Senior Platform Security Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Platform Security Engineer (Cybersecurity): Building an enterprise security platform with automated services, APIs, infrastructure-as-code modules, and CI/CD guardrails, with an accent on DevSecOps, cloud security, and identity protection. Focus on designing zero-trust IAM and PAM models, securing Kubernetes workloads, automating threat detection and remediation, and enabling secure software delivery at scale.
Location: Onsite in Hong Kong (SAR)
Company
is a digital bank focused on customer-centered financial products, data security, privacy, and financial management tools.
What you will do
- Design, build, and maintain an enterprise-wide security-as-code platform and secure-by-default infrastructure modules.
- Integrate SAST, DAST, secret scanning, and other security controls into CI/CD pipelines.
- Architect IAM and PAM solutions using dynamic, ephemeral, and just-in-time access for human and machine identities.
- Deploy and optimize cloud security posture management and container security solutions across multi-cloud infrastructure.
- Partner with engineering teams to troubleshoot delivery bottlenecks, reduce false positives, and promote security-by-design practices.
- Provide technical leadership, mentoring, and stakeholder guidance for the DevSecOps squad.
Requirements
- 10+ years of experience in software engineering, infrastructure engineering, or cybersecurity, including at least 4 years in cloud security or DevSecOps.
- Expert AWS architecture and automated CI/CD experience, including EC2, RDS, S3, IAM, KMS, API Gateway, and Lambda.
- Strong knowledge of OIDC, SAML, OAuth2, PAM, zero-trust architecture, and identity security.
- Extensive Terraform or CloudFormation experience, including modular infrastructure-as-code development and drift detection.
- Production-grade programming in Python, Go, or Java, plus experience securing Kubernetes, Docker, and service-mesh workloads.
- Experience with cloud security monitoring, vulnerability management, SIEM, container intrusion detection, and both Windows and Linux administration.
Nice to have
- CKS, AWS or Azure Security Specialty, AWS Solutions Architect, or CISSP certification.
- Exposure to security tools and technologies related to vulnerability management, patching, SIEM, PAM, or container intrusion detection.
Culture & Benefits
- Agile, high-growth environment with evolving priorities and an emphasis on automation and innovation.
- Opportunities to coach and develop technology teams.
- Banking and lifestyle benefits.
- Customer-focused culture with strong attention to data security, privacy, and data ethics.
- Permanent full-time employment.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →