Responsibilities
- Engineer, implement and monitor security measures for the protection ofputer systems, networks and information
- Identify and define system security requirements
- Designputersecurity architecture and develop detailed cyber securitydesigns
- Configure and troubleshoot security systems and infrastructure devices
- Develop technical solutions and new security tools to help mitigate security vulnerabilities and automate repeatable tasks
- Maintain all solution design documentation, processes, procedures and report on metrics to demonstrate effective and efficient management of services.
- Work with handling service requests on security tool standard changes, such as proxy whitelisting requests
- Delivery security service on-boarding such as security agent install, connecting systems to SIEM
- Review IT systems to ensure that they have met security acceptance criteria.
- Work with product vendors and suppliers to maintain and enhance existing security tooling and products
- Ensure that the organization security tools can detect and help with the response to cyber security incidents.
- Document and validate disaster recovery testing for CyberSecurity tools.
- Writeprehensive reports including assessment-based findings, oues and propositions for further system security enhancement s
- Support in m anag ing the Total Cost of Ownership (TCO) for security solutions which includes new investments and business-as-usual financials.
- Design and execute processes to make BAU changes to security tools ( eg web proxy changes, DLP mail rule changes, etc )
- Automate or script changes and validation processes
Requirements :
Proven work experience as a System Security Engineer or Information Security EngineerExperience in building, maintaining and operating security systems and platformsHands on experience in a number of security systems, including firewalls, intrusion detection systems, anti-virus software, authentication systems, log management, content filtering, data loss prevention systems, web proxies, etcExperience with network security and networking technologies and with system, security, and network monitoring toolsThorough understanding of the latest security principles, techniques, and protocols (such as zero trust , etc )Problem solving skills and ability to work under pressureMust have strong information security technology knowledge / concepts and can effectivelymunicate with senior management and a broad range of te chnical / non-technical audiences . Strong writtenmunication skills and verbal presentations to senior management .Must have a relevant University degree inputer Science, Information Management, or related field, or equivalent experience.Good presentation , project planning and document ation skillsFamiliarity with web related technologies (Web applications, Web Services, Service Oriented Architectures) and of network / web related protocolsFamiliarity with application, database and operating system securityFamiliarity with cloud security technologies (AWS or Azure is preferred)Familiarity with risk / control frameworks, such as Mitre ATT&CK, D3 FEND, OWASP, NIST Cybersecurity FrameworkFamiliarity in scripting or automation is a n added advantageFamiliarity with Identity and Lifecycle management is an advantagePrevious experience in regulated environments is an added advantageHKEX ismitted as an Equal Opportunity Employer. Diversity is one of our core values and we look to support, respect diverse perspectives, abilities, culture and experiences within our workplace.
Location : HKEX - TKO
Shift :
Standard - 40 Hours (Hong Kong SAR)
Scheduled Weekly Hours :
40
Worker Type :
Contract Job ID R002902