Wai Yee Wong

Governance, Risk and Compliance

Canberra, Australian Capital Territory, Australia

About

For the past 4 years, I was a dedicated Information Security Officer at PCCW Global, where my primary focus was maintaining the ISO 27001 certification for Console Connect — a leading software-defined platform enabling secure, on-demand global interconnections. I bridged the gap between high-level security governance and technical execution. By leading conversations within the Security Steering Committee, I ensured our ISMS remained robust and aligned with business goals. My work was deeply collaborative; I partnered with SMEs and team leaders to manage security implementations. Furthermore, I approached audits not just as a compliance hurdle, but as a vital tool for continuous improvement, facilitating a supportive environment for auditors to ensure our security posture was constantly evolving. My foundation in information security was built during nearly five years at IBM, where I worked as an IT Security Specialist managing audits, compliance, and the policy review cycle. I remained a firm believer in continuous growth to stay ahead of the evolving threat landscape, backed by a robust portfolio of certifications including CISM, ISO 27001 Lead Implementer & Auditor, CEH, and Security+.

Experience

  • Information Security Officer at PCCW GLOBAL Limited
    Jun 2022 - Jul 2026 · 4 yrs 2 mos

  • IBM Client Innovation Centre (Malaysia) Sdn Bhd ()
    • Client Security Policy Associate
      Aug 2016 - Dec 2019 · 3 yrs 5 mos

      Review IT Security Policies for commercial clients based in Australia and New Zealand. ● (2018 July onwards) Dedicated personnel in managing policy works for one of Australia's major banks, handling more than 100 Technical Specifications. The Technical Specifications document all the security configurable settings for example Password, Logging, Network, Encryption, Privileges and other regulatory (such as GDPR, PCI-DSS) mandated settings. These documents will be approved by customer and the settings will then be implemented across the system and health checked in future. ● Prepared Security Document between IBM and Customer based on the main contract which defines the security related roles and responsibilities. ● Co-ordinate with the Delivery Team on customer involvement for security policy maintenance and manage project in a timely manner. ● Stored the completed document and associated artifacts in the authorized repository for Services Delivery Team usage and future audit inspection. ● Notify the customer with potential threat whenever their settings are less stringent than the Recommended Value.

    • Client Security Policy Associate and Lead KCFR Tester
      Jul 2017 - Jun 2018 · 1 yr

      Lead KCFR (Key Controls over Financial Reporting) Tester (Additional Role) Own and drive KCFR Testing Program for IBM Global Account Australia and New Zealand to ensure the account complies with the Sarbanes-Oxley Act for z/OS Mainframe and AIX servers. --------- Security Policy Review (Continued) Please refer to job description above.

    • Security Delivery Specialist
      Sep 2015 - Aug 2016 · 1 yr

      Ensured Internal Compliance. ● Conducted and led internal audit on IBM delivered processes or architectures. ● Conducted compliance activities and report to the senior management on the center's security compliance status. ● Raised, tracked and assisted closure of security risks. ● Educated staff on compliance to the company's Information Technology Corporate Standard.

  • Banquet Server (Work and Travel) at Arrowwood Resort & Conference Center
    Jun 2014 - Sep 2014 · 4 mos

    ● Lived, worked and traveled in the United States for 4 months ● Met people from around the world and made long lasting friendships ● Supported own living and travelling expenses and covered own initial costs ● A fast and fun way to perfect my workplace English skills

  • Student Internship at Panasonic Appliances Air-Conditioning R&D Malaysia Sdn Bhd (PAPARADMY)
    Jun 2013 - Aug 2013 · 3 mos