Project Manager (C34400)
職位亮點
職位描述
Project Nature:
-
IT projects and on-going support Auxiliary Medical Service (AMS) and Civil Aid Service (CAS).
Responsibilities:
Serve a contract assignment under InfoTech's headcount, full-time second to serve Security Bureau;
(A) Design, implementation and operations of IT security controls including the more stringent security controls for Tier 2 and Tier 3 systems as specified in Appendix C of the IT Security Guidelines (G3) :-
-
Establish IT security organisation including the information security steering committee and the IT security management unit, hold regular meetings, prepare necessary documents and follow up outstanding issues.
-
Formulate IT security management framework including the risk registers to document identified risks, likelihood and severity of occurrence, and mitigation and monitoring measures.
-
Establish IT security threat management mechanism for threat identification, detection, monitoring and response.
-
Formulate IT security training programme for all personnel involved in support and operations of IT systems, and formulate and enforce contractual obligation with outsourced contractors.
-
Spell out, monitor and ensure necessary IT security controls are in place and functional throughout system development life-cycle and on-going system operations, in particular in the areas of access control, operations security, system acquisition / development / maintenance, business continuity, etc. Assist in user acceptance planning and execution in IT security perspectives. Ensure quality procedures, techniques and tools are used.
-
Review system development deliverables, documentation and operating procedures, identify IT security shortfalls and recommend improvements.
-
Bring up, drive and ensure on-time completion of compliance work including IT security risk assessment and audit, privacy impact assessments, vulnerability scanning, penetration tests, configuration review, code scanning, regular review on usage of privileged accounts, etc.
-
Formulate and maintain information security incident response plans, take lead to respond to IT security incidents.
-
Prepare and maintain documents and ensure timely submission to DPO for compliance monitoring and audit.
(B) IT project management
-
Take lead and be responsible for IT security aspects of multiple system development projects and IT infrastructure enhancement projects within a tight project timeline. Serve as the focal point to all levels of users and multiple contractors regarding IT security related matters.
-
Drive and monitor project progress, manage issues and delay and escalate to management when necessary, review and supplement system design, examine quality of deliverables, ensure the projects are delivered on time and meet user requirements and government IT standards.
-
Elicit and analyse user requirements, convert business process into technical requirements, prepare specifications for procurement of IT equipment and outsourced services.
-
Plan, participate and control all phases of projects including systems analysis and design, procurement and installation, implementation, system and user acceptance testing, production rollout, system nursing and maintenance.
-
Conduct regular assessment, review and risk management of the projects, proactively alert potential project risks and issues to projects team members.
(C) Carry out any other IT related tasks assigned by the supervisor.
Requirements:
-
Bachelor's degree holder in Computer Science, Information Technology or equivalent.
-
Possess at least one of the industry recognised IT security certification (e.g. CISA, CISSP, CISP, etc) is required; at least 5 years' experience in Information Security Management, IT Security; knowledge of managing corporate IT security framework;
-
Experience in compliance of government IT security policies and guidelines, IT security risk management and threat management (e.g. S17, G3, Security Risk Assessment and Audit (SRAA), and Privacy Impact Assessment (PIA)) is required; at least 3 years' experience in SRAA;
-
Experience in managing outsourced IT security and network enhancement projects, from requirement study, system design, implementation, to testing and deployment is required; at least 5 years' experience in network design, network and system management; Knowledge of endpoint security solutions is an advantage;
-
Strong communication and liaison skills with multiple user groups and contractors, experience in eliciting, analyzing, and documenting user requirements, as well as planning and coordinating larger-scale user acceptance and production rollout are required;
-
Experience in managing government IT projects and preparing general project deliverables (e.g. SA&D report, project schedule, resources plan, project progress report, UAT plan, production rollout plan, etc.) is required. Experience in preparing project deliverables in government formats (e.g. Project Management Plan, Project Initiation Document, PIDR, Project Highlight Report, Quality Assurance Report, etc.) is preferred.
-
Experience in government IT product and service procurement is preferred; Knowledge of IT procurement is an advantage;
-
Experience in Xinchuang (XC) products and solutions is preferred.
-
Project management certification (e.g. PRINCE2, PMP) is preferred.
-
Overtime and on-call outside office hour are required when necessary,
-
Independent, self-motivated and good sense of responsibility; and
-
Pleasant personality and good interpersonal skills.
Please apply by email or WhatsApp by quoting Job Title with InfoTech's Job Key No (one alphabet prefix with up to five digits) as subject. You may directly apply online for this post at https://www.infotech.com.hk/itjs/job/fe-view.do?method=feView&jjKey=34400
The information provided will be treated in strict confidence and be used only for consideration of your application for relevant / similar posts within the Group/ Company.
工作種類 | |
工作地區 | 金鐘 |
教育程度 |
學士
|
技能 | 溝通能力 |
受僱形式 | 全職 |
行業 | 資訊科技 / 電子商務 |
InfoTech is well acquainted with development languages, scripts, frameworks, deployment/test tools, database, servers, virtualization, storage, networks, infrastructure and information security. InfoTech understands complex business logic and application flow, we appreciate architecture and methodologies. InfoTech serves an extensive client base covering leading banks, financial institutions, government bureaux, departments, subvented organizations, Chinese and multinational corporations, academic institute, vendors, systems integrators, etc.
InfoTech offers permanent placement, executive search and contract staff secondment services. InfoTech is one of the largest and longest established IT staff services and executive search companies in Hong Kong. Over our 32 years’ corporate history, it is believed that about a third of the IT working population in Hong Kong has been served by InfoTech, no matter as job seekers, placed candidates, contract staff or employers.
IT talent is offering the right ICT solutions for society, InfoTech endeavours to provide the right career for IT talent. Count on InfoTech, the best-in-class IT career partner now.
InfoTech 尊重每位求職者。IT求職者都信賴 InfoTech,深信 InfoTech 隨時能夠幫助他們。求職者知道 InfoTech 懂 IT 術語、技術和薪酬水平。InfoTech 能耐心聆聽求職者對職業生涯的期望和抱負。IT 讓 InfoTech 存在,InfoTech 卻堅持人性化的搜索與篩選,建基於先進的招聘系統。InfoTech 會以謹慎、熱衷、忠誠、道德和專業的態度來處理每個招聘項目。
InfoTech 熟悉開發語言、腳本、框架、發佈和測試工具、數據庫、服務器、虛擬機、存儲、網路、基礎設施和資訊安全。InfoTech 明白複雜的商業邏輯和應用流程,瞭解系統架構與方法。InfoTech 服務各大銀行、金融機構、政府部門、資助機構、中國和跨國公司、科研院所、大學、厰商、系統集成商等。
InfoTech 的服務包括招聘、獵頭、派遣和租賃等。InfoTech 是香港其中一間最大和歷史最悠久的 IT 人才服務機構。在香港,約三分之一的 IT 人才,無論是以求職者、合約派遣員工或者是以僱主的身份,都曾經使用過 InfoTech 的服務。
IT人才正在為社會提供適當的 ICT 解決方案,InfoTech 同時致力為 IT 人才提供理想的職業。要信賴最好的 IT 職業合作夥伴 InfoTech,來開拓您職業生涯的新篇章。
Please apply to the relevant e-mail mailbox and quote InfoTech's Job Key No (two alphabet prefix with four digits) and Position as subject. Check other InfoTech hot jobs, press here.
Main: (852) 2836 0363
WhatsApp: (852) 9758 2775
Address: 18/F, Tower 2, Lippo Centre, 89 Queensway, HK