Position Description
We are looking for an IT Security Analyst who is proactive, self-motivate, willing- to-do attitude to be part of an international IT Security team to engineer and support security solutions.
As a team member in IT security team, you will be a contributor to the company’s IT and Cyber security strategy and operations. You and your team will be managing a portfolio of IT security tools in identity access management, network intrusion detection system, endpoint protection, email security, data leakage protection, application security, and other information security controls.
Key Areas of Responsibilities
Conduct penetration testing, vulnerability scanning and code review on different IT systems and technologies
Perform architecture Review and security assessments on IT systems’ design, configuration, source code review on both On-Perm and Cloud
Conduct Cyber-attack simulation using red team / blue team / purple team exercises
Prepare and review reports on identified security vulnerabilities and possible recommendations to remediate the vulnerabilities
Perform access review for vendor and guest access on IT systems and services.
Assist on Evaluating, Design, planning and implementing IT security solutions, such as Web Application Firewalls, Single Sign On/MFA, Biometric authentication, Cloud Based Public Key Infrastructure (PKI), Malware Sandboxing, AI red teaming, Zero Trust Solutions, etc.
Assist on first and second level support for some of IT security controls and tools including penetration test tools, vulnerability scanning tools, etc.
Be the subject matter expert for some of the IT Security tools.
Build and maintain an effective working relationship with the team’s key stakeholders - IT Security team members, IT teams and business teams.
Design and deliver new strategic security initiatives with collaboration from business partners.
Maintain an Up-to-date understanding of the latest threats, vulnerabilities, mitigation and industry best practices, Post Quantum Computing standard (ML-KEM, ML-DSA, SLA-DSA), and developments in Artificial Intelligence.
Requirements
Bachelor Degree of above in IT, Computer Science
3-5 years related experience in cybersecurity, with knowledge in regulatories
Preferably holds IT Security Certifications such as CISSP, CISA, CISM, etc. Certificates related to offensive security (e.g. OSCP, OSWP, OSEP or equivalent) are an advantage.
Candidates with backgrounds in Big4, IT consultancy firms, or Cyber Threat Intelligence are welcome to apply
Hands-on experience with penetration test and vulnerability scanning tools such as Burp Suite, Metasploit, ZAP, Qualys, Tenable/Nessus, Nmap, etc
Strong communication skills in English and Chinese, as well as project management skills
Experience of offensive security services on Web, Network, Server, Client Apps, Mobile, AI, Internet of Thing (IOT) is required:
Penetration testing
Security risk assessment/technical review
Configuration review
Vulnerability scanning and assessment
Knowledge and understanding of the following areas are the foundation to succeed on this role:
Microsoft 365 cloud services – e.g. Exchange online, Sharepoint, OneDrive, Teams, etc
Public Cloud computing platforms - Microsoft Azure, AWS, GCP, Ali Cloud, Tencent Cloud, etc
AI Tools/Models - OpenAI GPT, Anthropic Claude, Google Gemini, Microsoft Copilot, Amazon Bedrock, Grok
IP/Cisco Networking
Virtualization Technology
Microsoft Active Directory, Microsoft Certificate Authority, Microsoft Windows servers and Linux
Storage and Database fundamental
Good-to-have
Knowledge of two or more of the following security areas below is a plus:
Web Application Firewalls (Akamai, Cloudflare, AWS WAF, Azure WAF), Web filtering, DDoS protection
Single Sign On/MFA (Microsoft Entra/Okta/Cisco Duo)
Malware Sandboxing, Microsoft Cloud PKI and Intune
Zero Trust Solution (Zscaler, Palo Alto Networks, Microsoft Entra Private Access)
Stay informed on CITIC CLSA Job Opportunities
Not the right fit? You can create a job alert to receive our latest job openings that meet your interest.
Skills Required
- Bachelor's degree in IT or Computer Science
- 3-5 years related experience in cybersecurity
- Knowledge of regulatory requirements related to cybersecurity
- Hands-on experience with penetration testing and vulnerability scanning tools (Burp Suite, Metasploit, ZAP, Qualys, Tenable/Nessus, Nmap)
- Experience in offensive security services for Web, Network, Server, Client Apps, Mobile, AI, and IoT (penetration testing, risk assessment, configuration review, vulnerability scanning)
- Experience with Microsoft 365 services (Exchange Online, SharePoint, OneDrive, Teams)
- Experience with public cloud platforms (Azure, AWS, GCP, Ali Cloud, Tencent Cloud)
- Familiarity with AI tools/models (OpenAI GPT, Anthropic Claude, Google Gemini, Microsoft Copilot, Amazon Bedrock, Grok)
- Knowledge of IP/Cisco networking and virtualization technologies
- Experience with Microsoft Active Directory, Microsoft Certificate Authority, Windows Server and Linux
- Strong communication skills in English and Chinese and project management skills
- Ability to perform architecture reviews, security assessments, code review, and prepare remediation reports
- Ability to assist first- and second-level support and act as SME for security tools
- Preferably holds IT security certifications such as CISSP, CISA, CISM
- Offensive security certifications (OSCP, OSWP, OSEP or equivalent) are an advantage
- Backgrounds in Big4, IT consultancy, or Cyber Threat Intelligence are welcome
- Knowledge of Web Application Firewalls, SSO/MFA, malware sandboxing, Microsoft Cloud PKI, Intune, and Zero Trust solutions (Akamai, Cloudflare, AWS/Azure WAF, Microsoft Entra, Okta, Cisco Duo, Zscaler, Palo Alto Networks)
CLSA Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about CLSA and has not been reviewed or approved by CLSA.
-
Pay Growth & Progression — Base pay for junior bankers was increased significantly in 2021 to stay competitive in a hot market. This indicates willingness to adjust compensation when talent risks rise.
-
Healthcare Strength — Permanent staff are automatically enrolled in healthcare aligned to local markets, with added travel health and security support via International SOS. This points to solid core medical coverage with global-travel assistance.
-
Retirement Support — Permanent staff are automatically enrolled in pension plans aligned to local markets. A group retirement plan is administered regionally, signaling formalized retirement benefits infrastructure.
CLSA Insights
What We Do
CITIC CLSA is a wholly-owned subsidiary of CITIC Securities and its overseas business platform. Established in Hong Kong in 1986, CITIC CLSA is Asia’s leading capital markets and investment group, committed to driving the growth strategies of global institutional investors, corporations, governments and high-net-worth individuals. CITIC CLSA’s award-winning research, extensive Asia network, direct links to China and highly experienced financial professionals set CITIC CLSA apart from global investment banks and regional players. Over three decades, CITIC CLSA has built an extensive Asia network with deep local knowledge and connections. Globally, we operate from 13 countries across Asia, Australia, Europe and the Americas. For further information, please visit clsa.com







