About the Role
Senior Security Platform Engineer
Location: Hong Kong (SAR)
Application Deadline: 24 August 2026
We are looking for a highly skilled engineer to join our Cybersecurity team and act as a key architect and lead within our Architecture, Cloud & Identity Foundations pillar. You will build the Security Platform—a suite of automated services, APIs, and guardrails that allow our engineering squads to build and deploy at speed, securely. You will sit at the intersection of DevSecOps, Identity (IAM/PAM), and Cloud Security.
Responsibilities
- Security Platform Architecture: Design, build, and maintain our enterprise‑wide security‑as‑code platform. Develop and maintain “Golden Modules” (Infrastructure‑as‑Code) that empower developers to provision cloud resources that are secure by default.
- DevSecOps & Pipeline Integration: Architect security hooks within our CI/CD pipelines. Automate static and dynamic analysis (SAST/DAST) and secret scanning to ensure rapid, actionable feedback loops for development squads.
- IAM & PAM Governance: Architect and implement modern identity patterns. Shift the organization from static credentials to dynamic, ephemerally-driven and Just‑in‑Time (JIT) access models for both human and machine identities (Workload Identity).
- Cloud Infrastructure Security: Lead the deployment and optimization of Cloud Security Posture Management (CSPM) and Container Security solutions to detect and automatically remediate configuration drift across our multi‑cloud environment.
- Security Advocacy & Developer Experience: Act as a strategic bridge between Cybersecurity and Engineering. Troubleshoot deployment bottlenecks, reduce false‑positive fatigue, and lead the charge in fostering a “security‑by‑design” culture.
Qualifications
- 10+ years of experience in Software Engineering, Infrastructure Engineering, or Cybersecurity, with at least 4 years focused specifically on Cloud Security or DevSecOps.
- Expert‑level AWS cloud architecture and fully automated CI/CD pipeline design, including core services (EC2, RDS, S3, IAM, KMS, API Gateway, Lambda).
- Deep technical understanding of OIDC, SAML, OAuth2, and modern Privileged Access Management (PAM) architectures.
- Extensive Infrastructure‑as‑Code proficiency (Terraform, CloudFormation) with demonstrated experience in modular “Golden Module” development and drift detection.
- Production‑grade software engineering skills in Python, Go, or Java for security tooling and API development.
- Strong experience securing containerized workloads and orchestrators (Kubernetes, Docker, Service Mesh). Experience configuring, upgrading, monitoring K8S clusters, and debugging workload issues.
- Experience with Cloud Security Tools like CloudTrail, CloudWatch, GuardDuty, Security Hub, AWS Config.
- Experience with Windows and Linux server administration.
- Strong leadership, mentoring, and senior stakeholder engagement skills.
- True DevOps passion for automation and innovation, problem‑solving, and developing fit‑for‑purpose solution designs.
Requirements
- Previous experience in Cybersecurity engineering, Cloud security.
- Bachelor’s degree in computer science, Software Engineering, Cybersecurity, or a related technical field, or equivalent practical experience.
- Professional certifications such as CKS (Certified Kubernetes Security Specialist), AWS/Azure Security Specialty, AWS Solution Architect, or CISSP.
- Ability to distill complex security architecture into clear, actionable guidance for non‑security peers.
- Self‑starter comfortable operating in an agile, high‑growth environment where priorities evolve rapidly.
- Experience with vulnerability management tooling or general vulnerability management and patching.
- Experience with SIEM solutions.
- Experience with Privileged Access Management (PAM) solutions.
- Experience with Container Intrusion Detection tools.
- Exposure to the areas these tools address is highly preferable.
All personal data provided by applicants will be used for recruitment and other employment‑related purposes only. Personal data of unsuccessful applicants will be erased within 24 months of rejection of the applicant’s application.