What Jobs are available for Security Architect in Hong Kong?
Showing 51 Security Architect jobs in Hong Kong
Security Architect
Posted today
Job Viewed
Job Description
About us
eCloudvalley is a leading cloud services provider, recognized as the first AWS Premier Consulting Partner in Greater China Region. Since 2013, they've been helping businesses accelerate digital transformation with comprehensive cloud solutions, including consultation, migration, and managed services. Headquartered in Taiwan, eCloudvalley has a global presence, offering services in cloud infrastructure, information security, IoT, AI, and big data analytics.
【Key Highlights】
- Build and lead cloud security initiatives
- Collaborate with industry-leading cloud platforms
- Create impact in a fast-growing team
【Benefits】
- Five-day work week
- Performance-based bonuses
- Comprehensive medical and dental coverage
- Annual leave, Birthday leave, marriage leave
- L&D program and on-the-job training opportunities
- Various team-building activities and company events
【Job Duties】
- Provide technical expertise and consultation to sales teams and clients
- Understand client requirements and design tailored cybersecurity solutions
- Analyze client requirements to design bespoke cybersecurity solutions
- Conduct product demos, presentations, and proof-of-concept engagements
- Develop comprehensive cybersecurity architectures that align with client needs
- Create detailed solution proposals with technical specifications and implementation plans.
- Familiar with Managed Security Service and ZTA solution. (e.g.: Managed SOC / Managed EDR / Zscaler)
- Foster strong partnerships with clients and industry partners
- Advise on best practices and stay ahead of cybersecurity trends to provide insights and recommendations
- Collaborate with sales to identify and qualify new opportunities
- Partner with account executives, engineering, and support teams to ensure seamless solution delivery
- Provide feedback to refine our products and better address client needs
- Keep up-to date with the latest cybersecurity technologies, threats, and industry developments
- Participate in industry events, conferences, and training sessions to network and learn
【Requirements】
- 2-3+ years of hands-on experience in pre-sales, solutions architecture, or a similar role in the cybersecurity domain
- Proven track record of successfully designing and implementing cybersecurity solutions
- Strong understanding of cybersecurity principles, technologies, and best practices
- Proficiency in network security, endpoint security, cloud security, and threat intelligence
- Experience with security frameworks and compliance standards (e.g., NIST, ISO 27001)
- Strong communication skills, ability to explain complex technical concepts to non-technical stakeholders
- Strong problem-solving and analytical skills, ability to assess client environments, and ability to identify security gaps and risks.
- Strong interpersonal and relationship-building skills, ability to work collaboratively in a team-oriented environment.
- Fluency in written and spokenCantonese, Mandarin & English is required
【Preferred Requirements】
- Willing to business travel to meet clients and attend industry events
- Self-motivated, proactive, and able to manage multiple priorities
- Professional qualification holder will be an advantage:
(i) Security Analyst / Incident Handling-related certification (e.g.: EC-Council Incident Handler, EC-Council SOC Analyst)
(ii) Zscaler-related certification (e.g.: Zscaler Certified Delivery Specialist)
【How to Apply】
Interested parties, please click Apply now or send your resume with an expected salary and available date to Katie Ma by e-mail:
Apply now and start your journey with us :)
Is this job a match or a miss?
Senior Security Architect
Posted today
Job Viewed
Job Description
Role Introduction
Reports to: Infra & Security Architect Manager
Department: Information Technology Department
This role is part of our Information Technology Department (IMT). As a Senior Security Architect, you are responsible for providing technical leadership to define the IT Security strategy and standard across different platforms and services as well as todesign and build fit-for-purpose, cost-effective and robust Infrastructure Technology Solutions to support the delivery of business and IT programmes to meet business and non-functional requirements.
Key Responsibilities
- Define IT security standards, controls, architecture vision, principles, and target state blueprints
- Establish and promote infrastructure standards, procedures, and best practices within the team
- Collaborate with Enterprise Security Architects to align IT security standards and baselines
- Conduct Non-Functional Requirements (NFR) reviews for security design and project requirements
- Advocate and secure support for infrastructure architecture strategy and roadmap from key stakeholders
- Monitor compliance with corporate control standards for quality and security
- Lead analysis of current IT environment to identify deficiencies and recommend improvements
- Participate in solution design reviews, architecture governance forums, and industry technology forums
- Provide technical leadership and escalation support during testing, implementation, and transition phases
- Collaborate with Information Management domains, keep technical competencies updated, and support business and technology innovation
Requirements
- Bachelor's degree in Computer Science, Information Systems, or a related field
- At least 10 years of IT experience with a minimum of 8 years in IT security strategy and architecture design; CISSP certification is preferred
- Demonstrated technical management and specialist expertise in complex IT infrastructures
- Professional competency in at least three technical specializations and broad knowledge of emerging technologies
- Proven ability to develop solutions and make decisions independently with minimal supervision
- Experience building and maintaining senior-level relationships and influencing across all levels
- Understanding of leveraging technology to reduce costs and drive business innovation in dynamic industries
- Strong communication skills, including the ability to present and articulate ideas to diverse audiences
- Excellent analytical, problem-solving, decision-making, and troubleshooting abilities
- Customer-focused mindset with the ability to drive change and align tactical work with strategic goals
Application Deadline: 10-Nov-2025
Personal & Application Information
Cathay Pacific is an Equal Opportunities Employer. Personal data provided by job applicants will be used strictly in accordance with our Applicant Personal Information Collection Statement and for recruitment purposes only. Candidates not notified within eight weeks may consider their application unsuccessful. We keep records of your data for no longer than is necessary for the purpose for which we obtained them and any other permitted linked purposes. If your application is unsuccessful, we will keep your details on file for as long as is necessary to process your application or for the purposes of further job opportunities if you agree to such longer periods.
Is this job a match or a miss?
Senior Security Architect
Posted today
Job Viewed
Job Description
Cathay Pacific
Digital & Information Technology
Information Technology Department
Permanent
Hong Kong SAR (China)
Application deadline: 10 Nov 2025
Role IntroductionReports to: Infra & Security Architect Manager
This role is part of our Information Technology Department (IMT). As a Senior Security Architect, you are responsible for providing technical leadership to define the IT Security strategy and standard across different platforms and services as well as todesign and build fit-for-purpose, cost-effective and robust Infrastructure Technology Solutions to support the delivery of business and IT programmes to meet business and non-functional requirements.
Key Responsibilities- Define IT security standards, controls, architecture vision, principles, and target state blueprints
- Establish and promote infrastructure standards, procedures, and best practices within the team
- Collaborate with Enterprise Security Architects to align IT security standards and baselines
- Conduct Non-Functional Requirements (NFR) reviews for security design and project requirements
- Advocate and secure support for infrastructure architecture strategy and roadmap from key stakeholders
- Monitor compliance with corporate control standards for quality and security
- Lead analysis of current IT environment to identify deficiencies and recommend improvements
- Participate in solution design reviews, architecture governance forums, and industry technology forums
- Provide technical leadership and escalation support during testing, implementation, and transition phases
- Collaborate with Information Management domains, keep technical competencies updated, and support business and technology innovation
- Bachelor's degree in Computer Science, Information Systems, or a related field
- At least 10 years of IT experience with a minimum of 8 years in IT security strategy and architecture design; CISSP certification is preferred
- Demonstrated technical management and specialist expertise in complex IT infrastructures
- Professional competency in at least three technical specializations and broad knowledge of emerging technologies
- Proven ability to develop solutions and make decisions independently with minimal supervision
- Experience building and maintaining senior-level relationships and influencing across all levels
- Understanding of leveraging technology to reduce costs and drive business innovation in dynamic industries
- Strong communication skills, including the ability to present and articulate ideas to diverse audiences
- Excellent analytical, problem-solving, decision-making, and troubleshooting abilities
- Customer-focused mindset with the ability to drive change and align tactical work with strategic goals
Cathay Pacific is an Equal Opportunities Employer. Personal data provided by job applicants will be used strictly in accordance with our Applicant Personal Information Collection Statement and for recruitment purposes only. Candidates not notified within eight weeks may consider their application unsuccessful. We keep records of your data for no longer than is necessary for the purpose for which we obtained them and any other permitted linked purposes. If your application is unsuccessful, we will keep your details on file for as long as is necessary to process your application or for the purposes of further job opportunities if you agree to such longer periods.
Is this job a match or a miss?
Manager (Security Architect)
Posted today
Job Viewed
Job Description
Established in the 1970s, Sino Group is a leading property developer in Hong Kong, comprising private companies owned by the Ng Family as well as three listed companies. Our core business encompasses the development of residential properties, offices, industrial and retail properties for sale and investment in China (Hong Kong and Mainland), Singapore and Australia.
We are committed to Creating Better Lifescapes by promoting sustainable, green living in harmony with the environment, creating inspiring spaces through innovative design, while nurturing a sense of community in everything we do. Adhering to our core values of integrity, customer first, quality excellence, respect, teamwork, continuous improvement, preparedness, and sense of urgency, we work together closely to make Sino the preferred choice for customers, investors and employees.
To find out more about our commitment to Creating Better Lifescapes, please visit
The successful candidate will report to the Lead of Governance and Security in Information Technology Department. He/ She will deliver technical guidance in the areas of cyber security architecture, secure system development, drive the adoption of security architecture and secure development lifecycle practices across the Group. He/ She will lead all security architecture reviews or technical risk assessments, identify the right technology, design technical defined security architecture and ensure secure implementation. Moreover, he/ she will work with the project teams to design and document the secure architecture for the non-functional requirements of an end-to-end system encompassing security, reliability, sustainability, availability and performance.
He/ She will also organize vulnerability assessments, penetration testing and vulnerability scans for both cloud and on-premises systems and work with risk owners on the resolution of the identified risks to make sure all IT assets are properly configured with industrial security standards and patched regularly. He/ She will assist in the development and promotion of information security awareness program to raise the awareness of security risks, manage the outsourced Security Operation Centre (SOC), review and evaluate security events, trigger and manage security incident response when necessary and compile related risks and status reports for management review.
Additionally, He/ She will support the design and implementation of cutting-edge security technologies, such as Zero Trust (SASE) and Data Loss Prevention (DLP) initiatives and develop and coordinate an incident response plan for security breaches, including forensic analysis and remediation efforts.
Requirements:
Degree holder in Computer Science, Information Engineering, Information Security or related disciplines
Minimum 8 years of relevant work experience, in which at least 5 years of hands - on experience in Information Security, Internal Control or Operation Risk
In-depth knowledge of IT security best practices, security technologies, secure application architectures and emerging security trends.
Experience in penetration testing, common vulnerability assessment tools, MITRE ATT&CK or similar frameworks
Qualification in CISA / CISM / CISSP / CCSP or any industrial-recognized IT security certificate is an advantage
Good Knowledge on Security-related frameworks, such as ISO 27001, NIST CSF, CIS Controls, COBIT, PCI DSS, OWASP Top 10 as well as ITIL framework is an advantage
Hands - on experience in following security domains:
Privilege account management (PAM)
Identity and Access management (IAM)
Risk Management
Vulnerability and Patch Management
Incident Response Management
User Awareness Training and Phishing Simulation
Experience in Cloud Security and the latest Cloud Technologies such as SAP S/4 HANA, Azure, AWS, Office 365, Azure AD (Entra ID) is an advantage
Demonstrated ability to communicate information security and risk management concepts to both technical and business audiences.
Strong analytical and problem-solving skills
Able to work under pressure, proactive to initiate new projects for continuous improvement
Excellent command of both spoken and written English and Chinese
We are an equal opportunity employer who offer an inclusive and diverse workplace where people are valued and respected.
Before submitting your application, please read the Personal Data (Privacy) Policy and Personal Information Collection Statement at our Company website. Information provided will be treated in strict confidence and used for recruitment purposes only. If we have not contacted you within 4 weeks after your submission, you may consider your application unsuccessful.
Full-time
Is this job a match or a miss?
Information Security Architect
Posted today
Job Viewed
Job Description
Join us. Let's care for tomorrow.
At Allianz Global Investors we foster a culture of professionalism, fulfilment, and an inclusive working environment. Do you want to be part of a leading active asset management company? Then join us now as Information Security Architect in Hong Kong within the Information Security team.
What You Will Do
- Support of the continuous development and improvement of our global information security programme (including frameworks, processes, and tool sets) with a focus on security architecture and governance
- Conduct Security Architecture reviews based on industry-best practise, including threat modelling of systems and applications in scope as a vehicle to identify and communicate security risks
- Prepare and moderate regional security governance forums and status meetings, having modern and future-proof collaboration models in mind
- Act as a regional security point of conduct for auditors and business partners
- Driving our global security training and phishing exercises and conducting regional security awareness measures as part of our communication concept
- Work closely with a distributed team of Information Security, IAM and Cybersecurity professionals across Asia and Europe
What You Bring
- Deep expertise and proven experience in Information Security Management, including frameworks, regulations and security architecture
- 3-7 years of professional experience in information security/cybersecurity with specific industry qualifications (e.g., CISSP, CISM, CISA)
- Hands-on experience in developing solutions, such as relevant guidelines and operating procedures on the basis of best-practices, business needs and regulatory requirements as well es respective methodologies for control testing
- Experience in the identification of security risks as well as threat modelling based on internationally recognized frameworks, including the advisory on possible mitigating and controlling measures and architectures.
- Proven track record in working with diverse and distributed global teams, as well as excellent communication and interpersonal skills (communicating and reporting sophisticated technical concepts to business and risk partners)
- Experience interacting directly with senior stakeholders (C-Suite, Board and Regulators)
- Experience balancing multiple concurrent projects and priorities communicating and committing to realistic deadlines, showcasing a structured way of working
- Proficiency in English is a must, additional proficiency in Mandarin preferred and additional language skills are a plus
What We Offer
- Balanced work environment: A dynamic office culture that supports flexibility and collaboration
- Securing your future: Access to pension, retirement, and/or savings plans as applicable to the work location
- Shared success: Company share purchasing plan
- Support for what matters: Mental health and wellbeing programs
- Investments in your career: Career opportunities within the entire Allianz Group
- Investments in your skills: Comprehensive learning and development offerings, including certifications and professional qualifications
- … and so much more
About Allianz Global Investors
Allianz Global Investors is a leading global active asset manager.
We invest for the long term and want to create value for clients every step of the way. We do this by being active – in how we partner with clients and anticipate their needs, and build solutions based on capabilities across public and private markets. Our focus on enhancing our clients' assets leads naturally to a commitment to sustainability for positive change. Our goal is to enhance the investment experience for clients, whatever their location or goals.
Putting our clients' needs first, behaving in a transparent way and treating people fairly means acting with integrity. We encourage a collegial culture, that supports individual responsibility. We invest in the development of our employees to maximize the power of innovation.
We at Allianz believe in a diverse and inclusive workforce, we are committed to the principles of Equal Employment Opportunity and to helping applicants with any disabilities. We encourage you to bring your whole self to work, no matter where you are from, what you look like, who you love or what you believe in. We therefore welcome applications regardless of ethnicity or cultural background, age, gender, nationality, religion, disability or sexual orientation. Great to have you on board.
If you feel inspired to promote the active asset management experience, this is the place for you. Join our diverse, international, technology-enabled, and agile environment. Simply upload your CV in English to apply for this position If you need support to navigate our websites or at any stage during your application, please send an email with your request to
To Recruitment Agencies
Allianz Global Investors has an in-house recruitment team that sources great candidates directly. Therefore, Allianz Global Investors does not accept unsolicited resumes from agency or search firm recruiters.
When we do work with recruitment agencies, that engagement is formalized by a contract. Fees will only be paid when there is a contract in place.
Without a contract in place, we will not accept invoices on unsolicited resumes, even if the candidate was ultimately employed by Allianz Global Investors.
Finally, please do not contact hiring managers directly.
81675 | IT & Tech Engineering | Professional | n.a. | Allianz Global Investors | Full-Time | Permanent
Is this job a match or a miss?
Manager (Security Architect) (Ref: M-SA/JDB)
Posted today
Job Viewed
Job Description
At Sino Group, we bring people together for a better future. We value your uniqueness, commit to your career development and prioritize your wellness. We provide an inclusive and collaborative workplace, all-round training and work-life balance to unleash your full potential and empower you to grow together with the Group, both personally and professionally.
We are looking for talented people to be part of our dynamic team
Responsibilities:
The successful candidate will report to the Lead of Governance and Security in Information Technology Department. He/ She will deliver technical guidance in the areas of cyber security architecture, secure system development, drive the adoption of security architecture and secure development lifecycle practices across the Group. He/ She will lead all security architecture reviews or technical risk assessments, identify the right technology, design technical defined security architecture and ensure secure implementation. Moreover, he/ she will work with the project teams to design and document the secure architecture for the non-functional requirements of an end-to-end system encompassing security, reliability, sustainability, availability and performance.
He/ She will also organize vulnerability assessments, penetration testing and vulnerability scans for both cloud and on-premises systems and work with risk owners on the resolution of the identified risks to make sure all IT assets are properly configured with industrial security standards and patched regularly. He/ She will assist in the development and promotion of information security awareness program to raise the awareness of security risks, manage the outsourced Security Operation Centre (SOC), review and evaluate security events, trigger and manage security incident response when necessary and compile related risks and status reports for management review.
Additionally, He/ She will support the design and implementation of cutting-edge security technologies, such as Zero Trust (SASE) and Data Loss Prevention (DLP) initiatives and develop and coordinate an incident response plan for security breaches, including forensic analysis and remediation efforts.
Requirements:
- Degree holder in Computer Science, Information Engineering, Information Security or related disciplines
- Minimum 8 years of relevant work experience, in which at least 5 years of hands - on experience in Information Security, Internal Control or Operation Risk
- In-depth knowledge of IT security best practices, security technologies, secure application architectures and emerging security trends.
- Experience in penetration testing, common vulnerability assessment tools, MITRE ATT&CK or similar frameworks
- Qualification in CISA / CISM / CISSP / CCSP or any industrial-recognized IT security certificate is an advantage
- Good Knowledge on Security-related frameworks, such as ISO 27001, NIST CSF, CIS Controls, COBIT, PCI DSS, OWASP Top 10 as well as ITIL framework is an advantage
Hands - on experience in following security domains: -
Privilege account management (PAM)
- Identity and Access management (IAM)
- Risk Management
- Vulnerability and Patch Management
- Incident Response Management
- User Awareness Training and Phishing Simulation
- Experience in Cloud Security and the latest Cloud Technologies such as SAP S/4 HANA, Azure, AWS, Office 365, Azure AD (Entra ID) is an advantage
- Demonstrated ability to communicate information security and risk management concepts to both technical and business audiences.
- Strong analytical and problem-solving skills
- Able to work under pressure, proactive to initiate new projects for continuous improvement
- Excellent command of both spoken and written English and Chinese
Benefits
- Dental insurance
- Five-day work week
- Medical insurance
- Education allowance
- Performance bonus
We are an equal opportunity employer who offer an inclusive and diverse workplace where people are valued and respected.
Before submitting your application, please read the Personal Data (Privacy) Policy and Personal Information Collection Statement at our Company website. Information provided will be treated in strict confidence and used for recruitment purposes only. If we have not contacted you within 4 weeks after your submission, you may consider your application unsuccessful.
Is this job a match or a miss?
Application Security Solution Architect
Posted today
Job Viewed
Job Description
We are seeking a skilled Application Security Architect to join our team and lead efforts to design and implement secure software solutions. This role involves collaborating with development teams to ensure that security is integrated into the software development lifecycle. The ideal candidate will have a deep understanding of application security principles and a strong background in software development and security architecture.
Key Responsibilities:
- Design and implement security architecture solutions to protect applications and data across the organization.
- Collaborate with development teams to integrate security best practices into the software development lifecycle.
- Conduct security assessments and code reviews to identify vulnerabilities in applications and provide guidance for remediation.
- Develop and maintain security policies, standards, and guidelines for application security.
- Evaluate and recommend security tools and technologies to enhance application security posture.
- Stay current with emerging security threats and vulnerabilities, and proactively address them within the organization.
- Provide training and mentorship to development teams on secure coding practices and application security awareness.
- Participate in incident response activities, providing expertise in application security to help resolve security incidents.
- Work with cross-functional teams to ensure security requirements are met for new and existing applications.
- Develop and maintain documentation related to application security architecture and practices.
Requirements:
- Bachelor's degree in Computer Science, Information Security, or a related field.
- 7+ years of experience in application security or software development with a focus on security.
- Strong understanding of application security principles, vulnerabilities, and mitigation techniques (e.g., OWASP Top Ten).
- Experience with secure coding practices and security testing methodologies.
- Proficiency in programming languages such as Java, C#, Python, or JavaScript.
- Familiarity with application security tools and technologies (e.g., static and dynamic analysis tools, web application firewalls).
- Strong analytical and problem-solving skills.
- Excellent communication and interpersonal skills, with the ability to work effectively with development teams and other stakeholders.
- Relevant certifications such as CISSP, CSSLP, or CEH are a plus.
If this outstanding opportunity sounds like your next career move, please submit your resume in Word format via the Quick Apply Button.
Is this job a match or a miss?
Be The First To Know
About the latest Security architect Jobs in Hong Kong !
Application Security Solution Architect
Posted today
Job Viewed
Job Description
We are seeking a skilled
Application Security Architect
to join our team and lead efforts to design and implement secure software solutions. This role involves collaborating with development teams to ensure that security is integrated into the software development lifecycle. The ideal candidate will have a deep understanding of application security principles and a strong background in software development and security architecture.
Key Responsibilities:
- Design and implement security architecture solutions to protect applications and data across the organization.
- Collaborate with development teams to integrate security best practices into the software development lifecycle.
- Conduct security assessments and code reviews to identify vulnerabilities in applications and provide guidance for remediation.
- Develop and maintain security policies, standards, and guidelines for application security.
- Evaluate and recommend security tools and technologies to enhance application security posture.
- Stay current with emerging security threats and vulnerabilities, and proactively address them within the organization.
- Provide training and mentorship to development teams on secure coding practices and application security awareness.
- Participate in incident response activities, providing expertise in application security to help resolve security incidents.
- Work with cross-functional teams to ensure security requirements are met for new and existing applications.
- Develop and maintain documentation related to application security architecture and practices.
Requirements:
- Bachelor's degree in Computer Science, Information Security, or a related field.
- 7+ years of experience in application security or software development with a focus on security.
- Strong understanding of application security principles, vulnerabilities, and mitigation techniques (e.g., OWASP Top Ten).
- Experience with secure coding practices and security testing methodologies.
- Proficiency in programming languages such as Java, C#, Python, or JavaScript.
- Familiarity with application security tools and technologies (e.g., static and dynamic analysis tools, web application firewalls).
- Strong analytical and problem-solving skills.
- Excellent communication and interpersonal skills, with the ability to work effectively with development teams and other stakeholders.
- Relevant certifications such as CISSP, CSSLP, or CEH are a plus.
Is this job a match or a miss?
Application Security Solution Architect
Posted today
Job Viewed
Job Description
Company Introduction:
*We're home to Asia's most dynamic and vibrant capital markets.
Connecting capital, ideas, inspiration and innovation for deeper, more diverse and liquid global capital markets; providing greater choice and opportunity for our customers, each and every day.
HKEX is a purpose-driven company. Our commitment to the long-term development of our business and our markets is articulated in our purpose: "To Connect, Promote and Progress our Markets and the Communities they support for the prosperity of all."
Job Summary: *
The Application Security Solution Architect (ASSA) for HKEX Group is accountable for translating group-wide information and cyber security strategy, policy and control requirements into secure application solutions. They will focus on application-level security architecture, design, processes and controls.
The role is tasked with balancing the unique business objectives of a global exchange against the inherent security threat and risk profile applicable to critical national infrastructure.
Job Duties:
Job Responsibilities
- Architectural Oversight: Ensure that the information and cybersecurity architecture and solution designs for applications are engineered according to specifications and within acceptable risk tolerance levels, focusing on application-specific contexts.
- Support Development Teams: Collaborate with development teams to implement application-specific threat modeling, secure coding practices, and the effective use of application security assurance tools to enhance the security of software products.
- Integration Architecture Recommendations: Provide expert recommendations on application-level integration architecture, focusing on secure coding practices, web application firewalls, software composition analysis, static and dynamic code scanning, Software Bill of Materials (SBOM), and security measures within CI/CD pipelines, all crucial for securing application deployments.
- Application Security Assurance Tool Experience: Leverage experience with application security assurance tools, including onboarding, triaging issues, and assisting developers, to ensure that applications are built and maintained with robust security measures.
- Collaboration with Security Engineering: Work closely with the Security Engineering team to integrate security solutions into application development processes, ensuring that security is a fundamental aspect of the application lifecycle.
- Requirement Creation and Review: Develop and review functional and non-functional security requirements specifically tailored for application projects, ensuring these requirements enhance the security posture of applications.
- System Architecture Review: Conduct thorough reviews of application architecture and designs to ensure that all solutions have undergone appropriate security assurance and meet established security acceptance criteria, thereby protecting applications from vulnerabilities.
- Security Reference Patterns Development: Create and present application security reference patterns and technical security standards that guide secure application development, ensuring compliance with the Information Security Policy.
- Data Security: Create or review implementation of data layer protective and detective control patterns for data storage technologies, from high level SAAS applications to specific technologies, such as Databases, Kafka queues, object storage systems.
- Kubernetes / Cloud Security Expertise: Apply knowledge of Kubernetes / Cloud security technologies to enhance the security of applications deployed in containerized environments, addressing specific risks associated with cloud-native applications.
- Application Architecture Understanding: Demonstrate a comprehensive understanding of application architecture to apply relevant security controls and systems, minimizing cybersecurity risks specific to the application's design and functionality.
- Collaborative Project Delivery: Work collaboratively with project delivery and operational teams to ensure that applications are delivered on time and meet high-quality security standards throughout the system delivery lifecycle.
- Governance Participation: Actively participate in governance forums, such as the Architecture Community and Working Group, to contribute to the development of application security strategies and best practices
Job Requirement:
Academic and Professional Qualifications Required:
- Should have a relevant University degree in Computer Science, Information Management, or related field, or equivalent experience.
- Should have relevant experience with information security and enterprise architecture methods and frameworks (e.g., SABSA, TOGAF, NIST CSF)
- Cyber Security certifications, such as SABSA, CCSP (Certified Cloud Security Professional), CISSP (Certified Information Systems Security Professional) or security specific cloud certifications such as AWS, Azure, GCP, AliBaba Cloud, Kubernetes, etc would be looked upon favourably
Required Knowledge and Level of Experience:
- Must have significant and wide experience in the information and cyber security industry.
- Must have subject matter expertise in application threat modelling, secure coding practices in either Java or C++ (or other languages such as .Net, , go); and DevSecOps practices.
- Must have current experience of automated build and deployment pipelines and how to both secure a pipeline and assure the security of artefacts in a pipeline.
- Should have current experience of software and system assurance methodologies and associated vulnerability management and risk management practices.
- Should have current experience of operating one or more of SAST, SCA, DAST, IAST and SBOM.
- Should be able to perform automation scripting leveraging python and API's
- Should have relevant experience with industry best-practice approaches to the design, implementation, operation and management of IT systems (e.g., Agile, Waterfall, ITIL, COBIT).
- Should have recent experience of delivering solutions security in public and/or private cloud.
Optional Knowledge and Experience:
- Should have experience security Kubernetes technology and familiar with secrets management, PKI, service mesh, Istio, etc.
- Should have experience of developing/ contributing to security policies and standards.
- Should have current experience securing automated build and deployment pipelines and securing artefacts
- Should have familiarity with internal audit, risk and control management
- Relevant information security experience working with or for a global exchange, or similar regulated financial market infrastructure or critical national infrastructure would be looked upon favourably.
Skills set and Core Competencies Required for Role:
- An intelligent, articulate, consensus building and persuasive self-starter.
- Must have a strong business acumen and technology knowledge.
- Must be able to communicate information security-related concepts to a broad range of audiences.
- Experience of effective stakeholder management and collaborative mindset.
- Able to deliver within a fast-moving high-pressure environment, balancing multiple work streams and deliverables.
Personal Qualities:
- Open and approachable, with ability to work well within a team.
- Effective oral and written communicator
HKEX is committed as an Equal Opportunity Employer. Diversity is one of our core values and we look to support, respect diverse perspectives, abilities, culture and experiences within our workplace.
Location:
HKEX - TKO
Shift:
N/A
Scheduled Weekly Hours:
40
Worker Type:
Permanent
Is this job a match or a miss?
Manager - Network Security Solutions
Posted today
Job Viewed
Job Description
Are you passionate about network security and seeking a challenging role in a leading telecommunications company? This exciting opportunity offers the chance to drive network security solutions for a diverse range of clients, leveraging your expertise in a dynamic and growth-oriented environment.
About Our ClientHGC Global Communications Limited is a prominent Hong Kong-based international fixed-line operator, renowned for its comprehensive telecom and digital infrastructure solutions. With a global network spanning hundreds of international telecom operators and cloud service providers, HGC is at the forefront of innovation in ICT solutions, broadband services, and Wi-Fi provision. Backed by a team of over 700 technology and cybersecurity professionals, HGC delivers cutting-edge digital solutions to a diverse clientele, from residential customers to large corporations.
What you'll be doing?- Lead customer engagement: Spearhead activities related to network infrastructure, focusing on network security and enterprise networking solutions.
- Analyze and design: Gather customer requirements, identify pain points, and propose high-level designs to address client needs effectively.
- Showcase expertise: Conduct demonstrations and proof of concept tests to illustrate the value of proposed solutions.
- Drive technical discussions: Lead presentations and prepare proposals for prospective customers, showcasing your in-depth knowledge.
- Collaborate across teams: Work closely with Sales and Product teams to develop innovative solutions that meet market demands.
- Build client relationships: Cultivate strong connections with clients, understanding their unique needs and proposing tailored solutions.
- Innovate with automation: Develop customer-oriented automation and software-driven use cases to support strategic decision-making processes.
- Hands-on implementation: Occasionally manage project implementation services, ensuring smooth execution of solutions.
- Educational background: Degree holder in Computer Science or IT-related field, demonstrating a strong foundation in technology.
- Extensive experience: 8 years of experience in the IT networking field, showcasing a depth of knowledge and expertise. Candidates with less experience may be considered for a Solution Architect position.
- Industry certifications: Networking security vendor certifications or equivalent are preferred, highlighting your specialized skills.
- Practical know-how: Hands-on experience with Network Security solutions and strong problem-solving capabilities are essential.
- Self-motivated professional: Ability to work under pressure and drive projects forward independently.
- Excellent communicator: Strong interpersonal communication skills, team player mentality, and presentation abilities are crucial for success in this role.
- Language proficiency: Fluency in English and Cantonese to effectively communicate with diverse stakeholders and clients.
Our client offers an attractive remuneration package and other benefits, such as:
- Comprehensive health insurance coverage
- Performance-based bonus opportunities
- Special leave for personal milestones (birthday and marriage)
- Investment in your growth through training sponsorship
- Annual body check to ensure your well-being
- Generous annual leave allowance of at least 16 days
Ready to join this role? Click Apply now to submit your resume and share your availability and expected salary with us
We welcome applications from individuals of all backgrounds and experiences who are passionate about network security and eager to contribute to a leading telecommunications company.
All information received will be kept strictly confidential and will be used only for employment-related purposes.
Refer A Candidate and Earn $2,000)
SmartReward #SmartHireIs this job a match or a miss?