Sobre este puesto de IT Security Engineer en China CITIC Bank International
Mandatory Reference Checking Scheme (“MRC”) for Hong Kong
The Mandatory Reference Checking Scheme is a framework to facilitate Authorized Institutions (“AIs”) to bilaterally obtain reference information during their recruitment process for certain positions, such that misconduct information in an individual’s previous employments can be provided to AIs to inform their employment decisions.
For information related to MRC Scheme, “Frequently Asked Questions for In Scope Individuals” is published by HKAB/Industry Guidelines (https://www.hkab.org.hk/en/home) or further information will be available upon request, if it is applicable to the position(s) applied.
Country of Location:
China Hong KongJob Responsibilities:
• To support the new AI initiatives in security matters, such as additional controls of usage and identified the AI risks and also propose the compensation controls.
• To provide security advisory to Oversea Branches (OVB) IT teams
• To support regular Cybersecurity Drills relate to AI security scenarios planning, execution, and the drill reporting.
• Maintain information and cyber security standard & baseline
• Assist to defines IT security framework to guard against Cyber security exposure and technology risk
• To manage and support security check on new tools introduced into the bank.
• Support the implementation of policy or intelligence-based security solution for End Point Protection, DLP, APT, Application White-listing, etc per C-RAF requirement
• Assist to drive cybersecurity related projects including scope definition, vendor coordination, scheduling and technical implementation.
• Support the continuous improvement in SIEM correlation and used cases
• Assist to develop Security Operation Center (SOC) and establish KPI to formalize the measurement of degree of attack and our defense ability
• Make use of automation tool to ensure the platform and network security in compliance with the established standard and baseline
• Conduct security risk assessment for application, infrastructure and adoption of new technologies
• Liaise with internal and external parties / audits on handling the technical response to the audit review and assessment initiated
• Review exception events/logs from in-house security platforms as well as from market intelligence
Requirements:
• Degree holder in Information Technology or relevant discipline.
• 5+ years’ experience in IT in which at least 1 year in IT Security relevant
• AI Security and/or Governance related certification is an advantage
• Obtained Core / Professional level qualification of Relevant Practitioner under HKMA ECF on Cybersecurity
• Holder of CISSP, CISA, CISM or other recognized certificate is an advantage
• Knowledge on various platforms’ operation systems e.g. Windows, Unix, Linux, AI OS etc.
• Familiar with network security products such as Firewall, IDS/IPS, WAF, DDoS, VPN, End-point protection, Anti-phishing, DLP, APT and SIEM solution.
• Knowledge on new IT technology such as AI tools, LLM, MCP, etc.
• Knowledge with the encryption technology and hardware security module
• Knowledge on regulatory requirements such as HKMA, MAS, PCI-DSS and etc.
• Experience in handling vulnerability/penetration test service provider, PCI-DSS assessor, Cyber-attack simulation agency.