Analyst – Technology Risk Management (Ref: 260000SP)

MTR Corporation Limited 香港鐵路有限公司

Hong Kong

On-site

HKD 480,000 - 720,000

Full time

22 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

MTR Corporation Limited 香港鐵路有限公司 is seeking an experienced security operations professional to monitor IT/OT environments, coordinate incident response, and ensure regulatory reporting compliance. The role requires collaboration with the SOC and IT/OT teams to manage incidents from detection to resolution.

The ideal candidate has 3+ years in security operations or SOC roles, with relevant certifications and a proactive mindset for continuous improvement.

Qualifications

  • Bachelor degree in Computer Science, Information Security or a related discipline.
  • Minimum 3 years in security operations, incident response, or SOC roles in complex environments, with ICs/OT experience preferred.
  • Professional certifications such as CISSP, CISM, CISA, CISP or similar are highly preferred.
  • Specialized incident response or SOC certifications (GIAC, GCIH, GCFA) are an advantage.
  • Strong knowledge of monitoring, threat detection, and incident response; familiarity with NIST, SANS frameworks and regulatory reporting.

Responsibilities

  • Ensure security monitoring tools and processes (IDS/IPS, SIEM) cover critical IT/OT environments and that logs are retained and analyzed per policy.
  • Maintain readiness for cybersecurity incidents; classify incidents, activate response teams, and coordinate with SOC, IT/OT teams, and leaders.
  • Ensure timely statutory incident notifications and regulatory submissions within deadlines with detailed incident reports.
  • Lead post-incident reviews, root cause analysis, and continuous improvement; drive lessons learned and regular cyber drills.
  • Act as technology risk delegate providing real-time updates and metrics to information security leaders.
  • Collaborate with managed SOC and cybersecurity leads to align incident response with plan, policies, standards and guidelines.

Skills

Security monitoring
IDS/IPS
SIEM
Incident response
SOC coordination
Crisis management

Education

Bachelor in Computer Science or Information Security

Tools

SIEM platforms

Job description

  • Ensure security monitoring tools and processes, e.g. IDS/ IPS, SIEM, cover critical IT/ OT environments. Regularly fine-tune monitoring rules, review logs, and ensure log retention and analysis comply with corporate and regulatory requirements.
  • Maintain organizational readiness for cybersecurity incidents affecting critical systems. Ensure proper incident classification, activate response teams promptly, and coordinate communications among Security Operations Center (SOC), IT/ OT teams, and information security leaders.
  • Ensure timely and accurate statutory incident notifications and reporting, including regulatory submissions within prescribed timelines and detailed incident reports as required.
  • Lead post-incident reviews, root cause analysis, and continuous improvement initiatives. Drive implementation of lessons learned and conduct regular cyber incident drills to strengthen response capabilities.
  • Act as a technology risk delegate for security incidents, providing real-time updates and incident metrics to the information security leaders throughout the incident.
  • Collaborate closely with the managed SOC and cybersecurity leads in business units and functions to incident response aligns with the incident response plan, the information policies, standards and guidelines.
Responsibilities
  • Ensure security monitoring tools and processes, e.g. IDS/ IPS, SIEM, cover critical IT/ OT environments. Regularly fine-tune monitoring rules, review logs, and ensure log retention and analysis comply with corporate and regulatory requirements.
  • Maintain organizational readiness for cybersecurity incidents affecting critical systems. Ensure proper incident classification, activate response teams promptly, and coordinate communications among Security Operations Center (SOC), IT/ OT teams, and information security leaders.
  • Ensure timely and accurate statutory incident notifications and reporting, including regulatory submissions within prescribed timelines and detailed incident reports as required.
  • Lead post-incident reviews, root cause analysis, and continuous improvement initiatives. Drive implementation of lessons learned and conduct regular cyber incident drills to strengthen response capabilities.
  • Act as a technology risk delegate for security incidents, providing real-time updates and incident metrics to the information security leaders throughout the incident.
  • Collaborate closely with the managed SOC and cybersecurity leads in business units and functions to incident response aligns with the incident response plan, the information policies, standards and guidelines.
Requirements
  • Bachelor in Computer Science, Information Security or a related discipline
  • A minimum of 3 years' experience in security operations, incident response, or SOC roles, and implementing monitoring solutions in complex environments. Experience in a critical infrastructure or ICs/ OT security context is preferred
  • Possession of professional certifications such as CISSP, CISM, CISA, CISP or similar are highly preferred
  • Possession of specialized incident response or SOC-related certifications, e.g., GIAC, GCIH, GCFA, is an advantage
  • Strong knowledge of security monitoring, threat detection, and incident response. Familiarity with cyber incident management frameworks, e.g. NIST, SANS, and regulatory incident reporting requirements. Excellent crisis management and problem-solving skills, with the ability to remain calm and decisive under pressure
  • Strong communication skills, enabling clear coordination with both technical teams and senior management during incidents
  • Possession of a proactive mindset for continuous improvement, ensuring lessons learned from incidents lead to tangible security enhancements
Schedule

Full-time

Job Posting

10/Sep/26, 5:56:12 PM

Closing Date

24/Sep/26, 11:59:00 PM

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Manager
Information Security Manager

NTT Com Asia • Hong Kong

On-site
HKD 900,000 - 1,500,000
IT Security Operations Manager - IC
IT Security Operations Manager - IC

Classy Wheeler Limited • Hong Kong

On-site
HKD 700,000 - 900,000
CYBER SECURITY AND RISK ANALYST / CYBER SECURITY ENGINEER
CYBER SECURITY AND RISK ANALYST / CYBER SECURITY ENGINEER

Henderson Land Development Company Limited • Hong Kong

On-site
HKD 420,000 - 660,000
Fringe benefits
Senior Technical Manager, Security Operations Centre
Senior Technical Manager, Security Operations Centre

The Hong Kong Jockey Club • Sha Tin District

On-site
HKD 90,000 - 130,000
Information Technology Security Engineer
Information Technology Security Engineer

Midland Holdings Limited • Hong Kong

On-site
HKD 480,000 - 720,000
Security Analyst / Engineer - IC
Security Analyst / Engineer - IC

Classy Wheeler Limited • Hong Kong

On-site
HKD 50,000 - 70,000
DFIR Specialist / Senior SOC Analyst (Hong Kong)
DFIR Specialist / Senior SOC Analyst (Hong Kong)

THEOS • Hong Kong

Hybrid
HKD 600,000 - 900,000
Cybersecurity and Information Security Analyst
Cybersecurity and Information Security Analyst

Not Another Headhunting Company • Hong Kong

On-site
HKD 420,000 - 780,000
Cyber Security Operations Manager
Cyber Security Operations Manager

Classy Wheeler Limited • Hong Kong

On-site
HKD 900,000 - 1,200,000
Assistant Manager - Cyber Security Ops - Tech Risk & Security Assessment
Assistant Manager - Cyber Security Ops - Tech Risk & Security Assessment

New Galaxy Entertainment 2006 Company Limited • Hong Kong

On-site
HKD 420,000 - 700,000