Get more replies from employers
Send a job-specific resume in minutes.
AIA Hong Kong and Macau is looking for a leader in endpoint security to own and drive their global security capabilities. This role will involve overseeing the strategy, engineering standards, and operational governance for endpoint security across various environments.
The ideal candidate will manage endpoint technologies and lead incident response initiatives. Key responsibilities include developing security product strategies, managing vendors, and ensuring compliance with security standards.
Join us to enhance AIA's security posture and contribute to a high-performing team!
Provide technical and operational leadership for AIA’s global endpoint security capability—owning the strategy, engineering standards, and day-to-day governance of EDR/AV and endpoint hardening controls across Windows, Linux, and cloud workloads.
Own and drive the global endpoint security product strategy and roadmap, covering EDR/AV, exploit mitigation, device control, host firewall, and application control.
Align endpoint security capabilities with enterprise security architecture, regulatory requirements, and business priorities.
Define and enforce governance models for policy management, exception handling, and risk acceptance, including approval workflows and periodic reviews.
Evaluate emerging threats, platform changes, and new security capabilities, recommending strategic enhancements with clear risk vs. value trade-offs.
Lead the engineering design and implementation of endpoint security controls across Microsoft Intune Group Policy Objects (GPO) Configuration management platforms.
Define and maintain standardized security baselines and hardening guidelines, including reusable configurations and gold images aligned to CIS benchmarks.
Establish controls for exception management, configuration drift monitoring, and compliance enforcement.
Expand and strengthen endpoint runtime protection and agent guardrails to enhance resilience.
Manage and optimise endpoint security technologies, including Antivirus / EDR / HIPS, device control and application control, host-based firewall and exploit protection.
Ensure effective security coverage across user endpoints, servers, and cloud workloads.
Drive agent lifecycle management—packaging, deployment, upgrades, health monitoring, and decommissioning.
Achieve and maintain >=90% deployment and compliance posture across all regions and business units.
Own and operate endpoint security as a critical ITIL-aligned service, including incident triage and escalation, problem management and root cause analysis, major incident participation, change governance and release management.
Drive continuous service improvement (CSI) initiatives to enhance service reliability, performance, and user experience.
Troubleshoot and resolve complex endpoint security issues, ensuring effective stakeholder communication.
Collaborate closely with SOC and Incident Response teams to enhance detection use cases and analytics, improve response playbooks and automation, optimise containment actions (e.g., host isolation, process termination, file quarantine), and drive improvements in Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) for endpoint-related incidents.
Lead integration of endpoint telemetry into SIEM and analytics platforms, ensuring reliable log collection pipelines, data normalization and enrichment, scalable reporting and threat analytics, and enabling data-driven visibility and reporting for leadership and operational teams.
Drive integration of endpoint platforms with adjacent security controls, including email and threat gateways (e.g., Proofpoint, Exchange Online Protection), secure web gateways and ZTNA solutions (e.g., Zscaler).
Improve end-to-end threat prevention, detection, and response capabilities across multiple security layers.
Partner with patching and vulnerability teams to drive remediation prioritisation, reduce attack surface through secure configurations, and align endpoint security posture with industry frameworks such as CIS Benchmarks and the MITRE ATT&CK framework.
Define and track service KPIs, SLAs, and compliance metrics; develop dashboards and operational reports for leadership and regional stakeholders; conduct regular service reviews to drive improvements in adoption, stability, coverage, and user experience.
Manage endpoint security vendors and managed service providers, including contract governance and performance management, roadmap influence and feature enhancements, cost optimisation; engage with regional/in-country stakeholders to ensure alignment and compliance targets are met.
Provide technical leadership, mentorship, and coaching to engineers and analysts; develop and maintain standard operating procedures (SOPs), runbooks and playbooks, knowledge base articles; build scalable capabilities to support consistent global service delivery.
Monitor industry trends, emerging threats, and technology advancements across Windows, Linux, macOS, and cloud platforms; identify and implement feature enhancements and operational improvements; drive innovation to continuously strengthen endpoint security maturity and resilience.