Get more replies from employers
Send a job-specific resume in minutes.
Dah Sing Financial Group seeks an experienced cybersecurity professional to support MSSP operations, perform security assurance tasks, and participate in purple team exercises in a regulated banking environment.
You will gain hands-on exposure to security monitoring, control testing, and threat validation while collaborating with internal teams across IT and risk functions. Banking experience and HKMA ECF certifications are a plus.
Support the bank’s cyber defence functions by assisting with MSSP operations, performing security assurance tasks, and participating in purple team exercises. This role provides hands on exposure to security monitoring, control testing, and threat based validation activities in a regulated banking environment.
Monitor MSSP alerts and escalations, ensuring timely follow up with internal teams.
Perform initial triage security events under supervision.
Assist in maintaining SIEM/EDR use cases and updating detection rules.
Prepare MSSP performance summaries and KPI reports.
Support control testing activities across EDR, network security, and application security.
Collect evidence from system owners and validate completeness and accuracy.
Assist in documenting test results, findings, and remediation tracking.
Help maintain assurance documentation, checklists, and compliance records.
Participate in purple team exercises by documenting attack steps, detection results, and gaps.
Assist in mapping detection coverage to MITRE ATT&CK techniques.
Update detection logic and playbooks based on purple team outcomes.
Lead the end to end vulnerability management lifecycle: discovery, validation, risk rating, tracking, and closure.
Conduct proactive threat hunting exercises to identify and mitigate advanced persistent threats (APTs) and other sophisticated attack vectors.
Ability to conduct attack simulations (e.g., Metasploit, Cobalt strike) to validate detection coverage.
Bachelor’s degree in Information Security, Computer Science, or related discipline.
3-5 years of experience in cybersecurity, SOC, IT operations, or risk/compliance.
Basic understanding of SIEM, EDR, network security, and common attack techniques.
Familiarity with security frameworks (NIST CSF, ISO 27001, OWASP) is an advantage.
Experience in banking or finance sectors is a plus
Possession of relevant of HKMA ECF certifications in cybersecurity.
Please note that only shortlisted candidates will be notified.