- Blockchain Financial Platform
- Security Ownership
- Security Depth and Credibility
Our client, a financial organization in Hong Kong is hiring an
IT Security Specialist to support the delivery and ongoing security of mission-critical platforms used across the local capital markets ecosystem. As part of its next phase of growth, it is launching a
new blockchain-based platform, working closely with an external technology vendor.
This key hire will act as the
internal security authority, responsible for accepting vendor delivery from a security perspective and ensuring the platform meets regulatory, operational, and risk requirements.
Key Responsibilities: - Perform penetration testing, red teaming activities, and vulnerability assessments across systems, networks, applications, and new platforms.
- Conduct internal security risk assessments and identify security, operational, and compliance gaps.
- Act as the security lead during vendor delivery, reviewing architecture, designs, test results, and remediation activities.
- Collaborate with external vendors on security assessments, audits, and follow-up remediation.
- Propose and drive security mitigations, enhancements, and hardening measures across infrastructure and applications.
- Participate in secure architecture design, solution research, and technical implementation activities.
- Develop, update, and maintain security policies, standards, procedures, and guidelines in line with regulatory expectations.
- Support security awareness and best-practice adoption across technology and non-technical stakeholders.
Requirements: - Degree in Computer Science, Engineering, or a related discipline.
- Experience in cybersecurity consulting, security operations, solution delivery, or complex technology projects.
- Hands-on experience with penetration testing tools such as Metasploit, Burp Suite, and Nmap.
- Strong foundation across operating systems, networks, databases, and cloud environments.
- Practical experience in system hardening, vulnerability management, and secure configuration.
- Strong analytical mindset with the ability to assess risk from technical, business, and end-user perspectives.
- Confident communicator with strong written, verbal, and presentation skills.
- Prior client-facing or consulting experience is highly advantageous.
- Security certifications such as CISSP, CISA, CISP, or OSCP are preferred.
- Fluency in Cantonese is required.
Why This Role? - Exposure to financial market infrastructure.
- Hands-on involvement in a blockchain-enabled platform supporting bond and debt securities workflows.
- Opportunity to work closely with regulators, vendors, and senior stakeholders on high-impact security decisions.