Senior Security Platform Engineer – Cybersecurity
Application Deadline: 24 August 2026
Department: Technology-CDSIO
Employment Type: Permanent - Full Time
Location: Hong Kong (SAR)
Job Description
We are seeking a highly skilled Senior Security Platform Engineer to join our growing Cybersecurity team at Mox Bank.
In this role, you will act as a key architect and a lead within our Architecture, Cloud & Identity Foundations pillar. You will build the "Security Platform"—a suite of automated services, APIs, and guardrails that allow our engineering squads to build and deploy at speed, securely. You will sit at the intersection of DevSecOps, Identity (IAM/PAM), and Cloud Security.
You will provide technical leadership to the DevSecOps squad, have an Agile mindset with a keen interest in DevOps engineering across a range of technologies, while showcasing solid communication and team-player qualities.
Technical Experience
- AWS Cloud technologies and architecture patterns
- Solid understanding of continuous deployment and delivery (CI/CD) tools
- Experience with Source Control and SDLC tools and Python scripting
- Experience with zero‑trust architecture and Identity Security
Responsibilities
- Security Platform Architecture: Design, build, and maintain our enterprise‑wide security‑as‑code platform. Develop and maintain "Golden Modules" that empower developers to provision cloud resources that are secure by default.
- DevSecOps & Pipeline Integration: Architect security hooks within our CI/CD pipelines. Automate static and dynamic analysis and secret scanning to ensure rapid, actionable feedback loops.
- IAM & PAM Governance: Implement modern identity patterns. Shift the organization from static credentials to dynamic, ephemerally, and Just‑in‑Time access models.
- Cloud Infrastructure Security: Lead deployment and optimization of Cloud Security Posture Management and Container Security solutions to detect and automatically remediate configuration drift across multi‑cloud environments.
- Security Advocacy & Developer Experience: Bridge Cybersecurity and Engineering. Reduce false‑positive fatigue and foster a security‑by‑design culture.
Key Qualifications
- 10+ years of experience in Software Engineering, Infrastructure Engineering, or Cybersecurity, with at least 4 years focused specifically on Cloud Security or DevSecOps.
- Expert‑level AWS cloud architecture and fully automated CI/CD pipeline design, including core services (EC2, RDS, S3, IAM, KMS, API Gateway, Lambda).
- Deep technical understanding of OIDC, SAML, OAuth2, and modern PAM.
- Extensive Infrastructure‑as‑Code proficiency (Terraform, CloudFormation) with experience in modular "Golden Module" development and drift detection.
- Production‑grade software engineering skills in Python, Go, or Java for security tooling and API development.
- Strong experience securing containerized workloads and orchestrators (Kubernetes, Docker, Service Mesh).
- Experience with Cloud Security Tools (CloudTrail, CloudWatch, GuardDuty, Security Hub, AWS Config).
- Windows and Linux Server Administration experience.
- Strong leadership, mentoring, and senior stakeholder engagement skills.
- DevOps passion for automation and innovation.
- Passion for developing fit‑for‑purpose solution designs, coaching, and technology teams.
Requirements
- Previous experience in Cybersecurity engineering, Cloud security.
- Bachelor’s degree in computer science, Software Engineering, Cybersecurity or related field.
- Professional certifications such as CKS, AWS/Azure Security Specialty, AWS Solution Architect, or CISSP.
- Ability to distill complex security architecture into clear guidance for non‑security peers.
- Self‑starter comfortable operating in an agile, high‑growth environment.
- Experience with Vulnerability Management tooling or patching.
- Experience with SIEM solutions.
- Experience with PAM solutions.
- Experience with container intrusion detection tools.
- Exposure to these tool areas, though not mandatory, is highly preferable.