Senior Analyst, Information Security (Architecture & Change)

PFCC Group

Hong Kong

On-site

HKD 180,000 - 240,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

PFCC Group in Hong Kong seeks a Senior Analyst, Information Security (Architecture & Change) to shape and implement security strategy across networks and infrastructure. You will evaluate risks, regulatory requirements, and threat landscape to propose secure, business-aligned solutions.

The role requires deep security domain knowledge, DevSecOps experience, and strong communication to partner with IT and business units. Fluent English and professional certifications are preferred.

Qualifications

  • Minimum 5 years IT experience, with at least 3 years in Information Security.
  • Strong knowledge of security tooling and architectures.
  • Experience with ISO 27001, NIST CSF, CIS controls; familiarity with PCI-DSS, GDPR, MCSL regulatory requirements.

Responsibilities

  • Assist with designing and developing the company’s security strategy to improve and maintain its security posture/maturity level.
  • Understand current security risks and threat landscape and regulatory requirements.
  • Identify new security solutions or enhancements to enable business objectives.
  • Collaborate with business units and IT to balance information security and business needs.
  • Assess network architecture designs for alignment with security architecture and best practices.
  • Stay informed on latest security technologies and vendor evaluations.
  • Plan, track and review vendor deliverables; ensure compliance with ISO27001 requirements.

Skills

Security architecture
DevSecOps
Threat intelligence

Education

Bachelor's degree in Computer Science
CISSP or CISM certification

Tools

PAM
SIEM
WAF
EDR
DLP
Email security

Job description

Senior Analyst, Information Security (Architecture & Change)

Hong Kong, Hong Kong | Posted on 09/11/2024

  • Assist with designing and developing the company’s security strategy to improve and maintain its security posture/ maturity level
  • Understand current security risks, latest regulatory requirements as well as current and future threat landscape which could impact the organization
  • Based on the risks, regulatory requirements, and threat landscape, identify new security solutions or enhancement opportunities to allow the business to continue with achieving its business objectives
  • Liaise and facilitate with business units, IT, and other Information Security function teams to provide recommended approaches to problems which balances both information security and business requirements
  • Assess network architecture designs to ensure it is aligned with security architecture and best practices
  • Remain informed on the latest security technologies in the information security industry
  • Assist with product evaluations and comparisons as part of vendor selection
  • Assist with the planning, tracking, and reviewing of vendor deliverables
  • Ensure the new security solutions or enhancement opportunities are complying to relevant compliance and regulation requirements as well as ISO27001 requirements
Requirements

Experience

  • Minimum 5 years of IT related experience, with at least 3 years in Information Security
  • Strong technical knowledge of security system architectures, especially within network and infrastructure domains are needed
  • Strong knowledge of various security tooling used for risk control such as PAM, SIEM, WAF, EDR, DLP, email security, are required
  • Experience with Security Architect or Risk Management is highly desired
  • Knowledge of implementing Security processes and tools into software development to achieve DevSecOps practices are highly desired
  • Understanding of Tactics, Techniques and Procedures commonly used by threat actors
  • Familiar with security industry frameworks e.g. ISO 27001, NIST – Cyber Security Framework, CIS
  • Familiar with compliance and regulatory requirements e.g. PCI-DSS, GDPR, MCSL
Education
  • Bachelor’s degree in Computer Science, or related disciplines
  • An information security or other similar technical certification such as Certified Information Systems Security Professional (CISSP), or Certified Information Security Manager (CISM) is highly desirable
  • Fluent in written and spoken English
  • Ability to understand and convey the relationship between Security Risks and business risks
  • Strong analytical and inter-personal skills to communicate technical information to non-technical background users
  • Proven excellence in researching, organizing, writing, and presenting technical information via report writing and presentation (PowerPoint)
  • Capacity to work independently and in a team environment, and can demonstrate leadership ability and project management skills
  • Ability to multi-task and have solid project management skills
  • Ability to keep pace with a fast pace and growing company
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

InfoSec Architecture & Change Lead
InfoSec Architecture & Change Lead

PFCC Group • Hong Kong

On-site
HKD 180,000 - 240,000
Manager / Assistant Manager, Security Services
Manager / Assistant Manager, Security Services

CITIC Telecom International CPC Limited • Hong Kong

On-site
HKD 900,000 - 1,500,000
IT Security Manager (Finance/up to 70K)
IT Security Manager (Finance/up to 70K)

Manpower Services (Hong Kong) Limited • Hong Kong Island

On-site
HKD 900,000 - 1,400,000
IT Security Analyst
IT Security Analyst

Puyi Optical • Hong Kong

On-site
HKD 420,000 - 660,000
IT Security Manager - IC
IT Security Manager - IC

Classy Wheeler Limited • Hong Kong

On-site
HKD 600,000 - 900,000
IT Security Manager / Associate Director
IT Security Manager / Associate Director

Recruit Squad Limited • Hong Kong Island

On-site
HKD 900,000 - 1,600,000
Director, Deputy Head of Information Security, IT
Director, Deputy Head of Information Security, IT

Be Myjob Company Limited • Hong Kong

On-site
HKD 900,000 - 1,500,000
Information Security Manager
Information Security Manager

PCCW Solutions • Hong Kong

On-site
HKD 850,000 - 1,350,000
Senior IT Security Analyst (Cybersecurity, Compliance) (Logistics)
Senior IT Security Analyst (Cybersecurity, Compliance) (Logistics)

Classy Wheeler Limited • Hong Kong

On-site
HKD 480,000 - 720,000
(Senior) Security Specialist - Multiple Headcounts
(Senior) Security Specialist - Multiple Headcounts

Michael Page International (Hong Kong) Limited • Hong Kong Island

On-site
HKD 400,000 - 600,000
Comprehensive benefits package
Friendly work and team culture
Growth and development opportunities