Senior Technology Risk Analyst / Lead

Lalamove
Hong Kong
Workplace: OnsiteFull timeFunction: Legal, Risk & ComplianceExperience: 5+ yearsEducation: bachelorsSkills: ["Communication"]

Own enterprise technology risk activities across IT infrastructure, cloud environments, and SDLC. Maintain the enterprise risk register, run comprehensive risk assessments, and coordinate remediation and risk acceptance decisions across teams. Deliver clear executive-level risk dashboards and summaries, strengthen security control testing with internal audit, and continuously improve the ISO 27001-aligned ISMS. Drive AI security governance and support regular PCI DSS assessments.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Lalamove
Lalamove
10 hours ago

Senior Technology Risk Analyst / Lead

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 8 hours agoStatus: Live

Job Summary

Own enterprise technology risk activities across IT infrastructure, cloud environments, and SDLC. Maintain the enterprise risk register, run comprehensive risk assessments, and coordinate remediation and risk acceptance decisions across teams. Deliver clear executive-level risk dashboards and summaries, strengthen security control testing with internal audit, and continuously improve the ISO 27001-aligned ISMS. Drive AI security governance and support regular PCI DSS assessments.
Location: Hong Kong
Workplace: Onsite
Employment Type: Full time
Job Function: Legal, Risk & Compliance
Seniority: Mid level

Key Responsibilities

  • •Maintain the enterprise risk register and conduct comprehensive risk assessments across IT infrastructure, cloud environments, and the SDLC.
  • •Coordinate risk remediation plans across different teams and track risk acceptance decisions.
  • •Develop and maintain risk dashboards, producing executive summaries for management review.
  • •Champion AI security governance initiatives to ensure safe and compliant adoption of AI technologies.
  • •Support internal audit initiatives, facilitate security control testing, and maintain/continuously improve the ISO 27001-aligned ISMS including regular PCI DSS assessments.

Key Requirements

  • •Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, Business Administration, or a related field.
  • •5+ years of experience in IT Risk Management, Information Security, Compliance, or IT Audit.
  • •Strong understanding of risk assessment methodologies and frameworks such as NIST CSF, ISO 27001, and PCI DSS.
  • •Experience maintaining risk registers and tracking remediation lifecycles.
  • •Preferred: CRISC, CISA, CISM, ISO 27001 Lead Auditor, or similar risk and audit certifications.
Experience:5+ years
Education:Bachelor's in Cybersecurity, Information Technology, Risk Management, Business Administration
Skills:Communication
Certifications:CRISCCISACISMISO 27001 Lead Auditor
Tech Stack:NIST CSFISO 27001PCI DSSRisk registerDevSecOpsCI/CD pipelinesSecure architectureCloud architectureSDLCISMSAI security governanceExecutive dashboardsSecurity control testingEnterprise risk register

Company Brief

Lalamove
On-demand logistics platform providing same-day delivery, courier, and freight services for individuals and businesses across urban centers, connecting drivers with customers via a mobile and web app.
Industry: Last Mile Delivery
Company Size: Enterprise (1,001+ employees)
Growth: Scaleup
Valuation: Unicorn (USD 1B+)
Funding: Series E+
Headquarters: Hong Kong, Hong Kong
Founded: 2013
WebsiteLinkedIn