Назад
Company hidden
1 день назад

Senior Platform Security Engineer (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
China
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Senior Platform Security Engineer (Cybersecurity): Building an enterprise security platform with automated services, APIs, infrastructure-as-code modules, and CI/CD guardrails, with an accent on DevSecOps, cloud security, and identity protection. Focus on designing zero-trust IAM and PAM models, securing Kubernetes workloads, automating threat detection and remediation, and enabling secure software delivery at scale.

Location: Onsite in Hong Kong (SAR)

Company

hirify.global is a digital bank focused on customer-centered financial products, data security, privacy, and financial management tools.

What you will do

  • Design, build, and maintain an enterprise-wide security-as-code platform and secure-by-default infrastructure modules.
  • Integrate SAST, DAST, secret scanning, and other security controls into CI/CD pipelines.
  • Architect IAM and PAM solutions using dynamic, ephemeral, and just-in-time access for human and machine identities.
  • Deploy and optimize cloud security posture management and container security solutions across multi-cloud infrastructure.
  • Partner with engineering teams to troubleshoot delivery bottlenecks, reduce false positives, and promote security-by-design practices.
  • Provide technical leadership, mentoring, and stakeholder guidance for the DevSecOps squad.

Requirements

  • 10+ years of experience in software engineering, infrastructure engineering, or cybersecurity, including at least 4 years in cloud security or DevSecOps.
  • Expert AWS architecture and automated CI/CD experience, including EC2, RDS, S3, IAM, KMS, API Gateway, and Lambda.
  • Strong knowledge of OIDC, SAML, OAuth2, PAM, zero-trust architecture, and identity security.
  • Extensive Terraform or CloudFormation experience, including modular infrastructure-as-code development and drift detection.
  • Production-grade programming in Python, Go, or Java, plus experience securing Kubernetes, Docker, and service-mesh workloads.
  • Experience with cloud security monitoring, vulnerability management, SIEM, container intrusion detection, and both Windows and Linux administration.

Nice to have

  • CKS, AWS or Azure Security Specialty, AWS Solutions Architect, or CISSP certification.
  • Exposure to security tools and technologies related to vulnerability management, patching, SIEM, PAM, or container intrusion detection.

Culture & Benefits

  • Agile, high-growth environment with evolving priorities and an emphasis on automation and innovation.
  • Opportunities to coach and develop technology teams.
  • Banking and lifestyle benefits.
  • Customer-focused culture with strong attention to data security, privacy, and data ethics.
  • Permanent full-time employment.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →