Cyber Security Threat and Vulnerability Specialist

2 weeks ago


Hong Kong, Central and Western District, Hong Kong SAR China MUFG Full time

Cyber Security Threat and Vulnerability Specialist

Apply locations Hong Kong time type Full time posted on Posted 30+ Days Ago job requisition id 10068021-WD

Do you want your voice heard and your actions to count?

Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world's leading financial groups. Across the globe, we're 120,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.

With a vision to be the world's most trusted financial group, it's part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.

Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.

Key Responsibilities:

Ensure MUFG Securities Asia's information risk controls align with ISO27002 Information Security Standards, covering but not limited to:

Threat and Vulnerability Management
  • Oversee the regional threat and vulnerability function
  • Coordination of vulnerability remediation and response with Technology Teams
  • Perform periodic and on-demand vulnerability and baseline configuration scanning of organization systems and monitor the security patch and compliance status
  • Perform periodic vulnerability scanning and monitor the security patch and compliance status
  • Coordination of critical vulnerability response and security incident resolution
  • Maintain up-to-date documentation relating to threat and vulnerability management, including process, procedures, and standards
  • Maintain baseline exceptions within central registrar
  • Improve and automate existing vulnerability management process
  • Reports on identified vulnerabilities and their associated risks
Cyber Security Operations
  • Monitor and respond to cyber-security events in SIEM handled in accordance with the established protocol of the International Cyber Security Team
  • Escalate security incidents and participate in investigation and risk containment/mitigation where necessary. Assist the incident response process as requested by GSOC Team
  • Manage security tools (vulnerability scanner, web security, malware protection, etc.)
  • Conduct User Awareness Training to improve MUS employee awareness of Cyber Threats
IT Risk & Control
  • Assist in ensuring MUFG Securities Asia operates under comprehensive and relevant policies and standards with appropriate staff awareness, compliance monitoring and reporting
  • Assist in managing the regional information security risk profile and associated operational risk reporting of information security and technology incidents
  • Assist in preparing monthly regional information security management reports and metrics for risk committees
  • Support incident reporting
Audit & Regulatory Liaison
  • Coordinate internal and external audit activities for information security across MUFG Securities Asia and ensure consistent and timely answers to information requests
  • Assist in ensuring any issues and remedial actions resulting from information security incidents and audits are agreed with appropriate timescales for resolution
Business Continuity, Outsourcing & Vendor Management
  • Coordinate the Business Continuity Management activities such as BIA and BCP reviews. Assist the BCM function to coordinate with various IT teams on drill tests
Skills & Requirements:
  • University degree majoring in information security, information systems, computer science or engineering
  • 5 years or more experience in Cyber Security especially Threat and Vulnerability Management, from investment bank or financial service institutes
  • Practical experience and working knowledge in implementation and operation of security scanning solutions using Qualys, infrastructure penetration testing, and application security testing
  • Hands-on security operations, threat intelligence, incident response and other related experience would be beneficial
  • Professional qualifications: CISSP, CEH, CISP, GWAPT, OSCP or other security related qualifications would be an advantage
  • Familiar with security and control for technologies / enterprise applications: Windows, Firewall, Network appliances, Virtualization platforms and/or evaluating and implementing cyber security management, IT service management and IT governance framework using NIST 2.0, ISO27001, ITIL and COBIT respectively
  • Excellent communication skills in both oral and written English
  • Independent, flexible, self-starter possessing intellectual curiosity
  • Effective project management, prioritization, interpersonal and communication skills are essential

MUFG Bank Ltd & MUFG Securities Asia Limited (collectively referred to as "MUFG") is an equal opportunity employer. We view our employees as our key assets as they are fundamental to our long-term growth and success. MUFG is committed to hiring based on merit and organizational fit, regardless of race, religion or gender.

About Us

At MUFG, our colleagues are our greatest assets. Our Culture Principles provide a roadmap for how each of our colleagues must think and act to become more client-obsessed, inclusive and innovative. They reflect who we are, who we want to be and what we expect from one another. We are excited to see you take the next step in exploring a career with us and encourage you to spend more time reviewing them

#J-18808-Ljbffr

  • Hong Kong, Central and Western District, Hong Kong SAR China MUFG Full time

    About the RoleCyber Security Threat and Vulnerability Specialist is responsible for ensuring MUFG Securities Asia's information risk controls align with ISO27002 Information Security Standards. This involves overseeing regional threat and vulnerability functions, coordinating vulnerability remediation and response with Technology Teams, and performing...


  • Hong Kong, Central and Western District, Hong Kong SAR China KPMG Full time

    KPMG China is a leading professional services firm that provides multidisciplinary services from audit and tax to advisory. Our focus on serving client needs and industries drives our commitment to quality and responsible corporate citizenship.Job OverviewCyber security is a critical aspect of any organization, and at KPMG China, we recognize its importance...


  • Hong Kong, Central and Western District, Hong Kong SAR China MUFG Full time

    Business Requirements:The successful candidate will be responsible for ensuring that MUFG Securities Asia's information risk controls align with ISO27002 Information Security Standards. This involves overseeing regional threat and vulnerability functions, coordinating vulnerability remediation and response with Technology Teams, and performing periodic and...


  • Hong Kong, Central and Western District, Hong Kong SAR China Wizlynx Malaysia Sdn Bhd Full time

    What We're Looking ForWe're looking for an Advanced Cyber Threat Hunter to join our team in Hong Kong. The ideal candidate will have a strong background in cyber security, with experience in threat hunting, vulnerability assessment, and incident response.">Key Responsibilities:Conduct advanced threat hunts, identifying potential security threats and...


  • Hong Kong, Central and Western District, Hong Kong SAR China BIXIN Full time

    Introduction:As a leading financial institution in Hong Kong, we require a skilled IT professional to join our team.Job Summary:We are seeking an experienced Cyber Security Engineer to lead our network security operations in Hong Kong.Responsibilities:Develop and implement network security strategies to protect against cyber threats.Conduct regular security...


  • Hong Kong, Central and Western District, Hong Kong SAR China Centurion Information Security Full time

    Job Description:Company Overview:Centurion Information Security is a leading provider of information security services, dedicated to helping organizations protect their assets and maintain a strong security posture.Job Summary:We are seeking an experienced Penetration Tester to join our team, responsible for conducting penetration testing and vulnerability...

  • Cyber Security Leader

    2 weeks ago


    Hong Kong, Central and Western District, Hong Kong SAR China BDx Data Centers Full time

    The Cyber Security Leader will provide incident response and readiness as part of a 24x7 Security Operations Centre. This role supports global vulnerability management processes, including OS and infrastructure patching, hardening, and testing efforts.The successful candidate will operate security-related tools to identify active threats, attacks,...


  • Hong Kong, Central and Western District, Hong Kong SAR China Wizlynx Malaysia Sdn Bhd Full time

    Wizlynx Malaysia Sdn Bhd is a leading provider of Cyber Security Services. We are seeking an experienced Cyber Security Specialist to join our team.Job DescriptionThe successful candidate will lead and execute a variety of engagements, conducting secure code review and advanced hands-on penetration testing beyond automated tool validation. This will include...


  • Hong Kong, Central and Western District, Hong Kong SAR China Wizlynx Malaysia Sdn Bhd Full time

    Job Description">We are seeking an experienced Cyber Security Specialist to join our team in Hong Kong. The ideal candidate will have a strong background in cyber security, with experience in penetration testing, vulnerability assessment, and incident response.">Key Responsibilities:Conduct network, web, and mobile application penetration tests, identifying...


  • Hong Kong, Central and Western District, Hong Kong SAR China Pinpoint Asia Full time

    Pinpoint Asia A leading enterprise with an advanced technology presence in the region is seeking a Senior Consultant for Tech Recruitment - Infrastructure and Cybersecurity. Our client requires this role to be filled. The ideal candidate will assume the position of Cyber Security Incident Manager, guiding the response process during major security...


  • Hong Kong, Central and Western District, Hong Kong SAR China MUFG Full time

    Company OverviewMUFG Bank Ltd & MUFG Securities Asia Limited (collectively referred to as "MUFG") is an equal opportunity employer. We view our employees as our key assets as they are fundamental to our long-term growth and success. MUFG is committed to hiring based on merit and organizational fit, regardless of race, religion or gender.Job DescriptionThe...


  • Hong Kong, Central and Western District, Hong Kong SAR China Bank Of China (Hong Kong) Limited Full time

    About UsBank of China (Hong Kong) Limited is a leading financial institution in Hong Kong, providing a wide range of banking services to individuals, businesses, and institutions.Job DescriptionWe are seeking a highly skilled IT Security Specialist to join our team. The successful candidate will be responsible for providing cyber security incident response...


  • Hong Kong, Central and Western District, Hong Kong SAR China Wizlynx Malaysia Sdn Bhd Full time

    Job DescriptionWe are seeking an experienced Cyber Security Specialist to join our team. The ideal candidate will have a strong background in penetration testing, secure code review, and application security.The successful candidate will lead and execute secure code reviews, network, web application, and wireless penetration tests of varying complexity. They...


  • Hong Kong, Central and Western District, Hong Kong SAR China Wizlynx Malaysia Sdn Bhd Full time

    At Wizlynx Malaysia Sdn Bhd, we are seeking a talented Cyber Security Specialist to join our team of expert professionals. As a leading provider of cyber security services, we have designed a comprehensive service portfolio that covers the entire risk management lifecycle.In this role, you will be responsible for leading and executing secure code reviews,...


  • Hong Kong, Central and Western District, Hong Kong SAR China I-TRACING Full time

    About the Role">I-TRACING is seeking a skilled Cyber Security Analyst to join our growing team in Hong Kong. Reporting to the APAC SOC Manager, you will be responsible for monitoring the SIEM system for suspicious events and anomalous activity.">Key Responsibilities">Monitor the SIEM system for security threats and incidentsProvide first-level response for...


  • Hong Kong, Central and Western District, Hong Kong SAR China I-TRACING Full time

    About the Role:We are seeking an experienced Cyber Security Professional to join our team in Hong Kong. As a key member of our SOC, you will be responsible for monitoring the SIEM system, providing first-level response for security events, handling event triaging, conducting proactive threat hunting, and validating suspicious events.Key...


  • Hong Kong, Central and Western District, Hong Kong SAR China Wizlynx Malaysia Sdn Bhd Full time

    Cyber Security SpecialistWe are seeking a highly skilled Cyber Security Specialist to join our team at Wizlynx Malaysia Sdn Bhd. As a (Senior) Cyber Security Consultant & Penetration Tester, you will execute a variety of engagements, including advanced hands-on penetration testing.This is a fantastic opportunity to leverage your technical expertise and...


  • Hong Kong, Central and Western District, Hong Kong SAR China Wizlynx Malaysia Sdn Bhd Full time

    (Senior) Cyber Security Consultant & Penetration TesterThis is a unique opportunity to join our team of expert cyber security professionals and contribute to the delivery of high-quality security services to our clients.In this role, you will be responsible for conducting advanced penetration testing, identifying vulnerabilities and weaknesses in our...


  • Hong Kong, Central and Western District, Hong Kong SAR China BDx Data Centers Full time

    Job DescriptionThe Cyber Security Manager will provide security incident response and readiness as part of a 24x7 Security Operations Centre within and in support of the IT Infrastructure and Operations team. This role involves supporting global vulnerability management processes including OS and infrastructure patching, hardening and testing efforts.Duties...


  • Hong Kong, Central and Western District, Hong Kong SAR China ConnectedGroup Limited Full time

    Our client, one of the largest listed companies in Hong Kong, is renowned for its cutting-edge technologies and customer-centric approach in providing day-to-day services to society. They are currently seeking a cyber security engineer to join their team. This is an initial 12-month contract position with the possibility of renewal. Candidate with more...