Jobiglo

No results.

IT Security Analyst – Penetration Testing & Cloud Security

CLSA · Île de Hong Kong

New
Mid 🇬🇧 English
Burp Suite Metasploit ZAP Qualys Tenable/Nessus Nmap Microsoft Azure AWS GCP Tencent Cloud Microsoft 365 OpenAI GPT Anthropic Claude Google Gemini Microsoft Copilot Amazon Bedrock Grok Microsoft Entra Okta Cisco Duo AWS WAF Azure WAF Zscaler Palo Alto Networks Microsoft Entra Private Access

Job description

About the role

We are looking for an IT Security Analyst who is proactive, self‑motivated, and has a willing‑to‑do attitude to join an international IT security team. You will contribute to the company’s cyber‑security strategy and operations, managing a portfolio of tools across identity access management, network intrusion detection, endpoint protection, email security, data leakage prevention, application security, and other controls.

Key responsibilities

  • Conduct penetration testing, vulnerability scanning and code reviews on on‑premise and cloud systems.
  • Perform architecture reviews, security assessments and source‑code analysis for IT system designs.
  • Run cyber‑attack simulations using red‑team, blue‑team and purple‑team exercises.
  • Prepare and present reports on identified vulnerabilities with remediation recommendations.
  • Assist in the design, planning and implementation of security solutions such as WAFs, SSO/MFA, biometric authentication, cloud PKI, malware sandboxing, AI red‑team tools and Zero‑Trust architectures.
  • Provide first‑ and second‑level support for security tools, including penetration‑test and vulnerability‑scanning platforms.
  • Act as subject‑matter expert for selected security products and maintain strong relationships with IT and business stakeholders.

Required profile

  • Bachelor’s degree in IT, Computer Science or related field.
  • 3‑5 years of hands‑on cybersecurity experience, preferably with exposure to regulatory environments.
  • Relevant certifications such as CISSP, CISA, CISM; offensive‑security certifications (OSCP, OSWP, OSEP) are a plus.
  • Strong communication skills in English and Chinese, with proven project‑management abilities.
  • Experience in offensive security services across web, network, server, client, mobile, AI and IoT environments.

Required skills

  • Penetration‑testing and vulnerability‑scanning tools: Burp Suite, Metasploit, ZAP, Qualys, Tenable/Nessus, Nmap.
  • Cloud platforms: Microsoft Azure, AWS, GCP, AliCloud, Tencent Cloud; Microsoft 365 services.
  • AI tools/models: OpenAI GPT, Anthropic Claude, Google Gemini, Microsoft Copilot, Amazon Bedrock, Grok.
  • Identity & access management: Microsoft Entra, Okta, Cisco Duo, Azure AD.
  • Web Application Firewalls and DDoS protection: Akamai, Cloudflare, AWS WAF, Azure WAF.
  • Zero‑Trust solutions: Zscaler, Palo Alto Networks, Microsoft Entra Private Access.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec CLSA.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Explore further

Salaries, guides and searches in Hong Kong.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

By continuing, you accept our terms of use.

Already have an account? Login

💬 Chat with us on Telegram Chat on WhatsApp

Published 2 hours ago

Expires 1 month from now

1 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

CLSA

Île de Hong Kong