Security Engineer / Security Team Lead - Assistant Vice President - Security Services - IT - 12months contract
HK-TKO G/F, Hong Kong
⚠️ We'll shut down after Aug 1st - try foo🦍 for all jobs in tech ⚠️
HKEX
HKEX Group's official website, covering investor relations, careers, corporate governance, market insights and our work in the community.Company Introduction:
We’re home to Asia's most dynamic and vibrant capital markets.
Connecting capital, ideas, inspiration and innovation for deeper, more diverse and liquid global capital markets; providing greater choice and opportunity for our customers, each and every day.
HKEX is a purpose-driven company. Our commitment to the long-term development of our business and our markets is articulated in our purpose: "To Connect, Promote and Progress our Markets and the Communities they support for the prosperity of all."
Job Summary:
The Information Security Engineer is responsible for designing, building and maintaining enterprise IT security solutions to address the organization’s security requirements. Reporting to the Information Security Services Lead, this role will work closely with IT Innovation Lab, software engineering teams, IT infrastructure team, IT compliance, security operations and cyber technology risk team.Job Duties:
Responsibilities
Engineer, implement and monitor security measures for the protection of computer systems, networks and information
Identify and define system security requirements
Design computer security architecture and develop detailed cyber security designs
Configure and troubleshoot security systems and infrastructure devices
Develop technical solutions and new security tools to help mitigate security vulnerabilities and automate repeatable tasks
Maintain all solution design documentation, processes, procedures and report on metrics to demonstrate effective and efficient management of services.
Work with handling service requests on security tool standard changes, such as proxy whitelisting requests
Delivery security service on-boarding such as security agent install, connecting systems to SIEM
Review IT systems to ensure that they have met security acceptance criteria.
Work with product vendors and suppliers to maintain and enhance existing security tooling and products
Ensure that the organization security tools can detect and help with the response to cyber security incidents.
Document and validate disaster recovery testing for CyberSecurity tools.
Write comprehensive reports including assessment-based findings, outcomes and propositions for further system security enhancements
Support in managing the Total Cost of Ownership (TCO) for security solutions which includes new investments and business-as-usual financials.
Design and execute processes to make BAU changes to security tools (eg web proxy changes, DLP mail rule changes, etc)
Automate or script changes and validation processes
Requirements:
Proven work experience as a System Security Engineer or Information Security Engineer
Experience in building, maintaining and operating security systems and platforms
Hands on experience in a number of security systems, including firewalls, intrusion detection systems, anti-virus software, authentication systems, log management, content filtering, data loss prevention systems, web proxies, etc
Experience with network security and networking technologies and with system, security, and network monitoring tools
Thorough understanding of the latest security principles, techniques, and protocols (such as zero trust, etc)
Problem solving skills and ability to work under pressure
Must have strong information security technology knowledge/concepts and can effectively communicate with senior management and a broad range of technical/non-technical audiences. Strong written communication skills and verbal presentations to senior management.
Must have a relevant University degree in Computer Science, Information Management, or related field, or equivalent experience.
Good presentation, project planning and documentation skills
Familiarity with web related technologies (Web applications, Web Services, Service Oriented Architectures) and of network/web related protocols
Familiarity with application, database and operating system security
Familiarity with cloud security technologies (AWS or Azure is preferred)
Familiarity with risk / control frameworks, such as Mitre ATT&CK, D3FEND, OWASP, NIST Cybersecurity Framework
Familiarity in scripting or automation is an added advantage
Familiarity with Identity and Lifecycle management is an advantage
Previous experience in regulated environments is an added advantage
HKEX is committed as an Equal Opportunity Employer. Diversity is one of our core values and we look to support, respect diverse perspectives, abilities, culture and experiences within our workplace.
Location:
HKEX - TKOShift:
Standard - 40 Hours (Hong Kong SAR)Scheduled Weekly Hours:
40Worker Type:
Contract* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Automation AWS Azure Cloud Compliance Computer Science Firewalls Intrusion detection IT infrastructure MITRE ATT&CK Monitoring Network security NIST OWASP Scripting Security Assessment Report SIEM Vulnerabilities Zero Trust
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.