
Brian C.
Manager, Group Cyber Defense @ John Swire & Sons (H.K.) Ltd.
About
I am an individual who has been working across audit, security and operations, focused on making detection and response actually work. I care about real outcomes, improving detection quality, reducing noise, shortening response time, and building procedures that hold up during real incidents. Not building one more layer of control/tools on top of another.While many focus on penetration testing, red teaming, or leadership titles, I rather focus on execution: detecting early and responding effectively when it matters. My work includes studying attacker patterns, and turning TTPs into actionable detections, tuning rules to reduce false positives and improve the life of Operations and Support, automating response where it genuinely improves speed and consistency, and configuring tools to work effectively instead of constantly introducing new ones. I aim to bridge security, Infra and Operations through practical, efficient, and executable solutions. Not that into Linkedinese too.
Hong Kong SAR
Hong Kong
Computer & Network Security
Cloud Access Security Broker (CASB), Endpoint Detection and Response, Security Information and Event Management (SIEM), Azure Sentinel, Cyber Threat Hunting (CTH), ITGC, Personal Data Protection, FinTech, IT Risk Management, KYC Verification, Cybersecurity Auditing, Security Incident Response, Microsoft Defender for Endpoint, Project Management, Release Management, Quality Assurance, IT Audit, Information Security Management, Internal Audit, Vendor Management
Experience

Manager, Group Cyber Defense
Hong Kong SAR
[Reporting to Group CISO] - Lead Group-wide cybersecurity incident management policy, standards and control framework, ensuring scalable adoption of tools. - Govern core cyber defense tools and platforms (EDR/XDR, SIEM/SOAR), driving threat Intel and knowledge sharing, detection playbooks and responses development, Operation Metrics/KPIs, and incident handling. - Enhance the threat detection, intelligence management, including custom detection rules, scripts to improve time‑to‑detect. - Strengthen the DLP capabilities and WAF rules to block data exfiltration and web based attacks. - Plan and orchestrate Group cyber crisis exercises to validate and uplift incident response readiness. - Lead enhancement project to cyber security operations for Head Office - Regularly analyze the latest threat intelligence, translate emerging threats into actionable detection strategies, and custom detection rules to improve time-to-detect and time-to-respond. - EDR/XDR and SIEM integrations, configuration and detection rules development and tuning, ensuring effective telemetry, detections and automation coverage. - Lead the cyber security budgeting, annual planning for specific service lines.

Vice President IT Audit
[Reporting to Managing Director of Audit] - Led risk‑based reviews of IT governance and cyber security controls across infrastructure and applications, assessing design and operating effectiveness for cyber resiliency. - Assessed adherence to technology risk, information security and data protection policies/regulations, highlighting gaps in identity, access management and security monitoring. - Tracked and challenged management action plans for IT audit, vulnerability assessment and penetration test findings to ensure timely and sustainable remediation. - Monitored emerging cyber threats, regulatory changes and industry practices, and translated them into updates to audit programmes and risk assessments. - Coordinated with external penetration testing and red‑team providers, from scoping and execution through to verification of remediation. - Provided advisory on data privacy, secure architecture and IT compliance for new initiatives, influencing design‑time security and risk acceptance decisions.

Senior Manager IT Audit
[Reporting to Chief Audit Executive] - Established the bank’s Internal IT Audit function from the ground up, including methodology, templates and tooling, to support regulatory approval and business commencement. - Designed and executed the inaugural IT and cybersecurity audit strategy and annual plan, aligned to local banking / cybersecurity regulations and the bank’s risk appetite. - Developed detailed audit programs covering remote onboarding, eKYC, e‑Banking, customer data protection, cyber security, technology risk management and business continuity management. - Led and delivered end‑to‑end fintech and cyber security audit engagements, providing clear findings, risk ratings and practical remediation recommendations to senior management. - Monitored and challenged management action plans, tracking remediation of IT, cyber security and compliance findings through to verified closure to ensure audit‑ready status for go‑live

IT Audit Manager, Group Audit
[Reporting to IT Audit Head] - Led and executed IT and cyber security audit engagements across domains including infrastructure & operations, technology risk management, vendor and third‑party risk, project management, SDLC and outsourcing. - Planned, coordinated and delivered ASEAN entities' IT and cybersecurity audits, providing remote support and oversight to ensure consistent audit coverage, risk assessment and remediation tracking across locations

Enterprise Security Testing Analyst / IT Quality Assurance
- perform annual security testing program of infrastructure service and application, provide recommendations and process improvement to teams, and followup the rectification progress. - draft up test report and status report to senior management for address the key risk uncovered. - shape up the remediation plan of corrective actions and track the status until proper closure.

Transition Analyst (Infrastructure and Security)
Hong Kong
- IT Project Governance, gate keeping for service launches relating to Enterprise services, Infrastructure services, security services. - Maintain key risk and status information and status reports update to Head of Transition, Head of Infrastructure and Senior management. - Build up the operational capability and manage the stakeholders' expectation upon deployment of services.
Brian C.'s Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.




