Now hiring

Security Operations Specialist (Hong Kong, HK, HK) @ HKT Services Limited

Hong Kong, HK, HKOnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

<p><strong>Responsible Domains as below:<br><br></strong></p> <p><strong>1. Monitoring &amp; Detection</strong></p> <ul> <li>Monitor security alerts from various sources, including SIEM (Security Information and Event Management), EDR (Endpoint Detection and Response), firewalls, and IDS/IPS systems.</li> <li>Triage incoming alerts to distinguish between benign events and genuine security incidents.</li> <li>Maintain and tune use cases within the SIEM to reduce false positives and improve detection capabilities.<br><br></li> </ul> <p><strong>2. Incident Response &amp; Management</strong></p> <ul> <li>Lead the technical response to security incidents, including malware outbreaks, ransomware, phishing campaigns, data leaks, and unauthorized access.</li> <li>Perform digital forensics, including disk and memory analysis, to determine the root cause and scope of an incident.</li> <li>Contain, eradicate, and recover from security incidents, ensuring business continuity.</li> <li>Document every step of the incident lifecycle, creating detailed after-action reports and timelines.<br><br></li> </ul> <p><strong>3. Threat Hunting &amp; Analysis</strong></p> <ul> <li>Proactively search for signs of advanced persistent threats (APTs) or malicious activity that may have evaded existing security controls.</li> <li>Analyze threat intelligence feeds to understand the current threat landscape and anticipate potential attacks against the organization.<br><br></li> </ul> <p><strong>4. Communication &amp; Reporting</strong></p> <ul> <li>Communicate technical findings to non-technical stakeholders, including management and legal teams, during active incidents.</li> <li>Prepare post-incident reports that include root cause analysis, lessons learned, and remediation recommendations.</li> <li>Escalate critical incidents according to the incident response plan.<br><br></li> </ul> <p><strong>5. Process Improvement</strong></p> <ul> <li>Recommend and implement improvements to security tools, policies, and playbooks based on lessons learned from incidents.</li> <li>Collaborate with the IT and Development teams to ensure vulnerabilities are patched and configurations are hardened.</li> </ul> <p><strong><br><br>Qualifications &amp; Requirements<br><br></strong></p> <ol> <li><strong>Education:</strong> Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or a related field (or equivalent practical experience).</li> <li><strong>Experience:</strong> 3+ years of experience in information security, with a focus on incident response, security operations, or threat analysis.</li> <li><strong>Tools:</strong> Proficiency with SIEM platforms (e.g.,ELK), EDR tools (e.g., CrowdStrike, SentinelOne, Defender ATP), and NDR tools (e.g., Darktrace).</li> <li><strong>Forensics:</strong> Experience with digital forensics tools and techniques (e.g., EnCase, FTK, Volatility, Autopsy) is a plus.</li> <li><strong>Operating Systems:</strong> Deep understanding of Windows and Linux operating systems, including logging mechanisms, file systems, and common persistence mechanisms.</li> <li><strong>Cloud:</strong> Familiarity with cloud security and incident response in AWS, AliCloud, or GCP environments.</li> <li><strong>Scripting:</strong> Proficiency in scripting languages such as Python, PowerShell, or Bash for automation and log analysis.</li> <li><strong>Frameworks:</strong> Solid understanding of the Cyber Kill Chain, MITRE ATT&amp;CK framework, and NIST incident response lifecycle.</li> <li><strong>Analytical Thinking:</strong> Exceptional problem-solving skills and the ability to think like an attacker.</li> <li><strong>Communication:</strong> Excellent written and verbal communication skills; ability to explain complex technical issues to a non-technical audience.</li> <li><strong>Stress Management:</strong> Ability to remain calm and methodical under pressure during active security breaches. Must be willing to work during non-office hours and ad-hoc request during incident support.</li> <li><strong>Certifications (Preferred but not mandatory)</strong></li> </ol> <ul> <li>GIAC Certified Incident Handler (GCIH)</li> <li>Certified Information Systems Security Professional (CISSP)</li> <li>CompTIA Security+</li> <li>Certified Ethical Hacker (CEH)</li> </ul>

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores