An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Mox Bank is seeking a Cyber Security Engineer to join the Cybersecurity team in Hong Kong. The role focuses on security engineering, automation, and maintaining internal cybersecurity tooling within CI/CD pipelines.
You will embed automated security testing, manage policy-as-code linting tools, and write scripts to reduce manual effort while ensuring tooling reliability. With 2–3+ years of experience, you will work under mentorship toward DevSecOps and platform security, building scripts in
Cyber Security Engineer Cyber Security Engineer Technology-CDSIOHong Kong (SAR)Permanent - Full TimeHong Kong (SAR)Technology-CDSIOPermanent - Full Time View all jobs
We are seeking a highly motivated Cyber Security Engineer to join the growing Cybersecurity team at Mox Bank.
In this role, you will focus on security engineering, automation, and systems maintenance. Reporting to the Senior Platform Security Engineer, you will help embed automated security testing into software pipelines, maintain policy-as-code linting tools, write scripts that reduce manual operational effort, and keep internally built cybersecurity tools running reliably.
This is a strong growth opportunity for an ambitious junior engineer with 2–3+ years of experience. With direct mentorship from senior engineering and architecture leads, the role offers a clear pathway into DevSecOps and platform security.
Writing and maintaining scripts in Python, Bash, or similar languages to automate routine security tasks and operational workflows.
Supporting security tools within CI/CD pipelines, including SAST, DAST, secrets detection, software composition analysis, and vulnerability triaging.
Working with Git, source control practices, pull requests, and basic software delivery workflows to manage internal security tooling and infrastructure code.
Foundational exposure to AWS cloud concepts, IAM roles, infrastructure-as-code, configuration drift monitoring, and cloud security hygiene.
Maintaining internal systems, documentation, dependencies, and automation solutions so that cybersecurity tooling remains reliable, current, and production-aligned.
Using automation tools, APIs, webhooks, and AI-assisted techniques responsibly to improve speed, accuracy, and operational efficiency.
Assist in the day-to-day administration and health checks of automated security tools embedded in our developer pipelines, including SAST, DAST, and Software Composition Analysis.
Monitor automated pipelines for exposed secrets, API keys, and credentials, and trigger rapid remediation when alerts occur.
Review automated scan results, help identify false positives, and guide development squads on baseline remediation steps.
Write clean, documented scripts, primarily in Python or Bash, to automate routine security checks, log aggregation, and administrative tasks.
Maintain and optimize webhook-based messaging pipelines that push critical security alerts into squad and team collaboration channels.
Monitor and review configuration scans on Infrastructure-as-Code templates to identify misconfigured cloud storage, over-privileged security groups, or unencrypted assets before they reach production.
Support the team in tracking cloud configuration drift, helping identify when manual modifications bypass our GitOps pipelines.
Manage the routine maintenance, performance health, and patching of internally built applications, scripts, and automation solutions developed by the cybersecurity engineering (CSE) squad.
Monitor and update code dependencies, libraries, and base container images for internal cyber infrastructure to prevent security vulnerabilities within our own toolset (e.g., managing Dependabot alerts for internal repos).
Maintain up-to-date documentation, deployment guides, runtime instructions, and README files for all internal systems and automated code solutions to ensure team continuity.
Ensure internal cybersecurity testing environments and infrastructure deployments match production configurations and are correctly tracked using Git version control.
Support the Senior IAM Engineer by executing routine, automated checks on cloud access roles, ensuring orphaned accounts are flagged for deletion.
Help package automated security report outputs and scanning metrics to pass to the Governance team for regulatory review.
Identify, design, and implement opportunities to replace repetitive manual security tasks, data compilation, and alert triage with scalable scripts, code, or automated playbooks.
Review workflows, handoffs, and security tooling configurations to reduce operational friction, remove system noise, and improve the effectiveness of Mox’s security stack.
Use AI, machine learning, and LLM assistants responsibly to accelerate script generation, log analysis, pattern matching, threat intelligence summaries, and draft reporting while maintaining internal data classification requirements.
Proactively look for ways to make existing processes faster, cleaner, more reliable, and less manual.
Practical comfort and developing fluency in utilizing modern AI-powered coding assistants, analytics platforms, and conversational LLMs to securely enhance technical speed, analytical accuracy, and delivery output.
Basic exposure to automation tools, APIs, webhooks, or scripting patterns that help security systems communicate and share data.