Cyber Risk & Operations Manager
Company Background
We are a leading Asian investment firm withapproximately USD 13 billion in assets under management across our funds.Our flagship FengHe Asia Fund is recognised as one ofthe most consistent and best-performing long-short equity funds in Asia.
For more information, please visit www.fengheasia.com.
Role & Responsibilities
Managed Services Provider Oversight
- Act as the firm's primary point of accountability for the outsourced IT provider's security and risk performance
- Define, negotiate, and enforce SLAs, security requirements, and reporting obligations; review the outsourced IT provider's deliverables, reports, and evidence with acritical eye rather than accepting them at face value
- Run structured service and risk review meetings with the outsourced IT provider; track open issues, remediation items, and commitments to closure
- Independently validate the outsourced IT provider's work where warranted. E.g., commissioning third-party penetration tests, reviewing vulnerability scan results, sampling access reviews, and challenging patching and configuration practices
- Review the outsourced IT provider's assurance materials (SOC 2 reports, certifications, subcontractor arrangements) and assess residual risk to the firm
- Ensure the firm retains adequate knowledge, documentation, and exit options to avoid unhealthy dependency on any single provider
Cyber Risk Management & Governance
- Own the firm's cyber and IT risk framework: risk register, risk assessments, key risk indicators, and risk appetite reporting
- Maintain the firm's information security policies and ensure the outsourced IT provider's operations comply with them
- Report regularly to senior management (and the board/investors as required) on the firm's cyber risk posture, outsourced IT provider performance, and emerging threats
Incident Leadership
- Own the firm's incident response plan; ensure the outsourced IT provider's incident processes integrate well with it
- Lead the firm's response to any cyber incident. Direct and coordinate the outsourced IT provider, brief executives in real time, manage legal/regulatory/insurer notifications, and own investor and counterparty communications
- Run tabletop exercises involving both the firm and the outsourced IT provider at least annually; drive lessons learned into concrete improvements
Resilience & Awareness
- Ensure business continuity and disaster recovery arrangements delivered through the provider meet the firm's recovery objectives and are validated through regular testing
- Run the firm's security awareness program, including phishing simulations and targeted training for high-risk functions
Job Requirements
- 7+ years in cyber security, technology risk, or IT governance, ideally including experience overseeing managed service providers or outsourced IT arrangements
- Financial services background strongly preferred (hedge fund, asset manager, fund administrator, or investment bank); familiarity with the outsourced managed-IT model common among hedge funds is a significant advantage
- Strong technical fluency across the domains typically delivered by an outsourced IT provider: cloud infrastructure, identity and access management, EDR/SIEM, vulnerability management, network security, and backup/DR architectures
Skills & Attributes
- Sophistication and judgment: strong understanding of what effective security assurance looks like, with the ability to hold a large vendor to a high standard
- Gravitas and communication: credibly represents the firm in front of investors, regulators, boards, and vendor executives; translates technical risk into commercial language
- Exceptional attention to detail: thorough in reviewing assurance reports, technical evidence, and documentation, with a strong eye for gaps
- Composure under pressure: leads decisively during incidents in a high-intensity environment
- Strong vendor management skills: builds a productive, collaborative working relationship with the provider while maintaining clear accountability
- High integrity and discretion: handles highly sensitive information appropriately