DevSecOps / Application Security Lead / Security Analyst

5 days ago


Hong Kong Island, Hong Kong SAR China ST Partnership Limited Full time

DevSecOps / Application Security Lead / Security Analyst We are looking for a multi‑role in DevSecOps sector/ Application Security/ Security Analyst for our client. The successful talent will be responsible for ensuring the security of the software applications, identifying and mitigating potential security risks/vulnerabilities, and implementing best practices for application security throughout the software development life cycle. Application Security Architect (DevSecOps) ~ 65-85K Responsibilities Architectural Oversight: Ensure cybersecurity architecture and solutions meet specifications and risk tolerance in application contexts. Support Development Teams: Collaborate with teams on threat modeling, secure coding, and application security tools. Integration Architecture Recommendations: Advise on secure coding, web application firewalls, and CI/CD security measures. Application Security Assurance Tools: Utilize experience with security assurance tools to support developers and enhance application security. Collaboration with Security Engineering: Integrate security solutions into development processes. Requirement Creation and Review: Develop and review security requirements for application projects. System Architecture Review: Conduct security reviews of application designs to meet acceptance criteria. Security Reference Patterns: Create guidelines for secure application development aligned with security policies. Data Security: Review and implement data protection controls across various technologies. Kubernetes/Cloud Security: Enhance security for applications in containerized environments. Application Architecture Understanding: Apply security controls based on application design to minimize risks. Collaborative Project Delivery: Ensure timely delivery of secure applications. Governance Participation: Contribute to application security strategies in governance forums. Qualifications Relevant degree in Computer Science or related field; experience with security frameworks (e.g., SABSA, TOGAF). Cybersecurity certifications (e.g., CISSP, CCSP) are preferred. Significant experience in cybersecurity, application threat modeling, and secure coding (Java, C++, etc.). Familiarity with SAST, SCA, DAST, and DevSecOps practices; experience with automated pipelines. Proficient in automation scripting (Python, APIs); knowledge of IT system management practices. Optional: Experience with Kubernetes security and policy development; familiarity with risk management. Security Analyst (~40-41K) Responsibilities System Monitoring: Oversee the uptime, reliability, stability, and compliance of security systems; collaborate with business units to address any gaps (15%). Anomaly Detection: Identify and respond to network anomalies and malware incidents across various security platforms (20%). DLP Management: Administer and monitor Data Loss Prevention (DLP) solutions for network, host, and cloud environments (15%). SIEM Investigation: Investigate and manage alerts from Security Information and Event Management (SIEM) systems (10%). Email Security: Monitor email and spam filtering systems, addressing any malicious events (10%). Application Oversight: Supervise application whitelisting and file integrity monitoring processes (10%). Compliance Assurance: Ensure cybersecurity configurations meet compliance standards using vulnerability management tools (10%). Vulnerability Management: Oversee the remediation of vulnerabilities and findings from penetration tests (10%). Additional Duties: Perform other tasks as assigned by the Manager of Security Architecture. Requirements Bachelor’s or equivalent degree in Information Systems, Computer Science, or a related field. 2–4 years of experience in IT or cybersecurity roles. Strong understanding of SIEM, IDS/IPS, malware protection, DLP, IAM, vulnerability scanning, and incident response. #J-18808-Ljbffr



  • Hong Kong Island, Hong Kong SAR China ST Partnership Limited Full time

    A technology consulting firm in Hong Kong is looking for a multi-role DevSecOps/Application Security Lead/Security Analyst. This position involves ensuring the security of software applications, collaborating on threat modeling, and implementing security best practices throughout the software development life cycle. Candidates should have a relevant degree,...


  • Hong Kong Island, Hong Kong SAR China ASK IT LIMITED Full time

    A technology solutions provider in Hong Kong is seeking an experienced Information Security Specialist to lead Application Security programs and manage vulnerability management processes. The ideal candidate will have strong knowledge of secure coding practices, DevSecOps, and must hold relevant security certifications. Excellent communication skills in...


  • hong kong, Hong Kong SAR China ASK IT LIMITED Full time

    A technology solutions provider in Hong Kong is seeking an Information Security Specialist to lead Application Security programs and drive DevSecOps adoption. The ideal candidate will have a Bachelor's degree in a related field, at least four years of relevant experience, and expertise in application security principles. Proficiency in both Chinese and...


  • Hong Kong Island, Hong Kong SAR China Rise Associates Asia Limited Full time

    A Hong Kong-based insurance company is seeking an IT Security Specialist to enhance its security capabilities. The role involves leading application security initiatives, defining secure coding standards, and managing vulnerability assessments. Candidates should have a tertiary degree, experience in application security and vulnerability management, and be...


  • Hong Kong Island, Hong Kong SAR China Rise Associates Asia Limited Full time

    IT Security Specialist (Application Security/ Offensive Security) To cope with the strengthening of IT security capability against Insurance Authority’s requirements, this insurance company is looking for candidates with Application Security OR Vulnerability Scan for Application OR DevSecOps experiences to join on a 12-month renewable contract basis....


  • Hong Kong Island, Hong Kong SAR China Swing Consulting Ltd. Full time

    A leading technology consulting firm in Hong Kong is seeking a skilled professional to implement and support DevSecOps automation projects. The role involves defining DevSecOps policies and ensuring compliance governance while designing and developing DevSecOps automation covering the full project lifecycle. Candidates should have a Higher Diploma in...

  • Security Consultant

    5 days ago


    Hong Kong Island, Hong Kong SAR China Pentastic Security Limited Full time

    ️‍♂️ Join Our Team at Pentastic Security Limited as a SECURITY CONSULTANT! Are you passionate about cybersecurity and eager to develop a career in this dynamic field? Pentastic Security is looking for dedicated individuals to join our expanding team as Security Consultant. If you're ready to embark on an exciting journey in Cybersecurity, we want to...


  • hong kong, Hong Kong SAR China Michael Page International (HK) Ltd Full time

    A leading recruitment firm is looking for a skilled DevSecOps Team Lead in Hong Kong to champion secure, automated software delivery. The ideal candidate will manage a distributed team and drive automation and security practices across the software lifecycle. With 5-10 years of experience in DevOps, and proficiency in tools like Atlassian Suite, this role...

  • DevSecOps Lead

    5 days ago


    hong kong, Hong Kong SAR China Michael Page International (HK) Ltd Full time

    We are looking for a highly skilled DevSecOps Team Lead to champion secure, automated, and scalable software delivery across enterprise platforms. This role requires balancing release agility with strong security governance, driving cultural and technological transformation, and managing large-scale CI/CD/CT operations. The successful candidate will lead a...


  • Hong Kong Island, Hong Kong SAR China Delken Group Limited Full time

    Our client is a Leading Financial Institution. Temporary Systems Analyst (Information Technology) Responsibilities: Responsible for security architecture of multiple core platforms to support digital transformation for the Company Influence the cyber security posture through direct contribution and consultation with multiple teams of technologists covering...