工作机会
>
Hong Kong

    Infrastructure Security SpecialistPermanent contractHong Kong, Hong Kong - Société Générale Assurances

    Default job background
    Permanent contract
    描述

    Infrastructure Security Specialist

    Permanent contract|Hong Kong|IT (Information Technology)

    Infrastructure Security Specialist

  • Hong Kong, Hong Kong
  • Permanent contract
  • IT (Information Technology)
  • Responsibilities

  • Work closely with SOC, CERT and other security teams and Infrastructure skill teams in daily operation and review security requirements
  • Exception management: Evaluate and manage infrastructure security exceptions
  • Vulnerability management: Conduct scan, assessment and remediation follow-up
  • Incident management: Report and follow security incidents and their remedial actions
  • Request / Change management: Conduct security assessment for infrastructure request & changes
  • Review security architecture proposed by other infrastructure teams
  • Deliver innovation initiative to improve overall infrastructure security and efficiency
  • Manage and execute the Infrastructure related security projects
  • Be the security Interface with stakeholders at all levels, from technical engineers to senior management locally, regionally and globally
  • Work closely with other risk and security departments, including all 3 lines of defence
  • Cyber reporting: Production of various cyber security reporting (KPIs; KRIs). Coordinate among
  • Infrastructure teams to contribute to external stakeholders reporting and requests
  • Conduct security & risk awareness training to the Infrastructure teams
  • Profile required

  • Knowledge and hands-on experiences in IT, Infrastructure and information security
  • Knowledge and experience in IT infrastructure (speak the language, expertise not required)
  • Knowledge in technology regulatory requirement like HKMA, SFC, MAS, GDPR, CBIRC, etc. is required
  • Project management experience is desired
  • Knowledge and experience in a banking environment will be beneficial but not essential
  • Knowledge in the MITRE ATT&CK framework and hands-on experience on security incident investigation processes & techniques
  • Security knowledge in the Public Cloud, development and specific Infrastructure domains are a plus
  • Professional certification recognized by Regulatory bodies like HKMA, CISM, CISA or CISSP, is mandatory
  • Behavioral Skills

  • Client - Understanding and Respect: I listen to clients and colleagues in order to understand and anticipate their needs
  • Client - Risk: I strive to satisfy clients while taking into account risks for the company
  • Team Spirit - Synergies: I make cooperation with colleagues in and outside my team a priority
  • Team Spirit - Collective mindset: I favour the team's interest over my own results
  • Responsibility - Courage: I express my convictions and make decisions with courage and respect.
  • Responsibility - Accountability: I make decisions in my scope of responsibilities