SCHOOL OF CONTINUING EDUCATION
The School of Continuing Education, one of the seven Faculties/Schools of the University and a major provider of continuing and professional education in Hong Kong, offers a wide range of full-time and part-time programmes at the post-secondary, undergraduate and postgraduate levels for young learners and working adults. It also offers in-house training and short courses to meet the community needs and market demands. Operated on a self-financed basis, the School and its College of International Education currently employ about 400 full-time staff and 500 part-time instructors. The School is inviting applications for the following position:
Information Technology Manager (Cybersecurity and Network) (Ref. No.: 26270193)
Reporting to the Senior Information Technology Manager, the appointee will support the planning, implementation, operation, and continuous improvement of the School’s cybersecurity and network infrastructure. The role will assist in strengthening cybersecurity controls, managing network security operations, supporting identity and access management, coordinating security assessments, and ensuring that IT infrastructure and network services are secure, reliable, and aligned with institutional policies, compliance requirements, and operational needs.
This is a continuous-based position.
Key responsibilities
- Cybersecurity Operations and Compliance
- Formulate, implement, maintain, and review cybersecurity policies, standards, procedures, and operational controls to strengthen the School’s overall security posture.
- Manage cybersecurity risk management, vulnerability management, threat monitoring, incident response, and security remediation activities.
- Oversee the operation and administration of cybersecurity solutions, including endpoint protection, email security, identity protection, cloud security, data protection, and security monitoring tools.
- Review security alerts, guide incident investigation, and coordinate response and remediation actions with internal teams, vendors, service providers, and relevant stakeholders.
- Maintain and enhance cybersecurity documentation, incident response procedures, disaster recovery arrangements, audit evidence, and governance-related records.
- Plan and promote cybersecurity awareness initiatives and drive the adoption of good security practices across the School.
- Network Infrastructure and Network Security
- Lead the planning, design, implementation, administration, and continuous improvement of the School’s network infrastructure and network security environment.
- Manage firewalls, VPN, wireless networks, switches, routers, network segmentation, secure remote access, and related network services to ensure secure and reliable connectivity.
- Oversee network security controls, including access control, firewall rule review, secure configuration, network monitoring, capacity review, and vulnerability remediation.
- Manage network planning, performance monitoring, troubleshooting, service improvement, and resilience enhancement to support business and academic operations.
- Coordinate with internal teams, vendors, and service providers on network projects, infrastructure migration, cloud connectivity, and integration with institutional systems.
- Review and maintain network diagrams, configuration records, operational procedures, service documentation, and change records to support effective governance and service continuity.
- Lead or participate in business continuity, disaster recovery, and resilience planning for network and security infrastructure.
Required skills and experience
- At least 8 years of relevant experience in cybersecurity, network infrastructure, network security, system administration, or related IT disciplines, with proven experience in team supervision, project management, or service ownership.
- Strong hands-on and management experience in planning, implementing, administering, monitoring, and continuously improving cybersecurity controls and network infrastructure.
- Sound knowledge of cybersecurity governance and operations, including risk management, vulnerability management, threat monitoring, incident response, security remediation, audit support, and compliance requirements.
- Strong understanding of network technologies and network security, including switches, routers, firewalls, VPN, wireless networks, network segmentation, secure remote access, access control, network monitoring, and secure configuration management.
- Experience in leading or coordinating security assessments, audits, vulnerability scans, penetration tests, firewall rule reviews, configuration reviews, remediation planning, and follow-up actions.
- Practical knowledge of identity and access management, Single Sign-On, Multi-Factor Authentication, privileged access control, Microsoft 365, Entra ID, Azure, endpoint protection, email security, cloud security services, and related security controls.
- Experience in developing, reviewing, and maintaining technical documentation, network diagrams, configuration records, operational procedures, incident response procedures, audit evidence, service records, and governance-related documentation.
- Proven ability to manage internal users, IT teams, vendors, and service providers for daily operations, troubleshooting, project implementation, procurement support, contract follow-up, service delivery, and continuous service improvement.
- Good project management, planning, prioritisation, stakeholder engagement, and vendor coordination skills, with the ability to deliver assigned initiatives within agreed scope, timeline, budget, and quality expectations.
- Strong analytical, problem-solving, communication, coordination, leadership, and documentation skills, with the ability to explain technical matters clearly to both technical and non-technical stakeholders.
- Self-motivated, detail-oriented, responsible, and able to work independently, supervise assigned tasks, and collaborate effectively with internal teams and external parties.
- Good command of written and spoken English and Chinese, including fluent Cantonese.
Education and certifications
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Network Engineering, or a related discipline, or equivalent practical experience.
- Professional certifications preferred, including one or more of:
- CISSP;
- CISM;
- Microsoft Certified: Cybersecurity Architect Expert;
- CCNA, CCNP, or equivalent networking certification;
- Fortinet, Palo Alto, Check Point, Cisco Security, or equivalent firewall/network security certification;
- ITIL Foundation or above.
Shortlisted candidates will be invited to attend a written assessment.
The initial appointment will be offered on a fixed-term contract ending in August 2027. Re-appointment thereafter will be subject to mutual agreement and availability of funding.
Salary will be commensurate with qualifications and experience.
Application Procedure:
Applicants are invited to submit their applications at the HKBU e-Recruitment System. Those who are not invited for interview 8 weeks after submission of applications may consider their applications unsuccessful. Details of the University’s Personal Information Collection Statement can be found at https://hro.hkbu.edu.hk/en/worklife-at-hkbu/employee-favourable-environment.html#privacy-policy.
The School reserves the right not to make an appointment for the post advertised, and the appointment will be made according to the terms and conditions then applicable at the time of offer.
Review of applications is ongoing until the position is filled.