Analyst, IT Security Engineering, IT

Posted 16 Days Ago
Be an Early Applicant
Hiring Remotely in Hong Kong
Remote
Mid level
Fintech • Payments • Financial Services
The Role
Perform offensive and defensive security activities including penetration testing, vulnerability scanning, architecture and code reviews, red/blue/purple team exercises, security tool support, access reviews, and implementation of security solutions across on-prem and cloud environments. Provide recommendations, stakeholder collaboration, and stay current on threats, AI, and post-quantum developments.
Summary Generated by Built In

Position Description

We are looking for an IT Security Analyst who is proactive, self-motivate, willing- to-do attitude to be part of an international IT Security team to engineer and support security solutions.

As a team member in IT security team, you will be a contributor to the company’s IT and Cyber security strategy and operations. You and your team will be managing a portfolio of IT security tools in identity access management, network intrusion detection system, endpoint protection, email security, data leakage protection, application security, and other information security controls.

Key Areas of Responsibilities

  • Conduct penetration testing, vulnerability scanning and code review on different IT systems and technologies

  • Perform architecture Review and security assessments on IT systems’ design, configuration, source code review on both On-Perm and Cloud

  • Conduct Cyber-attack simulation using red team / blue team / purple team exercises

  • Prepare and review reports on identified security vulnerabilities and possible recommendations to remediate the vulnerabilities

  • Perform access review for vendor and guest access on IT systems and services.

  • Assist on Evaluating, Design, planning and implementing IT security solutions, such as Web Application Firewalls, Single Sign On/MFA, Biometric authentication, Cloud Based Public Key Infrastructure (PKI), Malware Sandboxing, AI red teaming, Zero Trust Solutions, etc.

  • Assist on first and second level support for some of IT security controls and tools including penetration test tools, vulnerability scanning tools, etc.

  • Be the subject matter expert for some of the IT Security tools.

  • Build and maintain an effective working relationship with the team’s key stakeholders - IT Security team members, IT teams and business teams.

  • Design and deliver new strategic security initiatives with collaboration from business partners.

  • Maintain an Up-to-date understanding of the latest threats, vulnerabilities, mitigation and industry best practices, Post Quantum Computing standard (ML-KEM, ML-DSA, SLA-DSA), and developments in Artificial Intelligence.

Requirements

  • Bachelor Degree of above in IT, Computer Science

  • 3-5 years related experience in cybersecurity, with knowledge in regulatories

  • Preferably holds IT Security Certifications such as CISSP, CISA, CISM, etc. Certificates related to offensive security (e.g. OSCP, OSWP, OSEP or equivalent) are an advantage.

  • Candidates with backgrounds in Big4, IT consultancy firms, or Cyber Threat Intelligence are welcome to apply

  • Hands-on experience with penetration test and vulnerability scanning tools such as Burp Suite, Metasploit, ZAP, Qualys, Tenable/Nessus, Nmap, etc

  • Strong communication skills in English and Chinese, as well as project management skills

  • Experience of offensive security services on Web, Network, Server, Client Apps, Mobile, AI, Internet of Thing (IOT) is required:

    • Penetration testing

    • Security risk assessment/technical review

    • Configuration review

    • Vulnerability scanning and assessment

  • Knowledge and understanding of the following areas are the foundation to succeed on this role:

    • Microsoft 365 cloud services – e.g. Exchange online, Sharepoint, OneDrive, Teams, etc

    • Public Cloud computing platforms - Microsoft Azure, AWS, GCP, Ali Cloud, Tencent Cloud, etc

    • AI Tools/Models - OpenAI GPT, Anthropic Claude, Google Gemini, Microsoft Copilot, Amazon Bedrock, Grok

    • IP/Cisco Networking

    • Virtualization Technology

    • Microsoft Active Directory, Microsoft Certificate Authority, Microsoft Windows servers and Linux

    • Storage and Database fundamental

Good-to-have

  • Knowledge of two or more of the following security areas below is a plus:

    • Web Application Firewalls (Akamai, Cloudflare, AWS WAF, Azure WAF), Web filtering, DDoS protection

    • Single Sign On/MFA (Microsoft Entra/Okta/Cisco Duo)

    • Malware Sandboxing, Microsoft Cloud PKI and Intune

    • Zero Trust Solution (Zscaler, Palo Alto Networks, Microsoft Entra Private Access)

Stay informed on CITIC CLSA Job Opportunities

Not the right fit? You can create a job alert to receive our latest job openings that meet your interest.

Skills Required

  • Bachelor's degree in IT or Computer Science
  • 3-5 years related experience in cybersecurity
  • Knowledge of regulatory requirements related to cybersecurity
  • Hands-on experience with penetration testing and vulnerability scanning tools (Burp Suite, Metasploit, ZAP, Qualys, Tenable/Nessus, Nmap)
  • Experience in offensive security services for Web, Network, Server, Client Apps, Mobile, AI, and IoT (penetration testing, risk assessment, configuration review, vulnerability scanning)
  • Experience with Microsoft 365 services (Exchange Online, SharePoint, OneDrive, Teams)
  • Experience with public cloud platforms (Azure, AWS, GCP, Ali Cloud, Tencent Cloud)
  • Familiarity with AI tools/models (OpenAI GPT, Anthropic Claude, Google Gemini, Microsoft Copilot, Amazon Bedrock, Grok)
  • Knowledge of IP/Cisco networking and virtualization technologies
  • Experience with Microsoft Active Directory, Microsoft Certificate Authority, Windows Server and Linux
  • Strong communication skills in English and Chinese and project management skills
  • Ability to perform architecture reviews, security assessments, code review, and prepare remediation reports
  • Ability to assist first- and second-level support and act as SME for security tools
  • Preferably holds IT security certifications such as CISSP, CISA, CISM
  • Offensive security certifications (OSCP, OSWP, OSEP or equivalent) are an advantage
  • Backgrounds in Big4, IT consultancy, or Cyber Threat Intelligence are welcome
  • Knowledge of Web Application Firewalls, SSO/MFA, malware sandboxing, Microsoft Cloud PKI, Intune, and Zero Trust solutions (Akamai, Cloudflare, AWS/Azure WAF, Microsoft Entra, Okta, Cisco Duo, Zscaler, Palo Alto Networks)

CLSA Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about CLSA and has not been reviewed or approved by CLSA.

  • Pay Growth & Progression Base pay for junior bankers was increased significantly in 2021 to stay competitive in a hot market. This indicates willingness to adjust compensation when talent risks rise.
  • Healthcare Strength Permanent staff are automatically enrolled in healthcare aligned to local markets, with added travel health and security support via International SOS. This points to solid core medical coverage with global-travel assistance.
  • Retirement Support Permanent staff are automatically enrolled in pension plans aligned to local markets. A group retirement plan is administered regionally, signaling formalized retirement benefits infrastructure.

CLSA Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Hong Kong
2,160 Employees
Year Founded: 1986

What We Do

CITIC CLSA is a wholly-owned subsidiary of CITIC Securities and its overseas business platform. Established in Hong Kong in 1986, CITIC CLSA is Asia’s leading capital markets and investment group, committed to driving the growth strategies of global institutional investors, corporations, governments and high-net-worth individuals. CITIC CLSA’s award-winning research, extensive Asia network, direct links to China and highly experienced financial professionals set CITIC CLSA apart from global investment banks and regional players. Over three decades, CITIC CLSA has built an extensive Asia network with deep local knowledge and connections. Globally, we operate from 13 countries across Asia, Australia, Europe and the Americas. For further information, please visit clsa.com

Similar Jobs

CLSA Logo CLSA

Sr. Analyst, IT Security Engineering, IT

Fintech • Payments • Financial Services
Remote
Hong Kong
2160 Employees

BlackRock Logo BlackRock

Aladdin Client Engagement, Associate

Fintech • Information Technology • Financial Services
Remote
Hong Kong
25000 Employees
Remote or Hybrid
2 Locations
289097 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account