Analyst, IT Security Engineering, IT

CITIC Securities International Company Limited

Hong Kong Island

On-site

HKD 420,000 - 640,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

CITIC CLSA is seeking an IT Security Analyst to join an international security team in Hong Kong. You will manage a portfolio of security controls, conduct penetration testing and vulnerability management, and support design and operation of cyber security programs across on‑prem and cloud environments.

The role requires hands-on experience with security testing tools, strong English and Chinese communication, and the ability to collaborate with IT and business units on risk remediation and

Qualifications

  • Bachelor degree in IT/CS or related field.
  • 3-5 years of cybersecurity experience with regulatory knowledge preferred.
  • Certifications such as CISSP/CISA/CISM are a plus; offensive security certs are advantageous.

Responsibilities

  • Conduct penetration testing, vulnerability scanning and code reviews on IT systems and technologies.
  • Perform architecture reviews and security assessments of IT systems’ designs and configurations (On-Prem and Cloud).
  • Conduct cyber-attack simulations using red/blue/purple team exercises.
  • Prepare reports with identified vulnerabilities and remediation recommendations.
  • Assist in evaluating, designing and implementing security controls including MFA, PKI, WAFs and IAM.

Skills

Penetration testing
Vulnerability scanning
Security assessments
Red team exercises
Cloud security

Education

Bachelor Degree in IT/CS

Tools

Burp Suite
Metasploit
ZAP
Nessus
Nmap
Qualys

Job description

CITIC CLSA provides global investors and corporate executives with insights, liquidity and capital to drive their growth strategies.

Award-winning research, an extensive Asia footprint, direct links to China and highly experienced finance professionals differentiate our innovative products and services in asset management, corporate finance, equity and debt capital markets, securities and wealth management.

As part of CITIC Securities (SSE: 600030, SEHK: 6030), China's leading investment bank, CITIC CLSA is uniquely positioned to facilitate cross-border capital flows and connect China to the world and the world to China.

CITIC CLSA operates from 13 countries across Asia, Australia, Europe and the Americas. For further information, please visit www.clsa.com.

Position Description

We are looking for an IT Security Analyst who is proactive, self-motivate, willing- to-do attitude to be part of an international IT Security team to engineer and support security solutions.

As a team member in IT security team, you will be a contributor to the company's IT and Cyber security strategy and operations. You and your team will be managing a portfolio of IT security tools in identity access management, network intrusion detection system, endpoint protection, email security, data leakage protection, application security, and other information security controls.

Key Areas of Responsibilities

Conduct penetration testing, vulnerability scanning and code review on different IT systems and technologies

Perform architecture Review and security assessments on IT systems' design, configuration, source code review on both On-Perm and Cloud

Conduct Cyber-attack simulation using red team / blue team / purple team exercises

Prepare and review reports on identified security vulnerabilities and possible recommendations to remediate the vulnerabilities

Perform access review for vendor and guest access on IT systems and services.

Assist on Evaluating, Design, planning and implementing IT security solutions, such as Web Application Firewalls, Single Sign On/MFA, Biometric authentication, Cloud Based Public Key Infrastructure (PKI), Malware Sandboxing, AI red teaming, Zero Trust Solutions, etc.

Assist on first and second level support for some of IT security controls and tools including penetration test tools, vulnerability scanning tools, etc.

Be the subject matter expert for some of the IT Security tools.

Build and maintain an effective working relationship with the team’s key stakeholders - IT Security team members, IT teams and business teams.

Design and deliver new strategic security initiatives with collaboration from business partners.

Maintain an Up-to-date understanding of the latest threats, vulnerabilities, mitigation and industry best practices, Post Quantum Computing standard (ML-KEM, ML-DSA, SLA-DSA), and developments in Artificial Intelligence.

Requirements

Bachelor Degree of above in IT, Computer Science

3-5 years related experience in cybersecurity, with knowledge in regulatory

Preferably holds IT Security Certifications such as CISSP, CISA, CISM, etc. Certificates related to offensive security (e.g. OSCP, OSWP, OSEP or equivalent) are an advantage.

Candidates with backgrounds in Big4, IT consultancy firms, or Cyber Threat Intelligence are welcome to apply

Hands-on experience with penetration test and vulnerability scanning tools such as Burp Suite, Metasploit, ZAP, Qualys, Tenable/Nessus, Nmap, etc

Strong communication skills in English and Chinese, as well as project management skills

Experience of offensive security services on Web, Network, Server, Client Apps, Mobile, AI, Internet of Thing (IOT) is required:

Penetration testing

Security risk assessment/technical review

Configuration review

Vulnerability scanning and assessment

Knowledge and understanding of the following areas are the foundation to succeed on this role:

Public Cloud computing platforms - Microsoft Azure, AWS, GCP, Ali Cloud, Tencent Cloud, etc

Microsoft Active Directory, Microsoft Certificate Authority, Microsoft Windows servers and Linux

Storage and Database fundamental

Good-to-have

Knowledge of two or more of the following security areas below is a plus:

Malware Sandboxing, Microsoft Cloud PKI and Intune

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Analyst, IT Security Engineering, IT
Analyst, IT Security Engineering, IT

CLSA • Hong Kong

On-site
HKD 420,000 - 780,000
Sr. Analyst, IT Security Engineering, IT
Sr. Analyst, IT Security Engineering, IT

CITIC Securities International Company Limited • Hong Kong

On-site
HKD 420,000 - 660,000
IT Security Engineer: Pen Testing, Cloud & Zero Trust
IT Security Engineer: Pen Testing, Cloud & Zero Trust

CITIC Securities International Company Limited • Hong Kong Island

On-site
HKD 420,000 - 640,000
IT Cybersecurity Engineer
IT Cybersecurity Engineer

ConnectedGroup • Hong Kong

On-site
HKD 500,000 - 900,000
網絡安全工程師 Cybersecurity Engineer
網絡安全工程師 Cybersecurity Engineer

Aurora Information Solutions Limited • Hong Kong

On-site
HKD 360,000 - 540,000
Discretionary Performance Bonus
Medical Benefits
Opportunities on large-scale projects
IT Security Engineer: Threat & Defense Architect
IT Security Engineer: Threat & Defense Architect

CLSA • Hong Kong

On-site
HKD 420,000 - 780,000
Sr. Analyst, IT Security Engineering, IT
Sr. Analyst, IT Security Engineering, IT

CLSA • Hong Kong

On-site
HKD 600,000 - 1,000,000
Manager - Cyber-Security (Application)
Manager - Cyber-Security (Application)

Classy Wheeler Limited • Hong Kong

On-site
HKD 600,000 - 900,000
Cyber Security (Assistant) Manager
Cyber Security (Assistant) Manager

Ping An Digital Bank • Hong Kong

On-site
HKD 420,000 - 860,000
Assistant Manager - Cyber Security Ops - Tech Risk & Security Assessment
Assistant Manager - Cyber Security Ops - Tech Risk & Security Assessment

New Galaxy Entertainment 2006 Company Limited • Hong Kong

On-site
HKD 420,000 - 700,000