Job Responsibilities:
- Architecture Planning & Implementation: Design and optimize the bank-wide information security technical architecture, including defense-in-depth strategies and cybersecurity defense systems. Review security solutions for new systems and major change projects to ensure alignment with business system development. Conduct periodic assessments of existing security architecture, identify vulnerabilities, and lead implementation of hardening roadmaps.
- AI Security Operations Tool Design & Enablement: Research and implement AI/LLM applications in security operations (e.g., PoC, scenario-based solutions). Develop automated tools for log parsing, risk analysis, compliance verification, and operational efficiency optimization. Lead AI-driven initiatives (e.g., intelligent alert classification, security rule streamlining, sensitive data identification).
- Security Governance, Compliance & Audit: Maintain and enhance the bank’s information security management system (policies, standards, SOPs). Conduct system security compliance checks, data protection assessments, and collaborate with Risk/Audit departments. Develop remediation plans for vulnerabilities, internal control gaps, and audit findings, ensuring full resolution.
- Daily Security Operations & Incident Response: Monitor and analyze the bank’s cybersecurity/data security posture (e.g., correlation analysis, attack path tracing).Lead incident response, cyber drills, and post-incident reviews (PIR) for major security events. Continuously improve security monitoring capabilities and threat detection frameworks.
Job Requirements:
- Bachelor’s degree or above in Information Technology, Computer Science, or related disciplines;
- Minimum of 5 years of experience in banking information security;
- Technical skills required for the job position: Hands-on experience in Red/Blue team exercises and offensive security (e.g., SQL injection, XSS, privilege escalation, CC attacks). Foundational knowledge of AI/LLM and experience in security design/auditing. Full lifecycle management of information security products/services (procurement, implementation, O&M).5+ years in security tool operation and rule formulation (e.g., log parsing, risk analysis, compliance verification);
- Soft skills requirements: Strong strategic planning and cross-functional collaboration skills. Proven ability to drive innovation in AI-driven security solutions. High adaptability in dynamic, high-pressure environments;
- Passed in HKMA-recognized information security certifications (e.g., CISSP, CISM, CISA) is a must;
- Proficiency in both written and spoken English, Chinese and Putonghua;
Candidate with more experience will be considered for Senior IT Information Security Manager.