The Job
1、Provide professional security advisory service to customers by designing and proposing security solutions meeting customer's objectives
2、Understand customer's IT challenges and security requirements; and provide suggestions and comments to development team from technical and pre-sales perspectives of information security
3、Directs an ongoing, proactive risk assessment program for all new and existing systems and business processes; communicates risks and recommendations to mitigate risks to the senior management in term of non-technical and cost/benefit for decision making
4、Ensures vulnerabilities are managed by directing periodic vulnerability scans of servers connected to Company's networks; and support other department to ensure regulatory compliance in areas of ISO 27001 and PCI DSS
5、Evaluates security incidents and determines what response, if any, is needed and coordinates Company's responses when sensitive information is breached
6、Assist and conduct security risk assessment & audit for both internal and customers
The Person
1、Degree holder or above in Computer Science / Information Technology or related disciplines, or with qualification equivalent to Level 5 of Hong Kong Qualifications Framework (QF)
2、4-5 years of varied information technology experience on computer and networking infrastructure, operating systems, application software development, project management, regulatory compliance, and risk management
3、Good knowledge and experience in security planning and design with different technologies / solution
4、Professional certification (CISSP, CCSK, CCSP, CISA, CISM, etc.) is preferred
5、At least one of the CISSP, ISO/IEC27001 LA, CISM and CEH
6、Effective verbal and written communication skills and proficiency in writing technical specifications are required
7、Proficient in written and spoken English and Chinese
8、Creatively and critical thinking, responsible
9、Office: 27/F, Tower1, The Millennity, 98 How Ming Street, Kwun Tong, Kowloon, Hongkong
--------------------------------------------------------------------------------------------
主要職責
1、透過設計和提出滿足客戶目標的安全解決方案,為客戶提供專業(yè)的安全諮詢服務
2、了解客戶的 IT 挑戰(zhàn)和安全需求,並從資訊安全的技術和售前角度向開發(fā)團隊提供建議和意見
3、指導對所有系統(tǒng)及業(yè)務流程進行持續(xù)、積極主動的風險評估;以非技術性和成本效益分析的方式,向高階管理層傳達風險及風險緩解建議,以供決策參考
4、透過定期對連接到公司網(wǎng)路的伺服器進行漏洞掃描,確保漏洞得到有效管理;並支援其他部門確保符合 ISO 27001 和 PCI DSS 等監(jiān)管要求
5、評估安全事件,確定是否需要採取應對措施以及採取何種措施,並就敏感資訊外洩問題協(xié)調(diào)公司的應對措施
6、協(xié)助並進行內(nèi)部和客戶的安全風險評估和審計
任職要求
1、持有電腦科學/資訊科技或相關學科的學位或以上學歷,或具備相當於香港學歷框架(QF)第5級的資格
2、擁有4-5 年電腦和網(wǎng)路基礎設施、作業(yè)系統(tǒng)、應用軟體開發(fā)、專案管理、合規(guī)性和風險管理等方面的豐富資訊技術經(jīng)驗
3、具備良好的安全規(guī)劃與設計知識與經(jīng)驗,熟悉各種技術/解決方案
4、擁有專業(yè)認證CISSP、CCSK、CCSP、CISA、CISM 等將獲優(yōu)先考慮
5、至少持有 CISSP、ISO/IEC27001 LA、CISM 和 CEH 其中的一項認證
6、需要具備良好的溝通能力以及編寫技術規(guī)範的熟練程度
7、流利的英語和中文的聽說讀寫能力
8、具備創(chuàng)造性和批判性思維,有責任心
9、經(jīng)驗較少的候選人將被考慮擔任安全分析師
10、 工作地點﹕香港觀塘區(qū)巧明街98號1座27樓