
Joyce F.
Assistant Computer Officer – Department of Computer Science

Connect with Joyce F. to Send Message
Connect
Connect with Joyce F. to Send Message
ConnectTimeline
About me
CISO | Cyber Security | Technology Risk Management | Security Governance and Assurance
Education

Kornerstone Limited
-Certified Master Coach of NLP for Business Leadership and Success Coaching
University of Central England Business School
2004 - 2005Master of Science (MSc) Audit Management & Consultancy
University of Melbourne
2024 -Graduate Diploma Communications Law(current studying)

The University of Hong Kong
2014 - 2016Master’s Degree Master of Laws in Information Technology and Intellectual Property Law [LLM(IT&IPL)]
City University of Hong Kong
1998 - 2001Master of Science (MSc) Computer Science
Experience

City University of Hong Kong
Jun 2006 - Feb 2007Assistant Computer Officer – Department of Computer Science• Prepared courseware for CS courses, including data rights management, computer networks and Internet programming; and• Did researches on cryptography, web and wireless technologies, and network/system security.

Automated Systems (HK) Limited
Feb 2007 - Mar 2014Assistant Manager, Security Consulting• Conduct IT security risk assessment and audit services, ethical hacking / penetration tests, vulnerability scanning, application design review, web application security tests, mobile apps security tests, source code review, and database security review; • Perform IT security policies, guidelines, and procedures development and review;• Perform IT security control and compliance review;• Perform personal data privacy control and compliance review;• Provide recommendations to clients on managing risk, control and compliance issues;• Provide presentations senior management and technical staff, and security user awareness training to general staff;• Help clients to investigate application security incidents, root cause analysis, and propose remediation;• Provide IT security monitoring services, and detailed intrusion detection and monitoring report;• Assist in IT security risk assessment and audit service proposal write up and mandays estimation, and provide presale / proposal presentation; and• Monitor the progress of activities during the entire project life cycle, and point out any deviation from project plan. Show less

CLP Power Hong Kong Ltd
Mar 2014 - Dec 2015System Analyst – Cyber Security Team• Perform information security control review, • Provide advisory in information security policy compliance;• Promote cyber security awareness across the company;• Co-ordinate and manage the team for a tender process;• Manage and monitor projects deliverable, within the planned schedule and budget; and• Manage vendors to deliver deliverable on time, with good quality.

VF Corporation
Dec 2015 - Jul 2018Information Security Manager, Global Security Risk & Compliance (Regional Role)• Reported to Senior Director, Security Risk & Compliance, based in United States• Responsible for aligning global information risk management strategy and framework with emerging business requirements; governing and maintaining security standards required in the Asia region• Participated in performing security reviews on multiple eCommerce projects throughout Asia Pacific and Mainland China, to ensure sufficient controls were designed and integrated into the technical solutions to meet internal and local legal and regulatory requirements for Data Privacy and Cybersecurity, and Payment Card Industry Data Security Standard• Conducted regular security assurance tests to ensure implemented security controls in critical systems are SOX compliant Show less

AXA Hong Kong and Macau
Jul 2018 - Nov 2024Act as the member of AXA HK Chief Security Officer (CSO) Leadership Team to remotely provide security consultancy services: -- Oversee AXA HK’s information security and cybersecurity risks- Building and executing Security Strategy and Framework- Driving initiatives to secure AXA technology assets- Managing Security Governance, Risk and Compliance (GRC) process- Managing Security Budget- Collaborating with senior stakeholders to identify and manage cybersecurity risks- Participating in special projects (example: Fast Isolation Technical Analysis / Business Continuity Planning) Show less • Member AXA HK CSO Leadership Team• Equivalent to Chief Information Security Officer (CISO) role to: • Oversee AXA HK and Macau information security and cybersecurity risks • Build and drive security strategy and framework, based on NIST Cybersecurity Framework + ISO/IEC 27001 ISMS Standard + ISO/IEC 27002 ISMS Standard • Drive initiatives to secure company technology assets • Manage Information Security Budget • Maintain ISO/IEC 27001 Information Security Management System (ISMS) Certification for AXA HK (the scope of which incorporates all operations of AXA Hong Kong and Macau in the primary office locations) • Manage cybersecurity posture of AXA HK • Work closely with Group Security Team and Group IT to develop and update security policy, framework, and training materials for AXA entities; Local Risk Team, Compliance Team, IT Team, Business Teams to identify and manage cybersecurity risk • Provide management reporting to senior executives (Group CSO, AXA HK CEO, Board or equivalent) • Participate in special projects, including conducting due diligence in Merger and Acquisition Transactions, providing advice on various projects related to Mainland China customer data protection • Backup to the day-to-day cybersecurity operations (1st line of defence)• Led a team of five people to: Manage Security Governance, Risk and Compliance (GRC) process Develop, update and enforce AXA HK Security Policy and Process documents Conduct security architecture reviews, application security risk assessments Conduct vendor (3rd party) security assessments Conduct regular security assurance tests to assess the effectiveness of security controls Prepare management update on security status and remediation update; and requested information from regulators Launch security awareness campaigns for AXA HK and Macau users, new joiners, IT developers, agents and contractors Conduct risk assessment for security exception requests Show less
Principal Consultant
Aug 2023 - Nov 2024Head of Information Security, Assurance & Governance (equivalent to CISO role)
Mar 2022 - Jul 2023Senior Manager, Information Security Assurance & Governance (equivalent to CISO role)
Apr 2020 - Feb 2022Manager, Information Security Operations
Jul 2018 - Mar 2020
Licenses & Certifications

ITIL Foundation Certificate in IT Service Management
EXINJul 2012%C2%B2.webp)
Certified Secure Software Lifecycle Professional (CSSLP)
(ISC)²Apr 2009%C2%B2.webp)
Certified Information Security Professional (CISSP)
(ISC)²May 2002.webp)
Certified Risk Management Professional (CRMP)
DRI International (Disaster Recovery Institute)Nov 2021
Certified in Risk and Information Systems Control (CRISC)
ISACASept 2011
Certified Information System Audit (CISA)
ISACAJun 2003
Certified Data Privacy Solutions Engineer (CDPSE)
ISACAJul 2020
Certificate of Cloud Security Knowledge (CCSK)
Cloud Security AllianceApr 2013.webp)
Certified Business Continuity Professional (CBCP)
DRI International (Disaster Recovery Institute)Feb 2014
Honors & Awards
- Awarded to Joyce F.2016 (ISC)2 Asia Pacific Information Security Leadership Achievements (ISLA) (ISC)2 Jul 2016 ISLA program is to recognize the outstanding professionals in the region for their contribution to the success of information security projects and raising the information security awareness throughout last year.
Volunteer Experience
Hon. Secretary & Treasurer
Issued by Professional Information Security Association on Sept 2017
Associated with Joyce F.Chairperson
Issued by Professional Information Security Association on Sept 2016
Associated with Joyce F.Vice Chairman (Membership & Constitution)
Issued by Professional Information Security Association on Sept 2015
Associated with Joyce F.Vice-Chairperson (Internal Affairs)
Issued by Professional Information Security Association on Sept 2014
Associated with Joyce F.Membership Chair
Issued by (ISC)2 Hong Kong Chapter on Feb 2016
Associated with Joyce F.Secretary
Issued by (ISC2)2 Hong Kong Chapter on Jan 2014
Associated with Joyce F.
Recommendations

Yousra dahaj
Financial & Accountant Analyst | Finance and accounting Teacher | Certified® SAP S/4HANA Consultan...الرباط-سلا-القنيطرة المغرب
Pedro henrique
FullStack Developer Node | React | TypescriptDublin, County Dublin, Ireland
Muhammed tanrıkulu
ParalegalBelgium
Jory hogeveen
Full Stack Web & App Developer | Designer | Sound engineer | ProducerNijmegen, Gelderland, Netherlands
Shaun powell cspo
IT Professional | IT Strategy |Business System Implementations | Process Design | IT Project Managem...Katy, Texas, United States
Kirill nemykin
WEB QA Engineer – G5 Games®Ukraine
Blessin siby
An enthusiastic Automotive Engineer looking for opportunitiesRiga, Latvia
Alexandros argyris
Food and Beverage Operations Manager at Branco MykonosGreece
Heidi van berkel
HR Project Manager/ Business Partner 4PSAmersfoort, Utrecht, Netherlands
Nur çatana
Eurasia & Middle East OU Senior FP&A DirectorIstanbul, Türkei
Sadiq ali a.
Standards & Controls Engineer at Jaguar Land RoverLondon, England, United Kingdom
Ivan bošnjak
🌐 Software Engineer🔹 Java🔹 SQL🔹 JavaScriptCroatia
Jonathan moskowitz
Managing Director - Investments, Financial Advisor at Wells Fargo AdvisorsMetro Jacksonville
Jonathan mimmo, m.s.
Analyst, Sr. Client Delivery Advocate at iCapitalStony Point, New York, United States
Dave deuel
Academic Dean Emeritus / Senior Research Fellow EmeritusBroadalbin, New York, United States
Ahmed medhat
ESP Engineerمصر
Simone hencke
Liderança e gestão de equipes,comercial.Canela, Rio Grande do Sul, Brazil
Leslie wasiluk
eCommerce Product/Content Specialist and Administrative Manager at Brand LabsNeenah, Wisconsin, United States
Geovana laniny, cea
Gerente de Relacionamento Select | Profissional do Segmento Financeiro | Certificação ANBIMA CEAUberaba, Minas Gerais, Brazil
Bhupesh varma
Talent Acquisition Partner (Mentor Hiring) - TalentServe || Suvidha Foundation Maharashtra, India ||...Maharashtra, India
...