The Head of Risk is responsible for leading Cyberport’s enterprise‑wide risk management framework, providing independent oversight and strategic risk advisory to senior management and the Board. The role ensures effective identification, assessment, management, and reporting of strategic, operational, technology, cybersecurity, regulatory, and emerging risks, in line with Hong Kong public‑sector governance standards and best practices.
Jobs Description
Enterprise Risk Management & Governance
Lead the design, implementation, and continuous enhancement of Cyberport’s enterprise‑wide risk management framework, policies, and methodologies, aligned with Hong Kong public‑sector governance standards and recognised best practices.
Establish and maintain risk appetite, tolerance levels, and key risk indicators, ensuring effective integration of risk considerations into corporate strategy, major programmes, investments, procurement, and new initiatives.
Risk Oversight Across Cyberport Functions
Provide independent oversight of risks across Cyberport’s key functions, including incubation and ecosystem programmes, investment activities, campus operations, corporate services, and enterprise IT / digital platforms.
Review and challenge business unit risk assessments and suggest risk mitigants to ensure alignment with the approved enterprise risk appetite.
Oversee technology and cybersecurity risk governance, covering data protection, system resilience, and third‑party/ vendor risk, and advise on emerging business, digital, and innovation‑related risks.
Regulatory, Statutory & Public Accountability Alignment
Support Cyberport’s alignment with applicable statutory, regulatory, and public accountability requirements.
Coordinate with internal stakeholders and, where required, government authorities and regulators; monitor regulatory developments and advise senior management and the Board on implications and risk exposure.
Risk Reporting, Assurance & Control
Deliver clear, concise enterprise risk reporting to senior management and the Board, and ensure timely escalation of material risks, control weaknesses, and incidents.
Provide oversight of the Risk, Legal & Compliance functions, coordinate effectively with Internal Audit, and oversee the remediation of audit findings, control deficiencies, and risk incidents.
Risk Culture & Capability Building
Promote a strong risk‑aware culture across the organisation through training, guidance, and active engagement with management and staff.
Strengthen organisational capability in risk identification, assessment, mitigation, and monitoring.
Perform other ad-hoc duties assigned by supervisor
Job Requirement
Degree in Risk Management, Finance, Business, Engineering, Information Systems, or a related discipline.
Professional qualifications such as LLM, PRM, CPA, CIA, CISA, FRM, or equivalent strongly preferred.
15+ years of relevant hands-on experience in enterprise risk management, governance, or related fields, gained in large, complex organizations, preferably public bodies, statutory organizations, or regulated entities.
Strong understanding of Hong Kong public‑sector governance and accountability expectations.
High integrity, sound judgement, strong communication skills, and ability to provide pragmatic advise.
Experienced in scenario analysis, resilience planning, and stress testing for strategic and emerging risks.
Experienced in crisis and incident management, including advisory support to senior management during major risk events.
Experienced in supporting post-incident reviews, lessons learned, and control enhancements.
Experienced in assessing commercial, investment, and partnership risks.
Experienced in supporting organisational transformation and innovation initiatives through practical, enabling risk management.
Experienced in engaging with the Board and senior executives.
Demonstrated ability to provide forward-looking, strategic risk insights aligned to organisational objectives and public value creation.
Excellent written and verbal communication skills, with demonstrated ability to distil complex risk issues for senior and non-technical audiences.
Ability to execute initiatives and delivery results independently.
Resilient, pragmatic, and solutions-oriented leader with strong emotional intelligence and organisational awareness.
We offer competitive package to the right candidate. Interested party please click "Apply Now" to apply on or before 15 August 2026 in confidence with full resume, stating present and expected salary, and available date and quote the reference.
Applicants who do not hear from us by 30 September 2026 may assume that their applications are unsuccessful.
Further information about the Cyberport is available at https://cyberport.hk/
Personal data collected will be treated in the strictest confidence and only be used for recruitment-related purpose.
Job details
- Industry
- Information Technology
- Job Function
- Legal / Professional Services > Legal & Compliance
- Location
- Southern District
- Employment Type
- Full Time
- Published On
- 27 Jul 2026
