The Job
1、Provide professional security advisory service to customers by designing and proposing security solutions meeting customer's objectives
2、Understand customer's IT challenges and security requirements; and provide suggestions and comments to development team from technical and pre-sales perspectives of information security
3、Directs an ongoing, proactive risk assessment program for all new and existing systems and business processes; communicates risks and recommendations to mitigate risks to the senior management in term of non-technical and cost/benefit for decision making
4、Ensures vulnerabilities are managed by directing periodic vulnerability scans of servers connected to Company's networks; and support other department to ensure regulatory compliance in areas of ISO 27001 and PCI DSS
5、Evaluates security incidents and determines what response, if any, is needed and coordinates Company's responses when sensitive information is breached
6、Assist and conduct security risk assessment & audit for both internal and customers
The Person
1、Degree holder or above in Computer Science / Information Technology or related disciplines, or with qualification equivalent to Level 5 of Hong Kong Qualifications Framework (QF)
2、4-5 years of varied information technology experience on computer and networking infrastructure, operating systems, application software development, project management, regulatory compliance, and risk management
3、Good knowledge and experience in security planning and design with different technologies / solution
4、Professional certification (CISSP, CCSK, CCSP, CISA, CISM, etc.) is preferred
5、At least one of the CISSP, ISO/IEC27001 LA, CISM and CEH
6、Effective verbal and written communication skills and proficiency in writing technical specifications are required
7、Proficient in written and spoken English and Chinese
8、Creatively and critical thinking, responsible
9、Office: 27/F, Tower1, The Millennity, 98 How Ming Street, Kwun Tong, Kowloon, Hongkong
--------------------------------------------------------------------------------------------
主要職責(zé)
1、透過設(shè)計(jì)和提出滿足客戶目標(biāo)的安全解決方案,為客戶提供專業(yè)的安全諮詢服務(wù)
2、了解客戶的 IT 挑戰(zhàn)和安全需求,並從資訊安全的技術(shù)和售前角度向開發(fā)團(tuán)隊(duì)提供建議和意見
3、指導(dǎo)對(duì)所有系統(tǒng)及業(yè)務(wù)流程進(jìn)行持續(xù)、積極主動(dòng)的風(fēng)險(xiǎn)評(píng)估;以非技術(shù)性和成本效益分析的方式,向高階管理層傳達(dá)風(fēng)險(xiǎn)及風(fēng)險(xiǎn)緩解建議,以供決策參考
4、透過定期對(duì)連接到公司網(wǎng)路的伺服器進(jìn)行漏洞掃描,確保漏洞得到有效管理;並支援其他部門確保符合 ISO 27001 和 PCI DSS 等監(jiān)管要求
5、評(píng)估安全事件,確定是否需要採取應(yīng)對(duì)措施以及採取何種措施,並就敏感資訊外洩問題協(xié)調(diào)公司的應(yīng)對(duì)措施
6、協(xié)助並進(jìn)行內(nèi)部和客戶的安全風(fēng)險(xiǎn)評(píng)估和審計(jì)
任職要求
1、持有電腦科學(xué)/資訊科技或相關(guān)學(xué)科的學(xué)位或以上學(xué)歷,或具備相當(dāng)於香港學(xué)歷框架(QF)第5級(jí)的資格
2、擁有4-5 年電腦和網(wǎng)路基礎(chǔ)設(shè)施、作業(yè)系統(tǒng)、應(yīng)用軟體開發(fā)、專案管理、合規(guī)性和風(fēng)險(xiǎn)管理等方面的豐富資訊技術(shù)經(jīng)驗(yàn)
3、具備良好的安全規(guī)劃與設(shè)計(jì)知識(shí)與經(jīng)驗(yàn),熟悉各種技術(shù)/解決方案
4、擁有專業(yè)認(rèn)證CISSP、CCSK、CCSP、CISA、CISM 等將獲優(yōu)先考慮
5、至少持有 CISSP、ISO/IEC27001 LA、CISM 和 CEH 其中的一項(xiàng)認(rèn)證
6、需要具備良好的溝通能力以及編寫技術(shù)規(guī)範(fàn)的熟練程度
7、流利的英語和中文的聽說讀寫能力
8、具備創(chuàng)造性和批判性思維,有責(zé)任心
9、經(jīng)驗(yàn)較少的候選人將被考慮擔(dān)任安全分析師
10、 工作地點(diǎn)﹕香港觀塘區(qū)巧明街98號(hào)1座27樓