IT Cybersecurity Engineer (B9C7410AE) Hong Kong

Salary: HKD45000 - HKD55000 per month

Our client is a well-established financial institution seeking a Cybersecurity Engineer to join its Information Security team. This position will play a critical role in strengthening the organization's cybersecurity posture through security engineering, vulnerability management, security controls implementation, cyber risk mitigation, and incident response support.

The successful candidate will work closely with infrastructure, cloud, application, risk, and business teams to ensure security best practices are embedded across the technology landscape.

Responsibilities of the Role: 

  • Implement, maintain, and enhance cybersecurity technologies, tools, and security controls across the enterprise.
  • Perform security assessments and support internal, regional, and regulatory security reviews.
  • Drive vulnerability management activities, including risk assessment, remediation tracking, and security hardening initiatives.
  • Monitor emerging cyber threats, security vulnerabilities, and threat intelligence to proactively identify risks.
  • Support cybersecurity incident response, investigation, containment, recovery, and reporting activities.
  • Assist in developing and maintaining cybersecurity policies, standards, procedures, and technical baselines.
  • Collaborate with infrastructure, cloud, and application teams to ensure secure technology design and implementation.
  • Support security monitoring and operational activities to protect critical systems and data assets.
  • Conduct security reviews of new technologies, projects, and systems to ensure compliance with security requirements.
  • Deliver cybersecurity awareness initiatives and promote security best practices across the organization.
  • Prepare security metrics, risk reports, and management updates for key stakeholders.

Required Skills for the Role: 

  • Bachelor's degree in Computer Science, Information Security, Information Technology, or a related discipline.
  • Minimum 5-8 years of experience in Cybersecurity, Information Security, IT Security, or Technology Risk.
  • Hands-on experience with security controls implementation, vulnerability management, and security assessments.
  • Good understanding of security domains, including:
    • Network Security
    • Endpoint Security
    • Identity & Access Management (IAM)
    • Security Monitoring
    • Threat Management
    • Incident Response
    • Cloud Security
  • Experience working with cybersecurity tools such as SIEM, EDR, vulnerability scanners, IAM, DLP, or security monitoring platforms.
  • Familiarity with cybersecurity frameworks and standards such as NIST, ISO 27001, CIS Controls, or equivalent.
  • Experience supporting security audits, compliance reviews, and regulatory assessments is an advantage.
  • Strong troubleshooting, analytical, and problem-solving skills.
  • Ability to communicate effectively with both technical and non-technical stakeholders.
  • Fluency in English and Cantonese; Mandarin would be an advantage.