Security Engineer

Morgan Mckinley Limited

Hong Kong

On-site

HKD 900,000 - 1,500,000

Full time

13 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Morgan McKinley Limited in Hong Kong is seeking an experienced information security professional to shape the security roadmap, enforce policies, and manage vendors and budgets. The role covers EDR/antivirus, threat hunting, and incident response, as well as firewalls, IDS/IPS, WAF, and access controls.

You will lead vulnerability management, DLP, PAM, and high-risk account auditing. With hands-on experience, you will coordinate penetration testing and risk reporting for IT management and

Qualifications

  • Bachelor's degree in Computer Science, IT Security, or related field with hands-on information security experience.
  • Financial services, insurance, or regulated industry experience preferred.
  • CISSP, CISM, OSCP, or equivalent is a strong advantage.
  • Proven experience conducting end-to-end pen tests for web, mobile, Active Directory, and internal networks.
  • Solid understanding of OWASP Top 10, logic flaws, and privilege escalation.
  • Working knowledge of SIEM, EDR, PAM, WAF, IDS/IPS, and honeypots.

Responsibilities

  • Assist in shaping the security roadmap, enforce security policies and regulatory compliance, and help manage security vendors, budgets, and tool selection.
  • Manage EDR/antivirus tools, threat hunting, and incident response.
  • Oversee firewalls, IDS/IPS, WAF, network segmentation, and access controls.
  • Lead vulnerability scans, patch management, and system hardening.
  • Enforce DLP, data classification, and access monitoring.
  • Support PAM implementation, manage bastion hosts and account lifecycles, and audit high-risk administrative activity.
  • Coordinate and perform penetration tests and vulnerability assessments, documenting remediation steps for key stakeholders.
  • Create security metrics, risk assessments, and technical reports for IT management and business leaders.

Skills

Analytical thinking
Stakeholder management
Cross-team collaboration
Continuous learning

Education

Bachelor's degree in Computer Science/IT Security or related field

Tools

Burp Suite
Nmap
Nessus/AWVS
Metasploit
Cobalt Strike
SIEM
EDR
PAM
WAF
IDS/IPS
Honeypots

Job description

Assist in shaping the security roadmap, enforce security policies and regulatory compliance, and help manage security vendors, budgets, and tool selection.

Manage EDR/antivirus tools, threat hunting, and incident response.

Oversee firewalls, IDS/IPS, WAF, network segmentation, and access controls.

Lead vulnerability scans, patch management, and system hardening.

Enforce DLP, data classification, and access monitoring.

Support PAM implementation, manage bastion hosts and account lifecycles, and audit high-risk administrative activity.

Coordinate and perform penetration tests and vulnerability assessments, documenting remediation steps for key stakeholders.

Create security metrics, risk assessments, and technical reports for IT management and business leaders.

Qualifications:

Bachelor's degree in Computer Science, IT Security, or related field with at least 4 years of hands-on information security experience.

Financial services, insurance, or regulated industry experience preferred.

CISSP, CISM, OSCP, or equivalent is a strong advantage.

Proven experience conducting end-to-end pen tests for web, mobile, Active Directory, and internal networks.

Solid understanding of common flaws like OWASP Top 10, logic flaws, and privilege escalation.

Proficiency with security tools including Burp Suite, Nmap, Nessus/AWVS, Metasploit, and Cobalt Strike.

Working knowledge of SIEM, EDR, PAM, WAF, IDS/IPS, and honeypots.

Strong analytical problem-solving, stakeholder management, cross-team collaboration, and continuous learning abilities.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

Tenth Revolution Group • Hong Kong

On-site
HKD 300,000 - 450,000
Penetration Tester
Penetration Tester

Centurion Information Security • Hong Kong

On-site
HKD 350,000 - 550,000
Security Engineer (Data & Endpoint Security)
Security Engineer (Data & Endpoint Security)

OKX • Hong Kong

On-site
HKD 400,000 - 600,000
Competitive total compensation package
L&D programs and education subsidy
Team building programs
+2
Senior Cyber Security Engineer (Finance) - IC
Senior Cyber Security Engineer (Finance) - IC

Classy Wheeler Limited • Hong Kong

On-site
HKD 800,000 - 1,000,000
IT Security Operations Manager - IC
IT Security Operations Manager - IC

Classy Wheeler Limited • Hong Kong

On-site
HKD 700,000 - 900,000
Senior Security Engineer, Analytics and Engineering
Senior Security Engineer, Analytics and Engineering

Jobtailor • Hong Kong

On-site
HKD 700,000 - 1,000,000
Senior Information Security Specialist
Senior Information Security Specialist

Michael Page International (Hong Kong) Limited • Hong Kong Island

On-site
Opportunity to work in a large organization
Prime location in the Central District
Chance to contribute to significant technology initiatives
Security Engineer – Tier 1 Buyside Firm
Security Engineer – Tier 1 Buyside Firm

Ashford Benjamin Ltd. • Hong Kong

On-site
HKD 600,000 - 900,000
Complimentary breakfast
Lunch provided
Gym reimbursement
+5
Manager - Cyber-Security (Application)
Manager - Cyber-Security (Application)

Classy Wheeler Limited • Hong Kong

On-site
HKD 600,000 - 900,000
Assistant Network Engineer
Assistant Network Engineer

HKT • Hong Kong

On-site
HKD 300,000 - 420,000