Senior Information Security Engineer - AVP

  • CN-Shenzhen-HyQ
  • Full-time
  • POSTED TODAY

About the job

Location:

CN-Shenzhen-HyQ

Shift:

Scheduled Weekly Hours:

40

Worker Type:

Permanent

Job Summary:

Job Duties:

Position Summary

We are seeking an experienced Information Security professional to lead and execute information security governance, security operations, security compliance, vulnerability management, and security monitoring initiatives across our business platforms.

The successful candidate will be responsible for aligning local security practices with Group security standards, driving security governance programs, managing security tools and controls, coordinating security assessments, and supporting security incident response activities.

Key Responsibilities

1. Security Operations & SOC

Own and maintain security monitoring processes and operational procedures. Coordinate SIEM and log management initiatives. Work with Group SOC and MSSP teams on security monitoring, alert handling, and escalation processes. Define log collection standards, onboarding scope, and monitoring requirements. Participate in threat detection and security operations improvement initiatives.

2. Security Incident Response

Develop and maintain Security Incident Response Plans and procedures. Coordinate incident investigation, containment, eradication, recovery, and post-incident review activities. Define security incident escalation workflows and communication mechanisms. Organize security drills, tabletop exercises, and response testing. Support regulatory and compliance-related incident reporting requirements.

3. Vulnerability & Security Assessment Management

Manage vulnerability scanning programs and security assessment activities. Track vulnerability remediation progress and risk mitigation activities. Coordinate: Vulnerability Scanning Penetration Testing Secure Configuration Reviews Source Code Reviews Application Security Testing CIS benchmark Security Architecture Reviews Prepare risk acceptance documentation and remediation plans.

4. Identity & Access Management

Manage privileged account governance and PAM/PIM controls with Change management team. Coordinate periodic access reviews and account audits. Maintain privileged account management standards and procedures with change management team.

5. Security Technology Management

Manage and govern security solutions including but not limited to:

SIEM WAF/Anti-DDOS IPS/IDS Endpoint Security PAM/PIM Web Proxy KMS/Certificate Services Security Monitoring Platforms in Tencent Cloud Responsibilities include:

Security product selection and evaluation Vendor management Security architecture review Security product implementation and optimization Security product lifecycle management

6. Security Compliance & Regulatory Requirements

Coordinate MLPS (等保) assessments and remediation activities. Support internal and external audits. Maintain compliance with applicable security regulations and standards. Manage third-party security assessments and compliance reviews. Coordinate security-related regulatory reporting and evidence collection.

Qualification Requirements

Education

Bachelor's degree or above in: Information Security Computer Science Information Technology Cyber Security Related disciplines

Experience

5+ years of Information Security experience Experience in security governance and compliance programs Experience with SOC/SIEM operations and log management Experience managing security projects and vendors Experience working with regional or Group security organizations is highly preferred Financial services or regulated industry experience is highly desirable

Technical Skills

Hands-on experience in several of the following areas:

Security Operations Center (SOC) SIEM Platforms (Splunk, ArcSight, 日志易, etc.) Vulnerability Management(Tenable) Penetration Testing Coordination Security Incident Response PAM / PIM Solutions (CyberArk/RenkEZ) Windows / Linux Security(CIS benchmark) Network Security Cloud Security Endpoint Security Security Compliance Frameworks Security Architecture Review

Preferred Certifications

One or more of the following:

CISSP CISM CISA ISO27001 Lead Implementer/ISO27001 Lead Auditor Security+

Soft Skills

Strong stakeholder management skills Strong communication and presentation skills Ability to coordinate across multiple teams and vendors Strong analytical and problem-solving skills Risk-based decision-making mindset Ability to work independently with minimal supervision

Company Introduction:

ITD SZ

港交所科技(深圳)有限公司 ,是2016年12月28日于深圳市前海自贸区成立的外商独资企业。

作为港交所的技术子公司, 港交所科技(深圳)有限公司 主要是为集团及其附属公司提供计算机软件、计算机硬件、信息系统、云存储、云计算、物联网和计算机网络的开发、技术服务、技术咨询、技术转让;经济信息咨询、企业管理咨询、商务信息咨询、商业信息咨询、信息系统设计、集成、运行维护;数据库管理、大数据分析;以承接服务外包方式提供系统应用管理和维护、信息技术支持管理、数据处理等信息技术和业务流程外包服务。