About iGears
iGears Technology Limited (科擎科技有限公司) has built software for Hong Kong organisations since 2004, including listed companies, public-sector bodies, NGOs, education organisations and churches. We develop and run 20 of our own SaaS products, and our MobPage division has published 200+ mobile apps. With offices in Hong Kong and Edmonton, Canada, we are now building an in-house cybersecurity team to deliver penetration testing, security risk assessments and privacy impact assessments for clients, and to secure our own platforms.
How we work together
Independent contractor, paid per engagement at an agreed day rate. Most work is remote document and configuration review, with occasional meetings or on-site visits in Hong Kong. You choose which engagements to take. If you would prefer regular part-time employment instead, tell us in your application and we will discuss an employment contract.
What you’ll do
- Deliver security risk assessments and audits (SRAA) and Privacy Impact Assessments (PIA) for Hong Kong clients, including public-sector projects, working with iGears’ lead assessor
- Review documentation, architecture and configurations, and map personal data flows
- Produce risk registers, remediation plans and reports in iGears’ templates
- Work within each engagement’s confidentiality and data-handling rules
What you’ll bring
- At least one of CISA, CISSP, CISM or ISO/IEC 27001 Lead Auditor
- At least 3 years in IT audit, security risk assessment or security consulting
- SRAA or PIA experience on Hong Kong public-sector projects
- Excellent written English
- Able to invoice iGears as a business (e.g. with a Hong Kong Business Registration Certificate)
- The right to work and do business in Hong Kong
- Willing to sign an NDA and to complete a background check where a client requires it
Nice to have
- A privacy certification such as CIPP/A, CIPP/E, CIPM or CDPSE
- Written Chinese, for bilingual deliverables
- Hands-on testing experience or OSCP
- Your own professional indemnity insurance
What we offer
- Paid per engagement at an agreed day rate
- Public-sector, enterprise and NGO assessment projects
- Flexible: you choose which engagements to take
- Part-time employment possible if you prefer it
Explore our platforms before you apply
- AI: GenCMS (gen-cms.com), AskCore (askcore.org), HumanLevelUP (humanlevelup.org), PromoPilot (promo-pilot.org), Webetter (webetter.co), PhotoCen (photocen.com), Duckbot (duckbot.hk, preview)
- Business operations: fileEC (fileec.com), InsightBook (insightbook.org), HRFlowTech (hrflowtech.com), MemberSys (membersys.org), AppointSys (appointsys.org), Paperless.Cards (paperless.cards)
- Messaging and marketing: SendPromotion.Email (sendpromotion.email), SendSMS.click (sendsms.click), MarketHK (markethk.net)
- Education and community: LearnSys (learnsys.org), ITChurch (itchurch.online)
- Directories: E12 (e12.hk, e12.ca) and E12 Careers (jobs.e12.hk, jobs.e12.ca)
Full list: https://www.igears.com.hk/platforms/
How to apply
Email [email protected] with the subject “Freelance SRAA/PIA – Your Name”. Please include your CV, your certification numbers, your day rate in HKD, your availability (days per month), and a redacted sample report if you have one.
iGears welcomes applications from all qualified candidates.
Personal data you provide will be used by iGears Technology Limited only for recruitment. Providing it is voluntary, but we can’t consider your application without it. It may be shared with other iGears offices if you are considered for a role there. Data of unsuccessful applicants is destroyed within two years. To access or correct your data, or for our full Personal Information Collection Statement, email [email protected].
https://e12.hk/pages/company.php?slug=igears-technology-limited
iGears Technology Limited (科擎科技有限公司) has built software for Hong Kong organisations since 2004, including listed companies, public-sector bodies, NGOs, education organisations and churches. We develop and run 20 of our own SaaS products, and our MobPage division has published 200+ mobile apps. With offices in Hong Kong and Edmonton, Canada, we are now building an in-house cybersecurity team to deliver penetration testing, security risk assessments and privacy impact assessments for clients, and to secure our own platforms.