Key Responsibilities:
1. Security Operations & Threat Management
Monitor & Support: Oversee daily operation of security tools (EDR, NDR, WAF, SIEM, PAM, MDM, Patching, etc.) and provide first-line incident response.
Vulnerability & Risk: Conduct risk/vulnerability assessments, manage the risk register, and ensure timely remediation of technical threats.
Emergency Preparedness: Lead disaster recovery (DR) and incident response drills; provide off-hours emergency support when required.
2. Infrastructure & System Hardening
Network & Server Security: Configure and harden firewalls, network appliances, servers, and applications against baseline standards.
Life-Cycle Support: Ensure security controls are integrated throughout system procurement, development, testing (UAT), and ongoing operations.
3. Compliance, Audit & Policy
Government Standards: Review and align internal IT security policies with government circulars and baselines (e.g., S17, G3).
Audits & Assessments: Manage Security Risk Assessment & Audit (SRAA) exercises, Privacy Impact Assessments (PIA), and external compliance checks.
4. Governance & Advisory
Steering Support: Serve as a security administrator for committee meetings (e.g., ISSC) and present status updates.
Technical Guidance: Provide expert advice on cloud security (GCIS/DCI, containers) and evolving business requirements.
5. Documentation & Administration
Asset & Lifecycle Management: Track software end-of-support dates, plan migrations, and coordinate updates to network diagrams, capacity plans, and hardware/software inventories.
Training & Procurement: Conduct internal security awareness training, assist with security tool procurement, and handle other supervisor-assigned duties.
Requirements:
Degree in computer subjects or related disciplines
At least 6 years working experience in IT industry with more than 3 years of hands-on experience working in the technology risk team, security operation team or security management unit of a sizeable organisation
At least 1 of the industry-recognised IT security certifications (e.g. CISA, CISSP, CISP, etc.)
Hands-on experience in technical support for IT security infrastructure, network equipment and security assessment tools (e.g., Cisco, H3C, Palo-Alto, Huawei, Nessus, OWASP Zap, etc.)
Hands-on experience in IT security design, implementation and operations in application system development projects
Experience in the technology and security risks of cloud-native applications running in a virtualised and/or containerized environment
Experience in review and update IT security related documents
Good command in spoken and written English and Chinese
職位詳情
- 工作經驗
- 6年
- 學歷
- 學士
- 行業
- 資訊科技
- 職能
- 資訊科技 > 保安 / 審計, 資訊科技 > 其他
- 地區
- 香港境內
- 福利
- 5-day week, Medical plan, Paid overtime
- 發佈日期
- 2026年8月3日
