Vista previa de la oferta
Senior Chief Information Security Office Director
senior · Risk & Compliance
Your role
Are you an experienced cyber and information security leader with deep knowledge of cyber risk management, regulatory expectations, global control frameworks and enterprise security governance? Do you have the ability to translate complex cyber threats, regulatory developments and control requirements into practical risk decisions for senior business and technology stakeholders?We are looking for a Senior CISO, Director (DI) based in Hong Kong to provide senior leadership across cyber and information security risk management for the North East Asia region. This role will act as a key regional focal point for cyber risk, regulatory engagement, cyber risk reduction, executive reporting and governance activities across the Group Chief Information Security Office. As Senior CISO, Director, you will help strengthen the Firm’s cyber defence posture by aligning cyber risk priorities with the threat landscape, regulatory expectations, business objectives and global CISO standards. The role requires close collaboration with business stakeholders, technology teams, BISOs, risk advisory teams, third-party risk specialists, non-financial risk teams, control owners and senior management.
Key responsibilities:
Regional Cyber Risk Leadership
• Serve as the Asia North CISO lead, providing subject matter expertise and leadership across cyber and information security risk domains for Hong Kong and Asia North markets.
• Act as the regional focal point for Cyber Risk Management, integrating key central CISO services into Asia North, including Business Information Security Office (BISO) engagement, risk advisory, third-party risk management, non-financial risk governance, key procedural controls, and GWM Control Self Assessments. • Provide senior oversight, challenge, and governance across cyber and information security risk topics, ensuring alignment with global CISO strategy, local regulatory expectations (e.g., HKMA and other Asia North regulators), and business risk appetite.
• Partner closely with Security Engineering, DISO, Technology Risk, and other control functions to ensure a cohesive and effective cyber risk management approach.
• Drive transparency, accountability, and timely remediation across cyber risk domains.
• Support the establishment and continuous improvement of a resilient and adaptive security posture aligned with organizational risk tolerance and business strategy.
• Provide leadership to local country CISOs across Asia North.
• Establish clear roles, responsibilities, and performance expectations aligned with APAC and global CISO strategy and regional priorities.
• Drive consistency in cyber risk management practices, governance standards, and regulatory engagement approaches across countries.
• Foster collaboration, knowledge sharing, and capability development, as well as support talent development, succession planning, and building a high-performing security leadership team.
Landscape and Cyber Awareness
• Proactively participate in industry cyber threat forum, assess the external cyber threat landscape, identifying emerging threats, regional attack patterns, and potential impacts to the organization.
• Translate threat intelligence, incident learnings, and control insights into actionable risk reduction priorities for senior stakeholders.
• Drive consistent cyber awareness messaging and campaigns across Asia North to enhance cyber resilience and promote management understanding of risk exposure. • Promote a strong cyber-aware culture in partnership with business and technology teams. Regulatory Engagement and Security Incident Leadership
• Lead and coordinate regulatory engagement related to CIS, together with other Asia North country CISO, acting as the primary CISO representative for cyber and information security matters with regulators (e.g., HKMA and relevant regional authorities).
• Analyze and respond to regulatory consultations, circulars, advisories, and examination findings related to CIS, ensuring appropriate interpretation, tracking, and remediation.
• Provide leadership during cyber incidents, including: o Regulatory notification and engagement o Executive communications and briefing o Coordination of post-incident reviews and regulatory responses
• Ensure consistent and high-quality regulatory deliverables, including submissions, self-assessments, and audit responses. Governance, Controls and Assurance
• Provide oversight, review, and challenge over cyber risk governance processes, control frameworks, and assurance activities.
• Support the design, implementation, and continuous improvement of Cyber risk processes and procedures, Control assessments and testing frameworks & Governance routines and reporting structures
• Provide oversight on key control activities including CISO outsourcing service review, exception management, and risk acceptance processes where relevant.
• Contribute to internal/external formal reporting, regulatory responses, executive updates, and governance materials, clearly articulating cyber risk posture, control effectiveness, and remediation progress.
• Ensure effective alignment of regional practices with global policies and standards.
Stakeholder Engagement and Executive Communication
• Build and maintain trusted relationships with senior stakeholders across business, technology, risk, compliance, audit, and external partners.
• Engage with technical SMEs and business stakeholders to ensure cyber risk requirements are clearly understood, prioritized, and effectively implemented.
• Represent the CISO function and present cyber risk topics, regulatory matters, control issues, and threat insights to Senior management forums, Risk and governance committees & External regulators and auditors
• Act as a key advisor to senior leadership on cyber risk matters and emerging threats.
Join us
At UBS, we know that it's our people, with their diverse skills, experiences and backgrounds, who drive our ongoing success. We’re dedicated to our craft and passionate about putting our people first, with new challenges, a supportive team, opportunities to grow and flexible working options when possible. Our inclusive culture brings out the best in our employees, wherever they are on their career journey. And we use artificial intelligence (AI) to work smarter and more efficiently. We also recognize that great work is never done alone. That’s why collaboration is at the heart of everything we do. Because together, we’re more than ourselves.We’re committed to disability inclusion and if you need reasonable accommodation/adjustments throughout our recruitment process, you can always contact us.
Contact Details
UBS Business Solutions SAUBS Recruiting
Disclaimer / Policy statements
UBS is an Equal Opportunity Employer. We respect and seek to empower each individual and support the diverse cultures, perspectives, skills and experiences within our workforce.Your team
You’ll be working in the Group Chief Information Security Office (CISO) APAC team, based in Hong Kong and reporting to the APAC CISO. The Group CISO vision is to protect, preserve and prolong the value of UBS data and digital services, and to enhance UBS’s brand and competitiveness in a digitized world. The CISO mission is to lead the management of all cyber threats and cyber risk across the Firm. CISO interacts with all levels within the organization, peers at other firms and business partners to establish and maintain a strong and adaptive security posture that aligns with organizational risk tolerance, cyber and information security requirements and the overall business strategy.Your expertise
• Ideally 10+ years of experience working or consulting with APAC regulators or global organizations in areas such as Cyber Security, Information Security, Cyber and Information Security, Regulatory, Information Technology Audit, Information Security Operations, Risk Management or Risk Control.• Strong knowledge of APAC cyber and information security regulatory requirements, or the ability to quickly develop deep familiarity with evolving regulatory expectations. Experience and knowledge of HKMA and SFC regulatory requirement in CIS is a must.
• Solid understanding of cyber threat management and how cyber risk connects to business priorities, operational resilience and enterprise risk management. • Proven experience conducting cyber risk assessments, technical risk analysis, control reviews and risk based challenge.
• Experience preparing formal reports, management updates, regulatory materials and cyber risk reporting.
• Strong analytical skills, including the ability to collect, interpret and synthesize significant amounts of information into clear insights and decisions.
• Experience with the NIST Cybersecurity Framework and relevant professional certifications such as CC, CISSP, CISA, CISM or CRISC would be advantageous.
• Fluency in English, with Cantonese and Mandarin language advantageous.
• Strong enthusiasm for cybersecurity and a commitment to keeping skills, knowledge and market awareness current.
About us
UBS is a leading and truly global wealth manager and the leading universal bank in Switzerland. We also provide diversified asset management solutions and focused investment banking capabilities. Headquartered in Zurich, Switzerland, UBS is present in more than 50 markets around the globe.We know that great work is never done alone. That’s why we place collaboration at the heart of everything we do. Because together, we’re more than ourselves. Want to find out more? Visit ubs.com/careers.