Associate VP

2 weeks ago


Hong Kong, Central and Western District, Hong Kong SAR China Hong Kong Exchanges and Clearing Limited Full time

Company Introduction:

We're home to Asia's most dynamic and vibrant capital markets.
Connecting capital, ideas, inspiration and innovation for deeper, more diverse and liquid global capital markets; providing greater choice and opportunity for our customers, each and every day.

HKEX is a purpose-driven company. Our commitment to the long-term development of our business and our markets is articulated in our purpose: "To Connect, Promote and Progress our Markets and the Communities they support for the prosperity of all."

Job Summary:
The Application Security Solution Architect (ASSA) for HKEX Group is accountable for translating group-wide information and cyber security strategy, policy and control requirements into secure application solutions. They will focus on application-level security architecture, design, processes and controls.

The role is tasked with balancing the unique business objectives of a global exchange against the inherent security threat and risk profile applicable to critical national infrastructure.

Job Duties:

Job Responsibilities

  • Architectural Oversight: Ensure that the information and cybersecurity architecture and solution designs for applications are engineered according to specifications and within acceptable risk tolerance levels, focusing on application-specific contexts.
  • Support Development Teams: Collaborate with development teams to implement application-specific threat modeling, secure coding practices, and the effective use of application security assurance tools to enhance the security of software products.
  • Integration Architecture Recommendations: Provide expert recommendations on application-level integration architecture, focusing on secure coding practices, web application firewalls, software composition analysis, static and dynamic code scanning, Software Bill of Materials (SBOM), and security measures within CI/CD pipelines, all crucial for securing application deployments.
  • Application Security Assurance Tool Experience: Leverage experience with application security assurance tools, including onboarding, triaging issues, and assisting developers, to ensure that applications are built and maintained with robust security measures.
  • Collaboration with Security Engineering: Work closely with the Security Engineering team to integrate security solutions into application development processes, ensuring that security is a fundamental aspect of the application lifecycle.
  • Requirement Creation and Review: Develop and review functional and non-functional security requirements specifically tailored for application projects, ensuring these requirements enhance the security posture of applications.
  • System Architecture Review: Conduct thorough reviews of application architecture and designs to ensure that all solutions have undergone appropriate security assurance and meet established security acceptance criteria, thereby protecting applications from vulnerabilities.
  • Security Reference Patterns Development: Create and present application security reference patterns and technical security standards that guide secure application development, ensuring compliance with the Information Security Policy.
  • Data Security: Create or review implementation of data layer protective and detective control patterns for data storage technologies, from high level SAAS applications to specific technologies, such as Databases, Kafka queues, object storage systems.
  • Kubernetes / Cloud Security Expertise: Apply knowledge of Kubernetes / Cloud security technologies to enhance the security of applications deployed in containerized environments, addressing specific risks associated with cloud-native applications.
  • Application Architecture Understanding: Demonstrate a comprehensive understanding of application architecture to apply relevant security controls and systems, minimizing cybersecurity risks specific to the application's design and functionality.
  • Collaborative Project Delivery: Work collaboratively with project delivery and operational teams to ensure that applications are delivered on time and meet high-quality security standards throughout the system delivery lifecycle.
  • Governance Participation: Actively participate in governance forums, such as the Architecture Community and Working Group, to contribute to the development of application security strategies and best practices
Job Requirement:

Academic and Professional Qualifications Required:
  • Should have a relevant University degree in Computer Science, Information Management, or related field, or equivalent experience.
  • Should have relevant experience with information security and enterprise architecture methods and frameworks (e.g., SABSA, TOGAF, NIST CSF)
  • Cyber Security certifications, such as SABSA, CCSP (Certified Cloud Security Professional), CISSP (Certified Information Systems Security Professional) or security specific cloud certifications such as AWS, Azure, GCP, AliBaba Cloud, Kubernetes, etc would be looked upon favourably
Required Knowledge and Level of Experience:
  • Must have significant and wide experience in the information and cyber security industry.
  • Must have subject matter expertise in application threat modelling, secure coding practices in either Java or C++ (or other languages such as .Net, node.js, go); and DevSecOps practices.
  • Must have current experience of automated build and deployment pipelines and how to both secure a pipeline and assure the security of artefacts in a pipeline.
  • Should have current experience of software and system assurance methodologies and associated vulnerability management and risk management practices.
  • Should have current experience of operating one or more of SAST, SCA, DAST, IAST and SBOM.
  • Should be able to perform automation scripting leveraging python and API's
  • Should have relevant experience with industry best-practice approaches to the design, implementation, operation and management of IT systems (e.g., Agile, Waterfall, ITIL, COBIT).
  • Should have recent experience of delivering solutions security in public and/or private cloud.
Optional Knowledge and Experience:
  • Should have experience security Kubernetes technology and familiar with secrets management, PKI, service mesh, Istio, etc.
  • Should have experience of developing/ contributing to security policies and standards.
  • Should have current experience securing automated build and deployment pipelines and securing artefacts
  • Should have familiarity with internal audit, risk and control management
  • Relevant information security experience working with or for a global exchange, or similar regulated financial market infrastructure or critical national infrastructure would be looked upon favourably.
Skills set and Core Competencies Required for Role:
  • An intelligent, articulate, consensus building and persuasive self-starter.
  • Must have a strong business acumen and technology knowledge.
  • Must be able to communicate information security-related concepts to a broad range of audiences.
  • Experience of effective stakeholder management and collaborative mindset.
  • Able to deliver within a fast-moving high-pressure environment, balancing multiple work streams and deliverables.
Personal Qualities:
  • Open and approachable, with ability to work well within a team.
  • Effective oral and written communicator
HKEX is committed as an Equal Opportunity Employer. Diversity is one of our core values and we look to support, respect diverse perspectives, abilities, culture and experiences within our workplace.

Location:
HKEX - TKO

Shift:
N/A

Scheduled Weekly Hours:
40

Worker Type:
Permanent
  • Associate VP

    2 weeks ago


    Hong Kong, Central and Western District, Hong Kong SAR China Charterhouse Partnership Hong Kong Full time

    Our client is a highly regarded and internationally recognized foreign bank with a strong presence in the global financial industry. They are now actively looking to recruit a highly skilled and experienced AVP/VP, Internal Audit Manager - Global Markets.Responsibilities Perform moderately complex audits including drafting audit reports, presenting issues to...

  • VP of Compliance

    2 weeks ago


    Hong Kong, Central and Western District, Hong Kong SAR China DARMAX GLOBAL Full time

    Company Our client is a global multi-billion-dollar Hedge Fund with a dynamic and collaborative culture. The Role: This powerhouse is currently seeking a driven Senior Associate/ VP, Compliance (Japanese Speaker) to join their ever-growing team due to organic growth - can be based in their Hong Kong, Singapore, or Japan office.  You will work closely with...

  • Associate VP

    2 weeks ago


    Hong Kong, Central and Western District, Hong Kong SAR China HARBRIDGE PARTNERS Full time

    Job Title: Legal Counsel (AVP- PRC or HK Qualified) Financial Services/ Securities firm experience preferred. Description:Draft, review, and negotiate a wide range of commercial contracts, including partnership agreements, vendor contracts, and customer agreements. Ensure all contracts align with the company's legal and business interests. Monitor and...

  • Associate VP

    2 weeks ago


    Hong Kong, Central and Western District, Hong Kong SAR China BOC International Full time

    The Role AVP, Model and System Risk, Risk management Key AccountabilitiesAssist in formulating and reviewing model risk management policy & procedures and operational manuals related to concentration risk, counterparty credit risk, and stress testing, ensuring compliance with regulatory standards. Provide assistance in credit risk related reporting ,...

  • Associate VP

    2 weeks ago


    Hong Kong, Central and Western District, Hong Kong SAR China DBS Bank (Hong Kong) Limited Full time

    Business Function As the leading bank in Asia, DBS Consumer Banking Group is in a unique position to help our customers realise their dreams and ambitions. As a market leader in the consumer banking business, DBS has a full spectrum of products and services, including deposits, investments, insurance, mortgages, credit cards and personal loans, to help...

  • Associate VP

    1 week ago


    Hong Kong, Central and Western District, Hong Kong SAR China DBS Bank (Hong Kong) Limited Full time

    Business Function As the leading bank in Asia, DBS Consumer Banking Group is in a unique position to help our customers realise their dreams and ambitions. As a market leader in the consumer banking business, DBS has a full spectrum of products and services, including deposits, investments, insurance, mortgages, credit cards and personal loans, to help our...

  • Associate VP

    3 days ago


    Hong Kong, Central and Western District, Hong Kong SAR China DBS Bank (Hong Kong) Limited Full time

    Business Function As the leading bank in Asia, DBS Consumer Banking Group is in a unique position to help our customers realise their dreams and ambitions. As a market leader in the consumer banking business, DBS has a full spectrum of products and services, including deposits, investments, insurance, mortgages, credit cards and personal loans, to help our...


  • Hong Kong, Central and Western District, Hong Kong SAR China Green Lake Executive Search Full time

    Counterparty Risk Manager, VP-Director G00342 Deliver effective counterparty risk management solutions for Group business initiatives, including OTC derivatives and synthetic prime brokerage operations, while ensuring seamless coordination across business units and support/control functions. Contribute to the development of counterparty risk measurement...

  • Associate VP

    2 weeks ago


    Hong Kong, Central and Western District, Hong Kong SAR China BOC International Full time

    The Role AVP, Credit Risk, Risk Management Key AccountabilitiesParticipate in formulating counterparty/credit risk management policies, process and governance standards. Responsible for analyze, approve and monitor the counterparty credit risk for multi trading desks. Responsible for analyze, approve and monitor issuers' default risk for bond investment...

  • Associate VP

    2 weeks ago


    Hong Kong, Central and Western District, Hong Kong SAR China BOC International Full time

    The Role ASSO/AVP, Trader, Fixed Income Department Key Accountabilities Act as trader to support bond investment activities; Solid fixed income investment experience and knowledge of fixed income products and markets Carry out investment research and formulate trade ideas, prepare regular reports on investment activities, performance, and market insights...

  • Associate VP

    2 weeks ago


    Hong Kong, Central and Western District, Hong Kong SAR China Hong Kong Exchanges and Clearing Limited Full time

    Company Introduction: We're home to Asia's most dynamic and vibrant capital markets. Connecting capital, ideas, inspiration and innovation for deeper, more diverse and liquid global capital markets; providing greater choice and opportunity for our customers, each and every day. HKEX is a purpose-driven company. Our commitment to the long-term development...

  • Associate VP

    2 weeks ago


    Hong Kong, Central and Western District, Hong Kong SAR China ALL-STAR AGENCY Full time

    Overview A high-growth corporate bank with continual investment in growth in the region is seeking to hire an Assistant Vice President - Syndications in the syndicated loans department to handle full spectrum of activities for securing the transactions including sales, credit analysis, due diligence in execution to maintain their edge in the syndicated...

  • Associate VP

    2 weeks ago


    Hong Kong, Central and Western District, Hong Kong SAR China Hong Kong Exchanges and Clearing Limited Full time

    Company Introduction: We're home to Asia's most dynamic and vibrant capital markets. Connecting capital, ideas, inspiration and innovation for deeper, more diverse and liquid global capital markets; providing greater choice and opportunity for our customers, each and every day. HKEX is a purpose-driven company. Our commitment to the long-term development...

  • Associate VP

    5 days ago


    Hong Kong, Central and Western District, Hong Kong SAR China Hong Kong Exchanges and Clearing Limited Full time

    Company Introduction: We're home to Asia's most dynamic and vibrant capital markets. Connecting capital, ideas, inspiration and innovation for deeper, more diverse and liquid global capital markets; providing greater choice and opportunity for our customers, each and every day. HKEX is a purpose-driven company. Our commitment to the long-term development...

  • Associate VP

    1 week ago


    Hong Kong, Central and Western District, Hong Kong SAR China The Edge Partnership Full time

    Responsibilities:Identify and assess operational risks in equities and eTrading activities. Monitor key risk indicators (KRIs) and track operational risk incidents. Develop and maintain risk registers and risk management documentation. Prepare operational risk reports for senior management. Enhance processes and controls, identifying and implementing...

  • Associate VP

    6 days ago


    Hong Kong, Central and Western District, Hong Kong SAR China ConnectedGroup Limited Full time

    A sizable overseas Bank is looking for an AVP level candidate for their Compliance Assurance team. Responsibilities: Conduct effective, objective, risk-based compliance monitoring activities pursuant to the annual Compliance Monitoring Plan. Identify potential or actual regulatory risks arising from the results of compliance monitoring and proposing...

  • Associate VP

    6 days ago


    Hong Kong, Central and Western District, Hong Kong SAR China DBS Bank (Hong Kong) Limited Full time

    Business Function: As the leading bank in Asia, Group Strategy, Transformation, Analytics and Research (GSTAR) supports our management on the implementation of the Group's agenda. Data Chapter, organized under GSTAR, is committed to create synergies between the data analytics functions across the bank, establish centres of excellence, shared services, and...

  • Associate VP

    5 days ago


    Hong Kong, Central and Western District, Hong Kong SAR China Captiare Limited Full time

    Our client is an international bank with long history in Hong Kong. They are seeking the following role: Assistant Vice President -Compliance Department Hong Kong - Compliance Assurance Job Duties & Responsibilities: Conduct effective, objective, risk-based compliance monitoring activities pursuant to the annual Compliance Monitoring Plan. Identify...

  • Associate VP

    5 days ago


    Hong Kong, Central and Western District, Hong Kong SAR China ALL-STAR AGENCY Full time

    Overview: A commercial bank in Hong Kong is looking for an independent and self-driven Financial Markets Sales to partner with Relationship Managers to provide tailor-made treasury solutions to fulfil the demands of the designated client segments. Roles Responsibilities:Partner with Relationship Managers as a Product Specialist to advise treasury products,...

  • Associate VP

    3 days ago


    Hong Kong, Central and Western District, Hong Kong SAR China Citi Full time

    Wealth Asia Capital Markets Group is currently looking for a high caliber professional to join our team as Assistant Vice President, Structured Products / Securities Analyst, based in Hong Kong. The Structured Products / Securities Analyst is a strategic professional with high energy and a keen interest in Capital Market products, who will stay abreast of...