protect Cathay's technology landscape. You will lead IT security assessments, oversee security testing activities, and ensure projects, applications, vendors, and technology initiatives are evaluated against security requirements, risk standards, and industry best practices. Working across assurance and testing disciplines, you will help teams understand security exposures, evaluate mitigation options, and make informed risk-based decisions.
Partnering with stakeholders across Information Technology and the wider business, you will oversee security testing quality, manage external testing vendors, guide responses to security findings, and develop frameworks covering areas such as cloud security assessments, contractual security requirements, and risk assessment methodologies. Your expertise in security standards, penetration testing practices, vulnerability assessment, ethical hacking, and threat awareness will help strengthen security outcomes across both project delivery and operational environments.
This is a role for a security professional who enjoys combining technical depth with leadership. By mentoring team members, improving assurance processes, promoting secure development practices, and influencing security decisions at multiple levels, you will help deliver a stronger and more resilient technology environment that supports Cathay's commitment to moving people forward in life.
Key Responsibilities
- Lead IT security risk assessments and security assurance activities, ensuring identified risks and mitigation actions are appropriately managed and tracked.
- Advise senior stakeholders on residual risks, vulnerabilities, security exposures, information asset misuse, and security non-compliance.
- Evaluate security risks associated with exception requests and recommend appropriate mitigation measures to business units.
- Develop, maintain, and continuously improve security assessment frameworks, testing procedures, methodologies, standards, and guidelines.
- Drive efficiency and consistency in assurance activities through the enhancement of control assessment approaches and security governance practices.
- Oversee security testing delivery across projects and business-as-usual activities, ensuring testing approaches, documentation, and outcomes are fit for purpose.
- Manage external testing vendors, assessment tools, testing quality standards, and acceptance criteria to ensure effective and reliable security testing outcomes.
- Prioritize and coordinate internal and external security testing resources while coaching and managing security testing team members.
- Investigate and communicate security findings, provide support during security incident resolution, and ensure residual risks are documented and understood by stakeholders.
- Promote security awareness and capability development by delivering training, encouraging secure coding practices, and monitoring emerging cyber threats and industry best practices.
Requirements
- 5-7 years of relevant experience in IT Security Assurance, Security Testing, Risk Assessment, or related cybersecurity disciplines
- Experience leading and mentoring small teams, with the ability to manage and develop team members
- Relevant security certification such as OSCP, GWAPT, OSEP, OSWE, OSCE, or CEH is preferred for assessment-related responsibilities
- Expert knowledge of cyber threats, attack techniques, security testing methodologies, security standards, and assessment tools
- Strong vendor management experience, including oversight of external security testing and assessment providers
- Hands-on knowledge of security frameworks and practices, including Vulnerability Assessment, IT Risk Assessment, Penetration Testing, Ethical Hacking, OWASP, NIST, OSSTMM, and OSINT
- Expert understanding of security solutions and tools used across assessment, testing, and assurance activities
- Strong communication and presentation skills, with the ability to articulate security risks and recommendations to both technical and non-technical stakeholders
- Excellent interpersonal, analytical, problem-solving, and decision-making skills, with strong troubleshooting capabilities
- Proactive, customer-focused mindset with the ability to drive change, build stakeholder relationships, and understand user and business needs
Personal & Application Information
Cathay Pacific is an Equal Opportunities Employer. Personal data provided by job applicants will be used strictly in accordance with our Applicant Personal Information Collection Statement and for recruitment purposes only. Candidates not notified within eight weeks may consider their application unsuccessful. We keep records of your data for no longer than is necessary for the purpose for which we obtained them and any other permitted linked purposes. If your application is unsuccessful, we will keep your details on file for as long as is necessary to process your application or for the purposes of further job opportunities if you agree to such longer periods.