岗位描述
岗位职责
The successful candidate will report to the Lead of Governance & Security in the Group Information Technology Department, supporting IT governance, information security operations and the secure adoption of cloud, Microsoft security and AI-enabled platforms. Key responsibilities are:
Manage the external Security Operations Centre (SOC) service provider, review security alerts and incident tickets, and coordinate investigation, escalation, response and closure with internal teams, vendors and relevant parties.
Support security incident response, including triage, investigation, containment coordination, root-cause review, remediation tracking, evidence documentation and management reporting.
Identify and assess security risks across cloud services, Microsoft 365 / Azure, identity platforms, web and API applications, ERP system, third-party integrations and AI-enabled solutions, and work with risk owners on practical mitigation actions.
Coordinate vulnerability assessments, penetration testing, security configuration reviews, patch follow-up and remediation to keep IT assets securely configured and regularly updated.
Improve security operation efficiency through better alert quality, detection use cases, escalation playbooks, dashboards, SOAR, scripting, workflow automation or AI-assisted investigation where appropriate.
Prepare regular incident, SOC performance, risk and remediation reports for management review, and support security awareness training and phishing simulation activities.
岗位要求
Degree holder in Computer Science, Information Engineering, Information Security, Cybersecurity or related disciplines
Minimum 3 years of relevant experience in IT security, SOC operations, incident response, risk management, cloud security or related areas
Practical experience in reviewing SOC alerts, investigating security events, coordinating incident response and working with external MSSP / SOC providers
Knowledge of security governance, incident response, vulnerability and patch management, PAM, IAM, web / API security, cloud security and security awareness practices
Experience with SIEM, SOAR, EDR / XDR, Microsoft Defender, Microsoft Sentinel, Microsoft Entra ID, vulnerability scanning, email security and cloud security monitoring tools would be an advantage
Knowledge of AI security governance, secure AI adoption, automation workflow control, data leakage prevention, audit logging and monitoring of AI agents or AI platforms would be an advantage
Knowledge of ITIL and security frameworks such as ISO / IEC 27001, NIST Cybersecurity Framework, CIS Controls, MITRE ATT&CK, OWASP Top 10 and OWASP API Security Top 10 would be an advantage
Professional qualifications such as CISSP, CISM, CISA, CEH, CCSP, Microsoft Security certifications or equivalent would be an advantage
Strong analytical, documentation, problem-solving, stakeholder management and communication skills, with good written and spoken Chinese and English