Shanghai Commercial Bank Ltd is seeking a Security Analyst in Hong Kong to monitor and analyze security events and logs. Responsibilities include identifying potential threats, conducting vulnerability assessments, and supporting security audits. The ideal candidate should hold a Bachelor's degree in Computer Science or a related field with at least 5 years of experience in information security, preferably in banking or regulated environments. Certifications like CISSP or CISM are preferred. The position offers a full-time opportunity.
Qualifications
Degree holder in Computer Science, Information Systems, or related disciplines.
Minimum 5 years of experience in information security, preferably in banking or regulated environments.
Hands-on experience with vulnerability scanning and log analysis.
Responsibilities
Monitor and analyze security events and logs.
Track emerging cybersecurity threats and security technologies.
Conduct regular vulnerability scanning and security assessments.
Skills
Information security
Vulnerability scanning
Penetration testing
Log analysis
Network protocols
Security devices
Analytical skills
Communication skills
Education
Bachelor's degree in Computer Science or related disciplines
Tools
SIEM
EDR
Firewalls
Job description
Responsibilities:
Monitor and analyze security events and logs, promptly identify potential threats or attacks, and coordinate timely response actions.
Track emerging cybersecurity threats, vulnerabilities, and security technologies to continuously enhance the Bank’s security posture.
Conduct regular vulnerability scanning, penetration testing, source code scanning, and security assessments to identify weaknesses and drive remediation.
Support internal and external security audits, compliance checks, and regulatory assessments.
Assist in maintaining and improving security monitoring operations, including SIEM, EDR, and firewall rule management.
Perform other duties and responsibilities as assigned by the IT Security team.
Requirements:
Degree holder in Computer Science, Information Systems, or related disciplines.
Minimum 5 years of experience in information security, preferably in banking, financial services, or regulated environments.
Hands-on experience with vulnerability scanning, log analysis, penetration testing, and monitoring operations.
Solid knowledge of mainstream operating systems (Windows, Linux, AIX), network protocols, and common security devices (IPS, WAF, firewalls, EDR, SIEM).
Security certifications such as CISSP, CISM, CISA, GPEN, or CEH are preferred.
Strong analytical skills, good communication abilities, and a collaborative teamwork spirit.
Candidates with less experience may be considered for Assistant Manager.