工作机会
>
Hong Kong

    Assistant Technical Manager, Vulnerability Management - Hong Kong, 香港 - The Hong Kong Jockey Club

    The Hong Kong Jockey Club background
    全职
    描述

    The Department

    The Cyber Security and Cloud Platforms Department is responsible for the protection of the Club's information, information systems, network infrastructure and cloud platforms, as well as assurance over the resiliency and continuity of the Club's IT infrastructure. The team is also responsible for establishing governance and formulating cyber security procedures and guidelines to ensure consistent Club-wide safeguards and conformance to regulations in Hong Kong and China. It works to protect the reputation and enhance the operational resiliency of The Hong Kong Jockey Club.

    The Job

    • Perform threat assessment and patch management advisory operations via analysis of open and commercial security intelligence feeds, and ensure business and IT patch management teams comply with defined Service Level Agreements (SLAs) for security patch deployment.
  • Work with IT infrastructure, network operations teams and other IT stakeholders to review and assess new set ups, changes, upgrades to the organisation's network infrastructure and network components so to ensure any move and change will not introduce security risks to the organisation.
  • Perform vulnerability scanning across the Club's technology landscape work with key stakeholders to identify, govern and mitigate identified vulnerabilities.
  • Work with assigned Project Manager to drive small- to mid-size IS initiatives to evaluate, acquire and deploy new IS technologies and capabilities, and ensure initiatives get completed on time and budget.
  • Work closely with business and IT stakeholders to schedule and perform system and network vulnerability scanning, classify and prioritise risks, and guide relevant stakeholders to ensure that systems and services that are either developed in-house or acquired commercially are secured against known attack vectors and prevalent threats.
  • Conduct the web scanning and automated code testing of in-house applications, and guide developers and IT colleagues on coding best practices and mitigations prior to production release to ensure that systems are resistant to known attack vectors, OWASP Top 10, when deployed.
  • Support the closure of key cyber security threats and vulnerabilities zero-day vulnerabilities or during the Project Development Lifecycle).
  • Support the reviews and updates of applicable cyber defense policies, regulations, and compliance documents specifically related to Threat Vulnerability Management and Security Testing
  • Undertake other duties assigned by Cyber Security Management.
  • Participate, contribute and help shape a diverse and inclusive culture with trust and respect. Play an active role to support cross team/division/department efforts and model collaborative behaviours.
  • About You

    • University Degree in computer science, engineering or related discipline
    • Minimum of 5 years practical experience in IT Security Operations, Network infrastructure in a corporate environment with large-scale transaction websites and complex IT infrastructures and operations
    • Cybersecurity certification such as GCIH, GSOC, CISSP, CISA, CISM, OSCP, MITRE ATT&CK Defender etc. would be desirable
    • Experience in Threat and Vulnerability Management
    • Technical background, particularly in web application development, infrastructure & networking
    • Able to manage execution of action plans for ensuring the safety and security of all information system assets
    • Excellent inter-personal
    • Must demonstrate effective oral and written communication skills, with the ability to communicate technical topics to management and non-technical audiences
    • Must possess analytical, problem solving and documentation skills
    • Expertise in security testing, threat and vulnerability management tools and techniques, particularly around vulnerability scanning, patch management and penetration testing
    • In-depth experience of secure coding practices, source code review, and Internet threat vectors such as the OWASP top
    • Deep knowledge of secure networking infrastructure, Firewall, IDS/IPS, WAF, Secure MTA, Load Balancer, Internet Proxy as well as End-Point security
    • Working knowledge of security data analytics and incident handling
    • Working knowledge in ISO27001/2 or regulatory compliance standard

    Terms of Employment

    The level of appointment will be commensurate with qualifications and experience.

    Closing Date

    Only shortlisted candidates will be notified


  • The Hong Kong Jockey Club Hong Kong, 香港 全职

    The Department · The Cyber Security and Cloud Platforms Department is responsible for the protection of the Club's information, information systems, network infrastructure and cloud platforms, as well as assurance over the resiliency and continuity of the Club's IT infrastructur ...


  • IGNITE RECRUITMENT HONG KONG LIMITED Hong Kong, 香港 全职

    The Role · Review, implement and enforce Cyber resilience policies across the organisation · Perform regular risk and vulnerability assessments to identify potential threats putting in place remediation actions · Define and implement Cyber Incident Response plan and playbook. · ...


  • Morgan McKinley Hong Kong, 香港 全职

    Act as the Head of Global Cyber Security Department, having past experience in developing Cyber Security Framework, Policies, Procedures, IR Playbook; and run security programs. · Responsibilities:Develop and implement Group Cyber Security best practices and policies across glob ...

  • Recruit Logic

    IT Security Analyst

    8小时前


    Recruit Logic Hong Kong, 香港 全职

    Job responsibility: · Alert management and threat response based on output from cybersecurity tools. · Provide L1 and 2 support for the team's existing security controls and tools, with primary focus on proxies, secure web gateways, and Internet infrastructure protection. · Form ...


  • NLS Hong Kong, 香港 全职

    My client, a leading crypto exchange, are seeking a talented Cryptographic Lead Engineer to join their expanding team to lead the development of cutting-edge cryptographic solutions for their exchange platform. · The role: · Lead the design, development, and implementation of cry ...


  • Omni Group Asia Ltd. Hong Kong, 香港 全职

    Responsibilities · Develop and maintain a comprehensive AML/CFT program in accordance with applicable laws, regulations, and international standards. · Lead and manage a team of AML/CFT professionals, providing guidance, training, and support to ensure a strong culture of complia ...


  • Oliver James Associates Hong Kong, 香港 全职

    *Key Responsibilities:* · Develop and implement information security policies and procedures to ensure compliance with industry regulations and best practices. · - Lead the planning and execution of security initiatives, including risk assessments, threat intelligence, and incide ...


  • Wellesley Associates Limited Hong Kong, 香港 全职

    Duties: · Work in a Platform, Automation and Tooling team to support the infrastructure, platform and tooling solution; · Technical lead to plan, direct and manage the exploitation and modernization of current installed technology and capability; · Maintain and develop a highly ...

  • FortisHill Consulting Limited

    IT Lead

    1周前


    FortisHill Consulting Limited Hong Kong, 香港 全职

    Responsibilities: · Leadership and Strategy:Develop and implement the IT strategy aligned with the company's goals and objectives. · Provide strategic direction and guidance to the IT team, ensuring alignment with business needs. · Drive innovation and continuous improvement in I ...


  • The Bank of East Asia Hong Kong, 香港 全职

    Responsibilities · Assist Section Head of investment Products Management to drive retail investment revenue growth under Personal Banking Division ("PBD"), BEA Hong Kong ("BEAHK"). Support business and marketing activities on investment products (include Unit Trusts, Bonds, Struc ...


  • The Bank of East Asia Hong Kong, 香港 全职

    Position Summary · Responsible for the 2nd line of defense in technology risk related matters under 3 tiers of risk defensive model, to monitor and review the established control mechanisms and resources for execution in Head Office, China, overseas branches and significant subsi ...


  • Hong Kong Exchanges and Clearing Limited Hong Kong, 香港 全职

    Company Introduction: · We're home to Asia's most dynamic and vibrant capital markets. · Connecting capital, ideas, inspiration and innovation for deeper, more diverse and liquid global capital markets; providing greater choice and opportunity for our customers, each and every ...


  • Hong Kong Exchanges and Clearing Limited Hong Kong, 香港 全职

    Company Introduction: · We're home to Asia's most dynamic and vibrant capital markets. · Connecting capital, ideas, inspiration and innovation for deeper, more diverse and liquid global capital markets; providing greater choice and opportunity for our customers, each and every ...


  • Hong Kong Exchanges and Clearing Limited Hong Kong, 香港 全职

    Company Introduction: · We're home to Asia's most dynamic and vibrant capital markets. · Connecting capital, ideas, inspiration and innovation for deeper, more diverse and liquid global capital markets; providing greater choice and opportunity for our customers, each and every ...


  • Hong Kong Exchanges and Clearing Limited Hong Kong, 香港 全职

    Company Introduction: · We're home to Asia's most dynamic and vibrant capital markets. · Connecting capital, ideas, inspiration and innovation for deeper, more diverse and liquid global capital markets; providing greater choice and opportunity for our customers, each and every ...

  • Hong Kong Exchanges and Clearing Limited

    Vice President

    6天前


    Hong Kong Exchanges and Clearing Limited Hong Kong, 香港 全职

    Company Introduction: · We're home to Asia's most dynamic and vibrant capital markets. · Connecting capital, ideas, inspiration and innovation for deeper, more diverse and liquid global capital markets; providing greater choice and opportunity for our customers, each and every ...


  • Hong Kong Exchanges and Clearing Limited Hong Kong, 香港 全职

    Company Introduction: · We're home to Asia's most dynamic and vibrant capital markets. · Connecting capital, ideas, inspiration and innovation for deeper, more diverse and liquid global capital markets; providing greater choice and opportunity for our customers, each and every ...


  • Eclipse Trading Hong Kong, 香港 全职

    Systems Engineer Team Lead · Eclipse Trading is one of Asia's leading proprietary derivatives trading firms. Founded in 2007, we have over 100 employees across three office locations – Hong Kong (our HQ), Sydney, and Shanghai. Our trading expertise and strategies are deployed ...


  • BAH Partners Hong Kong, 香港 全职

    The Firm: · An innovative financial technology firm that operates at the forefront of the industry, leveraging advanced technology and quantitative research to make informed, data-driven decisions. Work is characterized by collaboration, intellectual rigor, and a relentless pursu ...


  • Hang Seng Bank Limited Hong Kong, 香港 全职

    Job description · A Career with Hang Seng Bank · Hang Seng is committed to service excellence. Our people are our most important asset and play a vital role in our efforts to continually enhance our performance for customers and provide best-in-class products and services. We ...