Job Responsibilities:
- Perform daily security operation tasks, such as reviewing security events and logs, perform diagnosis and respond to security incidents, investigate phishing emails and websites
- Support the implementation of security initiatives to ensure the compliance with corporate information security policies and compliance standards
- Provide advice on security configurations to other system development and infrastructure projects, in various areas including network perimeter, OS platforms, identity and privileged access management
- Manage server vulnerability assessments and patching processes by identifying, prioritizing, and remediating security vulnerabilities in a timely manner
- Maintain the Zero Trust Network Access platform to ensure secure, reliable remote connectivity, including managing access policies, onboarding applications, monitoring performance, and troubleshooting issues to uphold strong access control and user experience
- Keep abreast of the latest technologies such as cloud computing and mobile devices, and the corresponding security challenges as well as controls
Job Requirements:
- Bachelor degree in Computer Science/ Cyber Security or relevant disciplines
- Minimum 4 years of work experience with at least 2 years in IT security or equivalent
- Hands-on experience in Security Operation Centre (SOC) or equivalent to security event monitoring and investigation
- Hands-on experience in deploying and supporting IT security infrastructures, such as firewall, IDS/IPS, web proxy security, email security, endpoint protection, vulnerability scanning, penetration test, SIEM, identity management, privileged access management and data encryption technologies
- Knowledgeable in cyber security incident handling
- Knowledgeable in TCP/IP, Linux/UNIX System Administration, and Windows System Administration
- Knowledge of Database Administration, Network Security, Mobile Technology, Cloud Security, Application Security, Active Directory Security and Virtualization Technology is preferred
- Familiar with information security standards such as ISO27001 and HKMA C-RAF is a plus
- Holder of security certificates such as GIAC, CEH, OSCP, CISSP, CISA is preferred
- Good problem solving and trouble shooting skills
- Effective communication and interpersonal skills
- Able to work under pressure, self-motivated and good team player
- Passionate about technology and cyber security
We offer successful candidate an attractive remuneration package and excellent career prospects. Interested parties please send your resume, present and expected salary, contact details and quoting the reference number by clicking "Apply Now"
Visit our web site: http://www.octopus.com.hk/ [link removed]
The personal data collected will be used for recruitment purposes only. If you are not contacted by us within six weeks, you may consider your application unsuccessful. Personal data with an unsuccessful applicant will be destroyed 12 months after rejection of the application. During this retention period, you have the right to request for correction or destruction of your personal data at any time. Any request for the correction or destruction of personal data should be addressed in writing to our Human Resources & Administration Department.
Octopus is an equal opportunity employer and all employment decisions and Human Resources policies are administered; especially those relating to recruitment & selection, compensation & benefits, promotion & transfer, training & development and termination & redundancy; without discrimination on the basis of age, race, colour, religion, sex,national origin, marital status, pregnancy, physical and mental disability and family status but on genuine occupational qualification, job performance, employees’ ability and internal/ external relativities.
