岗位描述
Job Responsibilities
Bank-wide Security Architecture Planning & Implementation
Design and optimize the bank’s end-to-end information security technical architecture using a defense-in-depth approach and cybersecurity defense systems.
Review security solutions for new systems and major change projects to ensure alignment with business and system development.
Conduct periodic assessments of existing security architecture, identify vulnerabilities, and lead the implementation of security hardening roadmaps.
AI Security Operations Tool Design & Enablement
Research and implement AI/LLM use cases in security operations (e.g., PoCs and scenario-based solutions).
Develop automated tools for log parsing, risk analysis, compliance verification, and improvements in operational efficiency.
Lead AI-driven initiatives such as intelligent alert classification, security rule streamlining, and sensitive data identification.
Security Governance, Compliance & Audit
Maintain and enhance the bank’s information security management framework, including policies, standards, and SOPs.
Perform security compliance checks and data protection assessments.
Coordinate with Risk and Audit teams; develop remediation plans to address vulnerabilities, internal control gaps, and audit findings, ensuring full closure.
Daily Security Operations & Incident Response
Monitor and analyze the bank’s cybersecurity/data security posture, including correlation analysis and attack path tracing.
Lead incident response efforts, cyber drills, and post-incident reviews (PIR) for major security events.
Continuously improve security monitoring capabilities and threat detection frameworks.
Job Requirements
Bachelor’s degree or above in Information Technology, Computer Science, or related disciplines.
Minimum 5 years of experience in banking information security.
Technical requirements
Hands-on experience in Red/Blue team exercises and offensive security (e.g., SQL injection, XSS, privilege escalation, command-and-control or DDoS/CC attack concepts).
Foundational knowledge of AI/LLM and experience in security design and/or security auditing.
Experience in full lifecycle management of information security products/services (procurement, implementation, and O&M).
5+ years in security operations tooling and security rule formulation (e.g., log parsing, risk analysis, compliance verification).
Soft skills requirements
Strong strategic planning and cross-functional collaboration skills.
Proven ability to drive innovation in AI-driven security solutions.
High adaptability in dynamic, fast-paced, and high-pressure environments.
Certification
Must have passed HKMA-recognized information security certifications, e.g., CISSP / CISM / CISA.
Language
Proficient in written and spoken English and Chinese, including Putonghua.
Additional
Candidates with more experience will be considered for Senior IT Information Security Manager
Interested parties, please send your resume to charlotte.mou@manpowergrc.hk