Likeremote

Subscribe to the latest remote jobs:

  • Likeremote jobs on https://LinkedIn.com/
  • Likeremote jobs on https://telegram.org/
  • Likeremote jobs on Reddit.com
Hong Kong Exchanges and Clearing Limited logo

Senior Information Security Engineer - AVP

Hong Kong Exchanges and Clearing Limited
  • 🇨🇳 China
  • On-site
  • Senior
  • 1 day ago
  • Vulnerability Management
  • Incident Response
  • SIEM
  • Penetration Testing
  • Change Management
  • WAF
  • KMS
  • Splunk
  • Tenable
  • CyberArk
  • Windows
  • Linux
  • Network Security
  • CISSP
  • CISM
  • CISA
  • ISO 27001
Not scoredNo CV on file. Upload one and this job gets a score out of 100.Upload CV

Location:

CN-Shenzhen-HyQ

Shift:

Scheduled Weekly Hours:

40

Worker Type:

Permanent

Job Summary:

Job Duties:

Position Summary 

We are seeking an experienced Information Security professional to lead and execute information security governance, security operations, security compliance, vulnerability management, and security monitoring initiatives across our business platforms. 

The successful candidate will be responsible for aligning local security practices with Group security standards, driving security governance programs, managing security tools and controls, coordinating security assessments, and supporting security incident response activities. 

 

Key Responsibilities 

 

1. Security Operations & SOC 

  • Own and maintain security monitoring processes and operational procedures. 
  • Coordinate SIEM and log management initiatives. 
  • Work with Group SOC and MSSP teams on security monitoring, alert handling, and escalation processes. 
  • Define log collection standards, onboarding scope, and monitoring requirements. 
  • Participate in threat detection and security operations improvement initiatives. 

 

2. Security Incident Response 

  • Develop and maintain Security Incident Response Plans and procedures. 
  • Coordinate incident investigation, containment, eradication, recovery, and post-incident review activities. 
  • Define security incident escalation workflows and communication mechanisms. 
  • Organize security drills, tabletop exercises, and response testing. 
  • Support regulatory and compliance-related incident reporting requirements. 

 

3. Vulnerability & Security Assessment Management 

  • Manage vulnerability scanning programs and security assessment activities. 
  • Track vulnerability remediation progress and risk mitigation activities. 
  • Coordinate:  
  • Vulnerability Scanning 
  • Penetration Testing 
  • Secure Configuration Reviews 
  • Source Code Reviews 
  • Application Security Testing 
  • CIS benchmark 
  • Security Architecture Reviews 
  • Prepare risk acceptance documentation and remediation plans. 

 

4. Identity & Access Management 

  • Manage privileged account governance and PAM/PIM controls with Change management team.  
  • Coordinate periodic access reviews and account audits. 
  • Maintain privileged account management standards and procedures with change management team.  

 

5. Security Technology Management 

Manage and govern security solutions including but not limited to: 

  • SIEM 
  • WAF/Anti-DDOS 
  • IPS/IDS 
  • Endpoint Security 
  • PAM/PIM 
  • Web Proxy 
  • KMS/Certificate Services 
  • Security Monitoring Platforms in Tencent Cloud 

Responsibilities include: 

  • Security product selection and evaluation 
  • Vendor management 
  • Security architecture review 
  • Security product implementation and optimization 
  • Security product lifecycle management 

 

 

6. Security Compliance & Regulatory Requirements 

  • Coordinate MLPS (等保) assessments and remediation activities. 
  • Support internal and external audits. 
  • Maintain compliance with applicable security regulations and standards. 
  • Manage third-party security assessments and compliance reviews. 
  • Coordinate security-related regulatory reporting and evidence collection. 

 

Qualification Requirements 

Education 

  • Bachelor's degree or above in:  
  • Information Security 
  • Computer Science 
  • Information Technology 
  • Cyber Security 
  • Related disciplines 

 

Experience 

  • 5+ years of Information Security experience 
  • Experience in security governance and compliance programs 
  • Experience with SOC/SIEM operations and log management 
  • Experience managing security projects and vendors 
  • Experience working with regional or Group security organizations is highly preferred 
  • Financial services or regulated industry experience is highly desirable 

 

Technical Skills 

Hands-on experience in several of the following areas: 

  • Security Operations Center (SOC) 
  • SIEM Platforms (Splunk, ArcSight, 日志易, etc.) 
  • Vulnerability Management(Tenable) 
  • Penetration Testing Coordination 
  • Security Incident Response 
  • PAM / PIM Solutions (CyberArk/RenkEZ) 
  • Windows / Linux Security(CIS benchmark) 
  • Network Security 
  • Cloud Security 
  • Endpoint Security 
  • Security Compliance Frameworks 
  • Security Architecture Review 

 

Preferred Certifications 

One or more of the following: 

  • CISSP 
  • CISM 
  • CISA 
  • ISO27001 Lead Implementer/ISO27001 Lead Auditor 
  • Security+ 

 

Soft Skills 

  • Strong stakeholder management skills 
  • Strong communication and presentation skills 
  • Ability to coordinate across multiple teams and vendors 
  • Strong analytical and problem-solving skills 
  • Risk-based decision-making mindset 
  • Ability to work independently with minimal supervision 

Company Introduction:

ITD SZ

港交所科技(深圳)有限公司,是2016年12月28日于深圳市前海自贸区成立的外商独资企业。

作为港交所的技术子公司,港交所科技(深圳)有限公司主要是为集团及其附属公司提供计算机软件、计算机硬件、信息系统、云存储、云计算、物联网和计算机网络的开发、技术服务、技术咨询、技术转让;经济信息咨询、企业管理咨询、商务信息咨询、商业信息咨询、信息系统设计、集成、运行维护;数据库管理、大数据分析;以承接服务外包方式提供系统应用管理和维护、信息技术支持管理、数据处理等信息技术和业务流程外包服务。

Senior Information Security Engineer - AVP · Hong Kong Exchanges and Clearing Limited

Auto apply with Likeremote