Contract Systems Analyst - IT Security, CISA, CISSP, CISP (C34401)


Hong Kong Island
1 year(s) work experience

Job Description

Project Nature:

  • IT projects and on-going support for a statutory body, Auxiliary Medical Service (AMS) and Civil Aid Service (CAS) on IT security related matters.

Duties:

Serve a contract assignment under InfoTech's headcount, full-time second to serve a statutory body; The appointed staff is required to work in the following areas:

  • Enhance, support and monitor suspicious events of IT security infrastructure including but not limited to end-point protection solution, end-point / network detection and response system (EDR/NDR), web application firewall (WAF), privileged account management system (PAM), centralised log management system, security information and event management system (SIEM), mobile device management system (MDM), web filtering system, patch management system, etc.;

  • Manage the security aspects of network infrastructure including network appliances and firewalls;

  • Manage security matters including configuration and hardening of servers and network appliances, recommend on application / program hardening;

  • Serve as security administrator in IT security organisations including the Information Security Steering Committee and IT Security Management Unit to provide updates on all IT security related matters;

  • Spell out, monitor and ensure necessary technical IT security controls are in place and functional throughout system development life-cycle and on-going system operations, in particular in the areas of access control, operations security, system acquisition / development / maintenance, business continuity, etc. Assist in user acceptance planning and execution in IT security perspectives. Ensure quality procedures, techniques and tools are used;

  • Review system development project deliverables, documentation and operating procedures, identify IT security shortfalls and recommend improvements;

  • Review and update the departmental IT security policies and guidelines according to the latest changes in Government-wide baseline or ad hoc circulars, and provide recommendations to plug the compliance gaps;

  • Coordinate application and infrastructure teams to produce and maintain IT security related system documentation including capacity management plan, up-to-date hardware and software list, configuration and network diagrams, etc.;

  • Monitor software end-of-support, produce migration plan, and ensure on-time completion of associated measures;

  • Identify new threats and known vulnerabilities, perform risk assessments to determine mitigation approach, update security risk register, ensure on-time completion of mitigation measures and reporting to supervisory bodies;

  • Conduct in-house IT security risk assessment and IT security awareness training, managing IT security risk assessment and audit (SRAA) exercises, privacy impact assessments (PIA), as well as compliance audit/check by external parties;

  • Provide first-line support for security incidents and coordinate disaster recovery drills and security incident drills;

  • Assist in procurement, setup, maintenance and support of IT equipment and services underpinning the security tools;

  • Provide technical advices to support latest IT security and business requirements;

  • Engage and collaborate with stakeholders to meet business objectives;

  • Carry out other technical and administrative duties assigned by the supervisor.

  • On-site or remote support out of office hours is required when necessary, which will be compensated by time-off in lieu.

Requirements:

The appointed staff should have:

  • Degree in computer subjects or related disciplines;

  • At least one of the industry-recognised IT security certifications (e.g. CISA, CISSP, CISP, etc.)

  • Hands-on experience in technical support for IT security infrastructure and network equipment (e.g. Cisco, H3C, Huawei, etc.);

  • Hands-on experience in IT security design, implementation and operations in application system development projects, preferably using the Government Cloud Infrastructure Services (GCIS);

  • Experience in the technology and security risks of cloud-native applications running in a virtualised and/or containerized environment;

  • Experience in compliance of government IT security policies and guidelines (e.g. S17, G3, SRAA, PIA), preferably for Tier 2 or Tier 3 systems;

  • Good command of written and spoken English and Chinese;

  • Good communication skills and customer service skills;

  • Independent, self-motivated and good sense of responsibility; and

  • Pleasant personality and good interpersonal skills.

  • The appointed staff will work mainly in Admiralty, Yau Ma Tei and Ho Man Tin, and may need to work in Wanchai, North Point, Kwun Tong, Cheung Sha Wan, Kowloon Bay and Sha Tau Kok when necessary.


Please apply by email or WhatsApp by quoting Job Title with InfoTech's Job Key No (one alphabet prefix with up to five digits) as subject.  You may directly apply online for this post at https://www.infotech.com.hk/itjs/job/fe-view.do?method=feView&jjKey=34401 

Email: itcareer@infotech.com.hk                         

Direct line for this post: (852) 3978 8032

General: (852) 2836 0363

WhatsApp: (852) 2836 0363

Address: 18/F, Tower 2, Lippo Centre, 89 Queensway, Hong Kong.

The information provided will be treated in strict confidence and be used only for consideration of your application for relevant / similar posts within the Group/ Company.


Job Function
Work Location Hong Kong Island
Education
Degree
Skills Analysis
Employment Type Contract
Industry IT / E-Business

About company
InfoTech Services ( HK ) Ltd. 資訊科技服務(香港)有限公司
InfoTech respects every job application. IT job seekers trust InfoTech and know that we are ready to help. We listen, speak your language and jargon, understand technical, pay level and career aspirations. InfoTech exists because of IT, InfoTech however executes search and selection by human, based on robust recruitment systems. InfoTech handles assignments with care, enthusiasm, diligence, ethics and professionalism.

InfoTech is well acquainted with development languages, scripts, frameworks, deployment/test tools, database, servers, virtualization, storage, networks, infrastructure and information security. InfoTech understands complex business logic and application flow, we appreciate architecture and methodologies. InfoTech serves an extensive client base covering leading banks, financial institutions, government bureaux, departments, subvented organizations, Chinese and multinational corporations, academic institute, vendors, systems integrators, etc.

InfoTech offers permanent placement, executive search and contract staff secondment services. InfoTech is one of the largest and longest established IT staff services and executive search companies in Hong Kong. Over our 32 years’ corporate history, it is believed that about a third of the IT working population in Hong Kong has been served by InfoTech, no matter as job seekers, placed candidates, contract staff or employers.

IT talent is offering the right ICT solutions for society, InfoTech endeavours to provide the right career for IT talent. Count on InfoTech, the best-in-class IT career partner now.

InfoTech 尊重每位求職者。IT求職者都信賴 InfoTech,深信 InfoTech 隨時能夠幫助他們。求職者知道 InfoTech 懂 IT 術語、技術和薪酬水平。InfoTech 能耐心聆聽求職者對職業生涯的期望和抱負。IT 讓 InfoTech 存在,InfoTech 卻堅持人性化的搜索與篩選,建基於先進的招聘系統。InfoTech 會以謹慎、熱衷、忠誠、道德和專業的態度來處理每個招聘項目。

InfoTech 熟悉開發語言、腳本、框架、發佈和測試工具、數據庫、服務器、虛擬機、存儲、網路、基礎設施和資訊安全。InfoTech 明白複雜的商業邏輯和應用流程,瞭解系統架構與方法。InfoTech 服務各大銀行、金融機構、政府部門、資助機構、中國和跨國公司、科研院所、大學、厰商、系統集成商等。

InfoTech 的服務包括招聘、獵頭、派遣和租賃等。InfoTech 是香港其中一間最大和歷史最悠久的 IT 人才服務機構。在香港,約三分之一的 IT 人才,無論是以求職者、合約派遣員工或者是以僱主的身份,都曾經使用過 InfoTech 的服務。

IT人才正在為社會提供適當的 ICT 解決方案,InfoTech 同時致力為 IT 人才提供理想的職業。要信賴最好的 IT 職業合作夥伴 InfoTech,來開拓您職業生涯的新篇章。

Please apply to the relevant e-mail mailbox and quote InfoTech's Job Key No (two alphabet prefix with four digits) and Position as subject. Check other InfoTech hot jobs, press here.


Main: (852) 2836 0363
WhatsApp: (852) 9758 2775

Address: 18/F, Tower 2, Lippo Centre, 89 Queensway, HK