Our client, a leading banking company, is currently seeking to hire a IT Security Engineer.
Responsibilities:
- To support the team to conduct regular security assessment, e.g. regular security scanning, handling SPAM/Phishing incident, etc.
- To support and follow up the Threats & Vulnerability Management process.
- To support the new security related project team's administration and documents tasks, such as IAM, Cloud Adoption, STDB, etc.
- To support implementing the iCAST remediation and new CNCB and Regulatory Requirement.
- To support the new security tasks for new projects initiatives, such as SIP & XDR antivirus management, Firewall Management Utility, etc.
- To support the enhancement on security tools, such as security scanning automations, PAMS script integrations, SIEM correlation rules, etc.
- As SME on Cybersecurity services to collaborate with application team for project scoping and delivery.
A ). Knowledge, Skill & Attributes
- 2-3 year hands-on experiences on IT security tools and applications or software development.
- Knowledge of the DevSecOps or similar agile development.
- Experiences on HK FSI, banking industry is preferred.
- Basic communications with English and Mandarin.
- Following security best practices in performing tasks.
B). Academic and Professional Qualification
- Degree holder (or above) which is related to Information Technology.
- Fulfill HKMA ECF is preferable Training and Relevant Experiences.
C). Training and Relevant Experiences
- 1-2 years experiences on HK FSI, banking industry is preferred.
- Basic knowledge on software programming and networking.
- Sound knowledge on Software Development Life Cycle.
D). Experiences on Application/Development Security is an advantage, i.e.
- Developing and maintaining software application security policies and procedures
- Developing and maintaining documentation of application security controls
- Implementing software application security controls
- Designing technical solutions to address security weaknesses
- Analyzing system services, spotting issues in code, networks and applications