Manager, Information Security

Dah Sing Financial Group

Hong Kong

On-site

HKD 500,000 - 700,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Dah Sing Financial Group seeks an experienced cybersecurity professional to support MSSP operations, perform security assurance tasks, and participate in purple team exercises in a regulated banking environment.

You will gain hands-on exposure to security monitoring, control testing, and threat validation while collaborating with internal teams across IT and risk functions. Banking experience and HKMA ECF certifications are a plus.

Qualifications

  • Bachelor’s degree in Information Security, Computer Science, or related discipline.
  • 3-5 years of experience in cybersecurity, SOC, IT operations, or risk/compliance.
  • Basic understanding of SIEM, EDR, network security, and common attack techniques.
  • Familiarity with security frameworks (NIST CSF, ISO 27001, OWASP) is an advantage.
  • Experience in banking or finance sectors is a plus.
  • Possession of HKMA ECF certifications in cybersecurity.

Responsibilities

  • Monitor MSSP alerts and escalations, ensuring timely follow up with internal teams.
  • Perform initial triage security events under supervision.
  • Assist in maintaining SIEM/EDR use cases and updating detection rules.
  • Prepare MSSP performance summaries and KPI reports.
  • Support control testing activities across EDR, network security, and application security.
  • Collect evidence from system owners and validate completeness and accuracy.
  • Assist in documenting test results, findings, and remediation tracking.
  • Help maintain assurance documentation, checklists, and compliance records.
  • Participate in purple team exercises by documenting attack steps, detection results, and gaps.
  • Assist in mapping detection coverage to MITRE ATT&CK techniques.
  • Update detection logic and playbooks based on purple team outcomes.
  • Lead the end to end vulnerability management lifecycle: discovery, validation, risk rating, tracking, and closure.
  • Conduct proactive threat hunting exercises to identify and mitigate advanced persistent threats (APTs) and other sophisticated attack vectors.
  • Ability to conduct attack simulations (e.g., Metasploit, Cobalt strike) to validate detection coverage.

Skills

SIEM
EDR
Network security
Threat hunting
MITRE ATT&CK

Education

Bachelor’s degree in Information Security

Tools

Metasploit
Cobalt Strike

Job description

Support the bank’s cyber defence functions by assisting with MSSP operations, performing security assurance tasks, and participating in purple team exercises. This role provides hands on exposure to security monitoring, control testing, and threat based validation activities in a regulated banking environment.

Key Responsibilities

Monitor MSSP alerts and escalations, ensuring timely follow up with internal teams.

Perform initial triage security events under supervision.

Assist in maintaining SIEM/EDR use cases and updating detection rules.

Prepare MSSP performance summaries and KPI reports.

Support control testing activities across EDR, network security, and application security.

Collect evidence from system owners and validate completeness and accuracy.

Assist in documenting test results, findings, and remediation tracking.

Help maintain assurance documentation, checklists, and compliance records.

Participate in purple team exercises by documenting attack steps, detection results, and gaps.

Assist in mapping detection coverage to MITRE ATT&CK techniques.

Update detection logic and playbooks based on purple team outcomes.

Lead the end to end vulnerability management lifecycle: discovery, validation, risk rating, tracking, and closure.

Conduct proactive threat hunting exercises to identify and mitigate advanced persistent threats (APTs) and other sophisticated attack vectors.

Ability to conduct attack simulations (e.g., Metasploit, Cobalt strike) to validate detection coverage.

Qualifications & Experience

Bachelor’s degree in Information Security, Computer Science, or related discipline.

3-5 years of experience in cybersecurity, SOC, IT operations, or risk/compliance.

Basic understanding of SIEM, EDR, network security, and common attack techniques.

Familiarity with security frameworks (NIST CSF, ISO 27001, OWASP) is an advantage.

Experience in banking or finance sectors is a plus

Possession of relevant of HKMA ECF certifications in cybersecurity.

Please note that only shortlisted candidates will be notified.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

InfoSec Analyst: Threat Detection & Purple Team
InfoSec Analyst: Threat Detection & Purple Team

Dah Sing Financial Group • Hong Kong

On-site
HKD 500,000 - 700,000
IT Security Manager (Finance/up to 70K)
IT Security Manager (Finance/up to 70K)

Manpower Services (Hong Kong) Limited • Hong Kong Island

On-site
HKD 900,000 - 1,400,000
HK Senior Detection and Response Engineer
HK Senior Detection and Response Engineer

Sopra Steria • Hong Kong

Hybrid
HKD 900,000 - 1,200,000
Hybrid working mode
Work-from-Abroad benefits
Annual bonus
+1
IT Security Manager (banking) (Finance/up to 70K)
IT Security Manager (banking) (Finance/up to 70K)

Manpower Services (Hong Kong) Limited • Hong Kong Island

On-site
HKD 469,000 - 781,000
IT Security Engineer - Financial Services
IT Security Engineer - Financial Services

Ikas International (Asia) Limited • Hong Kong

On-site
HKD 480,000 - 720,000
Cybersecurity Manager (Technical Controls, Infrastructure Security) (Bank)
Cybersecurity Manager (Technical Controls, Infrastructure Security) (Bank)

Classy Wheeler Limited • Hong Kong

On-site
HKD 800,000 - 1,200,000
Assistant Vice President, Cybersecurity
Assistant Vice President, Cybersecurity

Randstad Hong Kong Limited • Hong Kong

On-site
HKD 1,100,000 - 1,800,000
IT Security Analyst
IT Security Analyst

Puyi Optical • Hong Kong

On-site
HKD 420,000 - 660,000
Technology Risk Manager (Information Security Control Division)
Technology Risk Manager (Information Security Control Division)

Bank of China (Hong Kong) • Hong Kong

On-site
HKD 700,000 - 1,000,000
Assistant Vice President, Cybersecurity, Security & Architecture Group (HK)
Assistant Vice President, Cybersecurity, Security & Architecture Group (HK)

SMBC Group • Hong Kong

On-site
HKD 900,000 - 1,300,000