Analyst, IT Security Engineering, IT

CLSA

Hong Kong

On-site

HKD 420,000 - 780,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

CLSA is seeking an IT Security Analyst to join its international security team in Hong Kong. You will perform penetration testing, vulnerability assessments, and security reviews across on-prem and cloud environments, strengthening security controls and responses.

You will work with IT teams and business partners, stay updated on threats, and contribute to security strategy. Preference for CISSP/CISA/CISM and hands-on tool experience (Burp Suite, Metasploit, ZAP, Qualys, Nessus, Nmap).

Qualifications

  • Bachelor Degree in IT or Computer Science or related field.
  • 3-5 years of cybersecurity experience with regulatory knowledge.
  • Certifications such as CISSP, CISA, CISM preferred; offensive security certs (OSCP/OSWP/OSEP) a plus.
  • Experience in Big4, IT consultancies, or Cyber Threat Intelligence welcomed.
  • Hands-on with penetration testing and vulnerability scanning tools (Burp Suite, Metasploit, ZAP, Qualys, Nessus, Nmap).
  • Strong English and Chinese communication and project management skills.
  • Experience in offensive security services across web, network, server, client apps, mobile, AI, IoT.

Responsibilities

  • Conduct penetration testing, vulnerability scanning and code review on IT systems and technologies.
  • Perform architecture reviews and security assessments of IT designs, configurations, and source code (On-Prem & Cloud).
  • Conduct cyber-attack simulations using red/blue/purple team exercises.
  • Prepare reports with identified vulnerabilities and remediation recommendations.
  • Review access for vendors and guests across IT systems and services.
  • Assist in evaluating, designing and implementing security solutions like Web App Firewalls, SSO/MFA, PKI, AI red teaming, Zero Trust.

Skills

Penetration testing
Vulnerability assessment
Security architecture
Communication skills (EN & CN)
Project management
Regulatory knowledge

Education

Bachelor's degree in IT/Computer Science

Tools

Burp Suite
Metasploit
ZAP
Qualys
Tenable/Nessus
Nmap

Job description

We are looking for an IT Security Analyst who is proactive, self-motivate, willing- to-do attitude to be part of an international IT Security team to engineer and support security solutions.

As a team member in IT security team, you will be a contributor to the company’s IT and Cyber security strategy and operations. You and your team will be managing a portfolio of IT security tools in identity access management, network intrusion detection system, endpoint protection, email security, data leakage protection, application security, and other information security controls.

Key Areas of Responsibilities
  • Conduct penetration testing, vulnerability scanning and code review on different IT systems and technologies
  • Perform architecture Review and security assessments on IT systems’ design, configuration, source code review on both On-Perm and Cloud
  • Conduct Cyber-attack simulation using red team / blue team / purple team exercises
  • Prepare and review reports on identified security vulnerabilities and possible recommendations to remediate the vulnerabilities
  • Perform access review for vendor and guest access on IT systems and services.
  • Assist on Evaluating, Design, planning and implementing IT security solutions, such as Web Application Firewalls, Single Sign On/MFA, Biometric authentication, Cloud Based Public Key Infrastructure (PKI), Malware Sandboxing, AI red teaming, Zero Trust Solutions, etc.
  • Assist on first and second level support for some of IT security controls and tools including penetration test tools, vulnerability scanning tools, etc.
  • Be the subject matter expert for some of the IT Security tools.
  • Build and maintain an effective working relationship with the team’s key stakeholders - IT Security team members, IT teams and business teams.
  • Design and deliver new strategic security initiatives with collaboration from business partners.
  • Maintain an Up-to-date understanding of the latest threats, vulnerabilities, mitigation and industry best practices, Post Quantum Computing standard (ML-KEM, ML-DSA, SLA-DSA), and developments in Artificial Intelligence.
Requirements
  • Bachelor Degree of above in IT, Computer Science
  • 3-5 years related experience in cybersecurity, with knowledge in regulatories
  • Preferably holds IT Security Certifications such as CISSP, CISA, CISM, etc. Certificates related to offensive security (e.g. OSCP, OSWP, OSEP or equivalent) are an advantage.
  • Candidates with backgrounds in Big4, IT consultancy firms, or Cyber Threat Intelligence are welcome to apply
  • Hands-on experience with penetration test and vulnerability scanning tools such as Burp Suite, Metasploit, ZAP, Qualys, Tenable/Nessus, Nmap, etc
  • Strong communication skills in English and Chinese, as well as project management skills
  • Experience of offensive security services on Web, Network, Server, Client Apps, Mobile, AI, Internet of Thing (IOT) is required:
  • Penetration testing
  • Security risk assessment/technical review
  • Configuration review
  • Vulnerability scanning and assessment
  • Knowledge and understanding of the following areas are the foundation to succeed on this role:
  • Public Cloud computing platforms - Microsoft Azure, AWS, GCP, Ali Cloud, Tencent Cloud, etc
  • Microsoft Active Directory, Microsoft Certificate Authority, Microsoft Windows servers and Linux
  • Storage and Database fundamental
Good-to-have
  • Knowledge of two or more of the following security areas below is a plus:
  • Malware Sandboxing, Microsoft Cloud PKI and Intune
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

CYBER SECURITY AND RISK ANALYST / CYBER SECURITY ENGINEER
CYBER SECURITY AND RISK ANALYST / CYBER SECURITY ENGINEER

Henderson Land Development Company Limited • Hong Kong

On-site
HKD 420,000 - 660,000
Fringe benefits
網絡安全工程師 Cybersecurity Engineer
網絡安全工程師 Cybersecurity Engineer

Aurora Information Solutions Limited • Hong Kong

On-site
HKD 360,000 - 540,000
Discretionary Performance Bonus
Medical Benefits
Opportunities on large-scale projects
IT Cybersecurity Engineer
IT Cybersecurity Engineer

ConnectedGroup • Hong Kong

On-site
HKD 500,000 - 900,000
Manager - Cyber-Security (Application)
Manager - Cyber-Security (Application)

Classy Wheeler Limited • Hong Kong

On-site
HKD 600,000 - 900,000
Information Security Analyst
Information Security Analyst

Leadingnation • Hong Kong

On-site
HKD 500,000 - 700,000
Join a forward-thinking organization
Hands-on exposure to enterprise-level security operations
Collaborate with skilled technical teams
Systems & Security Engineer
Systems & Security Engineer

KOS International Limited • Hong Kong

On-site
HKD 420,000 - 580,000
Assistant Manager - Cyber Security Ops - Tech Risk & Security Assessment
Assistant Manager - Cyber Security Ops - Tech Risk & Security Assessment

Galaxy Entertainment Group • Hong Kong

On-site
HKD 420,000 - 660,000
Information Security Specialist
Information Security Specialist

KOS International Holdings • Hong Kong

On-site
HKD 360,000 - 600,000
IT Security Engineer - Hong Kong
IT Security Engineer - Hong Kong

IO TECH SOLUTIONS LIMITED • Hong Kong

On-site
HKD 500,000 - 800,000
Consulting - Cyber Security - Pentest - Staff/Senior
Consulting - Cyber Security - Pentest - Staff/Senior

Top Match Talent Solutions Limited • Hong Kong

On-site
HKD 420,000 - 540,000
Broad development platform
Professional training
Favorable welfare benefits
+1