Cyber Defence Lead

Hong Kong Executive Search

Hong Kong

On-site

HKD 900,000 - 1,200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Hong Kong Executive Search is seeking a senior information & cyber security professional for a banking/finance-focused role. The candidate will lead incidents, monitor threats, and drive incident response playbooks with collaboration from SOC and external investigators when needed.

The role requires deep knowledge of MITRE ATT&CK, malware analysis, forensics, and strong experience with Splunk ES to detect and respond to security events.

Qualifications

  • At least 7 years of experience in information & information security in banking/finance or security consulting.
  • Solid understanding of incident response, threat modeling and ATT&CK techniques.
  • Hands-on experience with Splunk Enterprise Security, analyzing security logs & network traffic.
  • Experience in malware analysis, digital forensics and response techniques.
  • Knowledge of network, desktop and server technologies, IDS/IPS.
  • Degree holder in Computer Science or related field.
  • Relevant certifications in information security (CISSP, CISA or CISM).

Responsibilities

  • Anomalies activity and cyber incident detection.
  • Manage the anomalies activity detecting process.
  • Assess the monitoring needs and define the monitoring scope and approach.
  • Work closely with Security Operation Center to ensure monitoring processes are effective.
  • Oversight and monitor activities performed by the Security Operation Center.
  • Monitor security events to ensure proper handling.
  • Respond to security events escalated from SOC and coordinate investigations.
  • Develop security metrics to monitor and report on the bank's security posture.

Skills

Incident response
Threat modeling
Threat hunting
MITRE ATT&CK
Digital forensics
Network security

Education

Bachelor in Computer Science
CISSP/CISA/CISM

Tools

Splunk Enterprise Security
IDS/IPS

Job description

  • Improve security incident response capability.
Responsibilities

Anomalies activity and cyber incident detection

  • Manage the anomalies activity detecting process.
  • Assess the monitoring needs and define the monitoring scope and approach.
  • Work closely with Security Operation Center to ensure that the monitoring process are effective.
  • Oversight and monitor on the activities performed by the Security Operation Center.
  • Monitor security events reported to ensure that all events are properly handled.
  • Response to security events escalated from the Security Operation Center and work with the relevant parties to investigate and response when needed.
  • Develop relevant information security metrics to monitor the banks information security posture and translate it into meaningful insights for the senior management.

Cyber incident response and management

  • Manage security incident and develop response plan and playbooks for various attacks and security events.
  • Oversight and monitor security incidents to ensure that all incidents identified are managed according to the incident management procedure and response plans.
  • Ensure escalation and reporting process are in place and followed.
  • Perform analysis to assess incident impact and determine whether the involvement of external investigators or forensic analysis are required to support incident investigation.
  • Work with external investigators on forensic analysis during cyber and information security incidents.
  • Drive the banks regular incident response drills exercise in responding to cyber and information security incidents.

Threat monitoring and analysis

  • Monitor threat intelligence from various sources to discover emerging cyber threats affecting the bank and customers.
  • Perform threat analysis and to identify potential security controls or remediation and other security improvement in response to the threats.
  • Perform threat hunting, leveraging available indicators of compromise, to identify potential threats that are lurking undetected.
  • Threat intelligence sharing and to collaborate with 3rd parties and industry peers.
  • Manage the threat and vulnerability management program.
Requirements
  • At least 7 years of experience in information & cyber security from either the banking and finance industry or security consulting with primary focus on Incident Response or Intrusion Detection.
  • Solid understanding of incident response, threat modeling and common attack vectors, adversary tactics, techniques & procedure, MITRE ATT&CK framework.
  • Hands on experiencein using Splunk Enterprise Security, analyzing security log & network traffic, identifying, and investigating security incidents.
  • Prior experience in malware analysis, virus exploitation and mitigation techniques, and digital forensic.
  • Understanding of network, desktop and server technologies, network intrusion methods, network containment, segregation techniques, IDS and IPS.
  • Degree holder major in Computer Science or related field.
  • Relevant certification in information security (e.g., CISSP, CISA or CISM etc.)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Incident Responder
Cyber Security Incident Responder

We+ Asia • Hong Kong

On-site
HKD 1,104,000 - 1,472,000
Cyber Defense Lead: Incident Response & Threat Intel
Cyber Defense Lead: Incident Response & Threat Intel

Hong Kong Executive Search • Hong Kong

On-site
HKD 900,000 - 1,200,000
HK Senior Detection and Response Engineer
HK Senior Detection and Response Engineer

Sopra Steria • Hong Kong

Hybrid
HKD 900,000 - 1,200,000
Hybrid working mode
Work-from-Abroad benefits
Annual bonus
+1
IT Security Operations Manager - IC
IT Security Operations Manager - IC

Classy Wheeler Limited • Hong Kong

On-site
HKD 700,000 - 900,000
Senior Cyber Security Engineer (Finance) - IC
Senior Cyber Security Engineer (Finance) - IC

Classy Wheeler Limited • Hong Kong

On-site
HKD 800,000 - 1,000,000
Senior Security Engineer, Analytics and Engineering
Senior Security Engineer, Analytics and Engineering

Jobtailor • Hong Kong

On-site
HKD 700,000 - 1,000,000
Solution Consultant
Solution Consultant

Millennium Technology Services • Hong Kong

On-site
HKD 900,000 - 1,500,000
(Senior) Cybersecurity Specialist - IC
(Senior) Cybersecurity Specialist - IC

Classy Wheeler Limited • Hong Kong

On-site
Cyber Security (Threat Intelligence/Hunting) Senior Analyst [HK Based Role]
Cyber Security (Threat Intelligence/Hunting) Senior Analyst [HK Based Role]

Sands China • Hong Kong

On-site
HKD 900,000 - 1,500,000
Assistant Manager (Cybersecurity) (Internal) - IC
Assistant Manager (Cybersecurity) (Internal) - IC

Classy Wheeler Limited • Hong Kong

On-site
HKD 600,000 - 800,000