A technology firm in Hong Kong is seeking an Application Security Evangelist responsible for integrating security into development practices. The ideal candidate will have over 5 years of experience in IT Application security, strong knowledge of cyber security controls, and proficiency in various frameworks. Key skills include leadership and communication. Knowledge in the fintech sector is preferred, along with a command of English and Chinese. Professional qualifications like CISM or CISSP are mandatory.
Qualifications
Over 5 years' experience in IT Application security and risk management area.
Strong technical or security skills related to IT applications and infrastructure.
Good command of both spoken and written English and Chinese; Mandarin is an advantage.
Possess at least two professional qualifications such as CISM, CISA, CISSP.
Responsibilities
Translate security concepts for developers and improve secure development standards.
Integrate security tools and processes into the Software Development Life Cycle.
Support incident response and architecture review processes.
Conduct application security design reviews.
Skills
Application security expertise
Risk management experience
Cyber security controls knowledge
Leadership skills
Communication skills
Analytical skills
Self-motivation
Technical skills in IT applications
Education
University degree in Computer Science or related disciplines
Job description
Responsibilities
Being an Application Security Evangelist who translates security concepts for developers
Improving and maintaining secure development standards and managing application security framework improvement projects
Integrating security tools, standards and processes into the Software Development Life Cycle (SDLC)
Ensuring that developers are trained with the appropriate level of security knowledge to perform their daily activities
Improving and supporting application security tool deployments including static analysis and runtime testing tools
Producing metrics reporting the state of application security programs and performance of development teams against requirements
Supporting Vendor Security activities to ensure third party software and development meets security standards
Supporting the incident response and architecture review processes whenever application security expertise is needed
Holding third party’s accountable for code quality
Integrating threat modeling practices into the product life cycle
Conducting application security design reviews and prioritise all application security issues
Providing security requirements for test‑driven design
Partnering with third parties to provide penetration testing services
Job Requirements
University degree in Computer Science or related disciplines
Over 5 years’ experience in IT Application security and risk management area
Strong technical or security skills related to IT applications and infrastructure; solid experience in cyber security controls and incident handling
Good knowledge in Companying environment
Knowledge and experience in Fintech is desirable
Strong knowledge of Companying regulations/guidelines relating to cyber security and technology risk management
Strong self‑motivation, with good leadership, communication, interpersonal and analytical skills
Great sense of ownership and servicing mindset
Good command of both spoken and written English and Chinese; Mandarin is an advantage
Possess at least two of the professional qualifications such as CISM, CISA, CISSP, CEH, GWAPT, GPEN and OSCP
Experienced in web and mobile application development/penetration testing preferred
Experienced in performing security risk assessment and audits based on industry standards
Familiar with various cybersecurity related frameworks such as ISO 27001 ISMS, CIS CSC (CIS Critical Security Controls) and NIST Cyber Security Framework