Assistant Manager - Cyber Security Ops

Galaxy Entertainment Group

Hong Kong

On-site

HKD 900,000 - 1,300,000

Full time

43 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Galaxy Entertainment Group seeks a Senior Analyst - Cyber Security Operations to lead the Security Operations Center and drive enterprise-wide cyber security controls. You will develop automated workflows, monitor incidents, and coordinate remediation across IS&T and business units in Hong Kong/Macau.

The role demands 4+ years in cybersecurity with incident response or SOC leadership, strong log analysis, and proficiency with SIEM/SOAR tools.

Qualifications

  • Bachelor's degree in a related field or equivalent experience.
  • 4+ years in cybersecurity with 2+ years in incident response or SOC management.
  • Knowledge of MITRE ATT&CK, threat intel, malware analysis, cloud security.
  • Hands-on with EDR, IDS/IPS, SIEM, and vulnerability management.
  • Strong English and Chinese communication; Cantonese/Mandarin a plus.

Responsibilities

  • Lead the SOC to monitor, handle and respond to incident alerts.
  • Lead incident response for malware, data breaches, insider threats, APTs.
  • Develop automated workflows for incident response processes.
  • Analyze logs from firewalls, endpoints, networks, cloud for threats.
  • Maintain incident response playbooks aligned with NIST.
  • Proactively hunt threats and conduct post-incident forensics.
  • Tune SIEM/SOAR use cases and onboard new log sources.
  • Provide leadership and mentor junior analysts; coordinate with vendors.

Skills

SOC leadership
Incident response
Threat hunting
Python scripting
PowerShell
Bash
Log analysis
Team coordination

Education

Bachelor's degree

Tools

EDR
IDS/IPS
SIEM
SOAR
Cloud security tools

Job description

As part of the Cyber Security Operations team within IS&T, the Senior Analyst - Cyber Security Operations plays a key role in protecting GEG's information assets. Reporting to the Assistant Vice President, this position is responsible for supporting to the development, management and implementation of enterprise-wide cyber security controls. The position will be opened to talents in Hong Kong / Macau.

PRIMARY RESPONSIBILITIES:
  • Lead the Security Operations Center (SOC) in monitoring, handling and responding to incident alerts.
  • Lead incident response activities for cybersecurity threats including malware, data breaches, insider threats, and advanced persistent threats.
  • Develop and implement automated workflows to enhance the efficiency of Cyber incident response processes.
  • Monitor, analyze, and respond to escalated security incidents and coordinate efforts with the SOC .
  • Ensure incident documentation and reporting are comprehensive and timely, for both operational review and compliance purposes.
  • Design and maintain incident response plans and playbooks in alignment with NIST and other relevant frameworks.
  • Conduct proactive threat hunting to identify unknown and emerging threats within the enterprise environment.
  • Perform forensic analysis and post-incident investigations to determine root causes and recommend remediations.
  • Develop, tune and maintain SIEM / SOAR use cases, detection rules and logic; onboard new and analyse log sources.
  • Continuously improve detection rules for alerting cyber threats and malicious activities across the corporate environment.
  • Analyze logs from firewalls, endpoints, networks, cloud, and other systems to identify threats.
  • Collaborate with IS&T, Legal, and Compliance teams to ensure cohesive incident response and reporting.
  • Recommend and implement security controls and preventive measures based on incident learnings.
  • Provide leadership and mentorship to junior analysts and coordinate with external partners.
  • Coordinate the security incident management process across IS&T teams and business units.
  • Build and maintain sustainable relationships with IS&T teams to ensure effective implementation and understanding of security controls.
  • Assist in leading the team to achieve defined goals and deliverables.
  • Assist in building and promoting the Information Security Awareness Programme.
  • Drive continuous improvements on information security controls and practices.
  • Lead and coordinate internal and external security reviews activities (e.g. Audit, Penetration Test) and follow up on identified deficiencies and ensure remediation steps have been taken.
REQUIREMENTS:
  • Bachelor's degree in computer science, computer engineering, systems analysis, or a related study, or equivalent experience.
  • 4+ years’ experience in cybersecurity, with at least 2 years focused on incident response and threat hunting and or in Security Operations Center management.
  • Knowledge of threat intelligence, malware analysis, network and cloud security, MITRE ATT&CK, and cyber kill chain methodologies.
  • Hands-on proficiency with forensic tools, endpoint detection & response (EDR), intrusion detection/prevention systems (IDS/IPS), and vulnerability management solutions.
  • Familiarity with cloud security (AWS, Azure, GCP), container security, WAFs, and proxies, is an advantage.
  • Demonstrated experience in managing response and remediation for high-impact incidents, ideally in a multi-location and/or hybrid cloud environment, would be an advantage.
  • Excellent written and verbal communication skills, with strong incident reporting capabilities in English and Chinese. Cantonese and/or Mandarin proficiency is an advantage.
  • Strong scripting and automation capabilities (Python, PowerShell, Bash) is an advantage.
  • Good leadership skills, and strong planning and organizational skills.
  • Strong interpersonal skills, including teamwork, facilitation and negotiation.
  • Strong analytical and technical skills, and ability to translate business needs into technical requirements.
  • Good ability to tactfully and positively manage and maintain business relationships.
  • Advanced experience and skills on administration of SIEM in terms of log collection, detection rules optimization, threat hunting, incident case reporting and dashboards creation. Including developing detection use cases and managing escalated incidents.
  • CISSP or CISM or GCIH or CEH is required; CRISC or CISA certifications is a plus.
  • Ability to work under pressure and react quickly to critical cybersecurity incidents.
  • Commitment to continuous learning in threat detection, offensive/defensive tactics, and evolving incident response methodologies.
  • Experience in collaborating with SOC or third-party security vendors.
Get your free, confidential resume review.
or drag and drop your file here.