Cyber Risk & Operations Manager
About the role
Company Background
We are a leading Asian investment firm with approximately USD 13 billion in assets under management across our funds.
Our flagship FengHe Asia Fund is recognised as one of the most consistent and best-performing long-short equity funds in Asia.
For more information, please visit
Role & Responsibilities
Managed Services Provider Oversight
Act as the firm's primary point of accountability for the outsourced IT provider's security and risk performance
Define, negotiate, and enforce SLAs, security requirements, and reporting obligations; review the outsourced IT provider's deliverables, reports, and evidence with a critical eye rather than accepting them at face value
Run structured service and risk review meetings with the outsourced IT provider; track open issues, remediation items, and commitments to closure
Independently validate the outsourced IT provider's work where warranted. E.g., commissioning third-party penetration tests, reviewing vulnerability scan results, sampling access reviews, and challenging patching and configuration practices
Review the outsourced IT provider's assurance materials (SOC 2 reports, certifications, subcontractor arrangements) and assess residual risk to the firm
Ensure the firm retains adequate knowledge, documentation, and exit options to avoid unhealthy dependency on any single provider
Cyber Risk Management & Governance
Own the firm's cyber and IT risk framework: risk register, risk assessments, key risk indicators, and risk appetite reporting
Maintain the firm's information security policies and ensure the outsourced IT provider's operations comply with them
Report regularly to senior management (and the board/investors as required) on the firm's cyber risk posture, outsourced IT provider performance, and emerging threats
Incident Leadership
Own the firm's incident response plan; ensure the outsourced IT provider's incident processes integrate well with it
Run tabletop exercises involving both the firm and the outsourced IT provider at least annually; drive lessons learned into concrete improvements
Resilience & Awareness
Ensure business continuity and disaster recovery arrangements delivered through the provider meet the firm's recovery objectives and are validated through regular testing
Run the firm's security awareness program, including phishing simulations and targeted training for high-risk functions
Job Requirements
7+ years in cyber security, technology risk, or IT governance, ideally including experience overseeing managed service providers or outsourced IT arrangements
Financial services background strongly preferred (hedge fund, asset manager, fund administrator, or investment bank); familiarity with the outsourced managed-IT model common among hedge funds is a significant advantage
Strong technical fluency across the domains typically delivered by an outsourced IT provider: cloud infrastructure, identity and access management, EDR/SIEM, vulnerability management, network security, and backup/DR architectures
Skills & Attributes
Sophistication and judgment: strong understanding of what effective security assurance looks like, with the ability to hold a large vendor to a high standard
Gravitas and communication: credibly represents the firm in front of investors, regulators, boards, and vendor executives; translates technical risk into commercial language
Exceptional attention to detail: thorough in reviewing assurance reports, technical evidence, and documentation, with a strong eye for gaps
Composure under pressure: leads decisively during incidents in a high-intensity environment
Strong vendor management skills: builds a productive, collaborative working relationship with the provider while maintaining clear accountability
High integrity and discretion: handles highly sensitive information appropriately
Questions about this role
Want AI Applyd to auto-apply to roles like this?
We tailor your resume per posting, fill the forms, and track replies for you.