Systems Manager (Information Security Office) [For Serving HA Staff Only]
Summary
Systems Manager in the Hospital Authority's IT and Health Informatics Division (Hong Kong) leading the Information Security Office: sets cybersecurity strategy, runs real-world attack simulations, manages the security technology lifecycle, budgets and a team of security professionals. Internal posting — open only to serving HA staff. HK$87,027–143,298/month.
Application Deadline \: 25 September 2026
Date of Issue \: 11 September 2026
Vacancy Notification Circular No. HOITD2609004
| Position | \: | Systems Manager (Information Security Office) |
| Rank | \: | Systems Manager |
| Department / Cluster | \: | Information Technology and Health Informatics Division, HA Head Office |
| Pay | \: | HK$87,027 to HK$143,298 (HMPS Point 7 to 19) per month including Monthly Allowance Up to 15% of total basic salary (after deducting the contribution of Mandatory Provident Fund by Hospital Authority) as end-of-contract gratuity may be offered to contract staff upon completion of the contract subject to satisfactory performance. |
Key Responsibilities
Develop and lead the execution of cybersecurity strategies to manage emerging risks and support IT initiatives.
Provide specialized offensive cybersecurity expertise, integrating strategic risk management and legal governance to conduct real-world attack simulations.
Implement HA’s cybersecurity strategic programmes and drive improvements through technological innovation and process optimization.
Manage the full lifecycle of cybersecurity technologies and services, including sourcing, assessment, development, implementation and support.
Manage a team of security professionals and external vendors, providing technical leadership and mentorship to maintain a high-performing workforce and foster a culture of continuous learning.
Oversee resource management, including budget control, manpower allocation and capacity planning.
Analyze short- and long-term business requirements and work with other IT teams to formulate the information security initiatives.
Entry Requirements
Degree in Computer Science or relevant disciplines; or equivalent.
Over 10 years’ post qualification Information Technology (IT) related experience.
Preferable Attributes/Exposure
Possession of Certified Information Systems Security Professional (CISSP) or equivalent certificate.
At least 5 years’ post qualification experience in cybersecurity technology, architecture and technical consultation and cybersecurity engineering, in which 3 years in a team leading role.
Solid knowledge in cybersecurity technology assessment, cybersecurity management framework, IT policy and standard, technology risk compliance, security review and risk posture reporting.
Strong leadership, analytical, communication and interpersonal skills, including fluency in both English and Chinese.
Innovative, open-minded and able to work under pressure.