- (1)負責管理安全運營團隊,就網絡安全事故和威脅進行監控、偵測、分析及應變工作;
- (2)支援和維護各類網絡安全工具和平台(例如SIEM、EDR、NDR、IDS、IPS、SOAR),確保其運作正常,設定正確,效能妥為優化,能有效偵測和應付威脅;
- (3)設計、採購、安裝和部署新的網絡安全解決方案及服務;
- (4)管理日常網絡安全警示,控制誤報率,即時處理異常狀況和潛在威脅,並擔任高度嚴重網絡安全事故的主要聯絡人;
- (5)在技術層面領導並協調整個網絡安全事故的應變流程,包括偵測、遏制以至根除及復原;
- (6)參與網絡安全威脅狩獵活動,識別自動化工具可能忽略的隱藏威脅;
- (7)促進團隊成員之間的知識轉移,以維持團隊的工作表現;
- (8)擬備、審核和更新文件,包括程序、手冊、標準、定期報告和調查報告;
- (9)處理查詢及投訴;以及
- (10)執行主管指派的任何其他職務。
職責
- (1)To lead the Security Operation Team in monitoring, detecting, analysing and responding to cybersecurity incidents and threats;
- (2)To support and maintain the normal operation of various cybersecurity tools and platforms, such as SIEM, EDR, NDR, IDS, IPS, SOAR, and ensure that they are properly configured and optimised for effective threat detection and response;
- (3)To design, procure, install and deploy new cybersecurity solutions and services;
- (4)To manage day-to-day cybersecurity alerts, control false positive rates and instance response to anomalies and potential threats, and serve as the primary contact point for high-severity cybersecurity incidents;
- (5)To lead and orchestrate the entire cybersecurity incident response process, from detection and containment to eradication and recovery, in technical aspect;
- (6)To participate in cybersecurity threat hunting activities and identify hidden threats potentially overlooked by automated tools;
- (7)To facilitate knowledge transfer among team members to maintain the performance of the team;
- (8)To prepare, review and update documentation, including procedures, manuals, standards, periodic reports and investigation reports;
- (9)To handle enquiries and complaints; and
- (10)To undertake any other tasks assigned by supervisors.
入職條件
- (1)持有本地大學頒授的資訊科技或電腦學學士學位,或具備同等學歷;
- (2)在香港中學文憑考試或香港中學會考中國語文科和英國語文科(2007年以前應為「課程乙」)取得第2等級(2007年以前應為「E級」)或以上成績,或具備同等成績;
- (3)取得上述學歷資格後,在資訊科技行業累積不少於五年的全職工作經驗,其中至少三年須從事網絡安全相關工作,且在網絡安全、應用程式安全、雲端安全、端點保護等領域擁有豐富知識;
- (4)在以下領域具備豐富的實務經驗:安全風險管理、安全解決方案,以及針對常見資訊科技技術(例如Linux/Windows、Active Directory、行動科技、雲端計算、網絡/應用系統防火牆、入侵偵測/防禦系統、負載平衡器、SSL VPN閘道、端點保護套件、資料外泄防護、分散式拒絕服務攻擊、進階持續性威脅、加密技術、勒索軟件、網絡安全標準等)的攻擊/防禦技術;
- (5)精通以下至少一個範疇:(i)操作安全資訊與事件管理(SIEM)或網絡安全相關工具,特別是Splunk或Elastic SIEM;(ii)為安全運營中心或網絡安全團隊提供一線/二線支援;以及(iii)處理安全事故應變工作,例如調查、遏制、根除及復修;
- (6)持有以下資格者將獲優先考慮:Certified Information Systems Security Professional (CISSP)/Certified Information Security Manager (CISM)/Certified Cloud Security Professional (CCSP)/Certified Information Security Professional (CISP)/Certified SOC Analyst (CSA)/Practical SOC Analyst Associate (PSAA);
- (7)具備良好的人際溝通和游說技巧,能有效令各持份者採納網絡安全解決方案,以達到營運目標;
- (8)具備良好的中、英文會話和書寫能力;以及
- (9)勤奮進取,具備良好的分析和解難能力。
- (1)A Hong Kong bachelor’s degree in Information Technology (IT) or Computer Studies, or equivalent;
- (2)Level 2 (Grade E before 2007) or above in both Chinese Language and English Language (Syllabus B before 2007) in the Hong Kong Diploma of Secondary Education Examination (HKDSEE) or the Hong Kong Certificate of Education Examination (HKCEE), or equivalent;
- (3)A minimum of 5 years’ full-time post-qualification work experience in the IT field, of which a minimum of 3 years should be in cybersecurity related areas, with strong knowledge of network security, application security, cloud security, endpoint protection, etc.;
- (4)Solid hands-on experience in the following areas: security risk management, security solutions, and attack/defense techniques on common IT technology, such as Linux/Windows, Active Directory, mobile technology, cloud computing, network/application firewalls, IDS/IPS, load balancers, SSL VPN, end-point protection suites, DLP, DDoS, APT, encryption technologies, ransomware and cybersecurity standards;
- (5)Proficient in at least one of the following areas:
- (i)operating SIEM or cybersecurity tools, especially Splunk or Elastic SIEM;
- (ii)providing first/second line support for security operation centres (SOCs) or cybersecurity teams; and
- (iii)handling security incident response activities, such as investigation, containment, eradication and remediation;
- (6)Preference will be given to holders of Certified Information Systems Security Professional (CISSP) / Certified Information Security Manager (CISM) / Certified Cloud Security Professional (CCSP) / Certified Information Security Professional (CISP) / Certified SOC Analyst (CSA) / Practical SOC Analyst Associate (PSAA);
- (7)Good interpersonal and persuasive skills in managing multiple stakeholders to adopt cybersecurity solutions effectively to meet operational targets;
- (8)Good oral and written communication skills in both Chinese and English; and
- (9)Diligent with great initiative and good analytical and problem solving abilities.
入職條件(註)
2007年前的香港中學會考中國語文科和英國語文科(課程乙) C級及E級成績,在行政上會分別被視為等同2007年或之後香港中學會考中國語文科和英國語文科第3級和第2級成績。



