- (1)在安全運營團隊擔任第一線支援,就網絡安全事故和威脅進行監控、偵測、分析及應變工作;
- (2)支援和維護各類網絡安全工具和平台(例如SIEM、EDR、NDR、IDS、IPS、SOAR),確保其運作正常,並在這些工具和平台出現技術故障時進行檢修;
- (3)安裝和部署新的網絡安全解決方案及服務;
- (4)監控網絡安全工具和平台的日常安全警示及活動;調查安全警示,並在潛在安全事故出現時將事件上報至相應的團隊;
- (5)跟進跨團隊的事故應變行動,並協助分析根本原因;
- (6)針對基礎設施及系統進行弱點掃描,並執行緩解措施;
- (7)擬備文件,包括安裝手冊、操作程序、定期報告和調查報告;以及
- (8)執行主管指派的任何其他職務。
職責
- (1)To work in the Security Operation Team as the first line support for monitoring, detecting, analysing and responding to cybersecurity incidents and threats;
- (2)To support and maintain the normal operation of various cybersecurity tools and platforms, such as SIEM, EDR, NDR, IDS, IPS, SOAR, and troubleshoot for any technical issues on these tools and platforms;
- (3)To install and deploy new cybersecurity solutions and services;
- (4)To monitor the day-to-day security alerts and activities arising from cybersecurity tools and platforms; investigate the security alerts and escalate any cases with potential security incidents to corresponding teams;
- (5)To follow up incident response actions across teams and assist in root cause analysis;
- (6)To scan for infrastructure and system weaknesses and implement mitigation measures;
- (7)To prepare documentation, including installation manuals, operation procedures, periodic reports and investigation reports; and
- (8)To undertake any other tasks assigned by supervisors.
入職條件
- (1)持有本地大學頒授的資訊科技或電腦學學士學位,或具備同等學歷;
- (2)在香港中學文憑考試或香港中學會考中國語文科和英國語文科(2007年以前應為「課程乙」)取得第2等級(2007年以前應為「E級」)或以上成績,或具備同等成績;
- (3)取得上述學歷資格後,在資訊科技行業累積不少於三年的全職工作經驗,其中至少一年須從事網絡安全相關工作,且在網絡安全、應用程式安全、雲端安全、端點保護等領域擁有豐富知識;
- (4)在以下領域具備豐富的實務經驗:安全風險管理、安全解決方案,以及針對常見資訊科技技術(例如Linux/Windows、Active Directory、行動科技、雲端計算、網絡/應用系統防火牆、入侵偵測/防禦系統、負載平衡器、SSL VPN閘道、端點保護套件、資料外泄防護、分散式拒絕服務攻擊、進階持續性威脅、加密技術、勒索軟件、網絡安全標準等)的攻擊/防禦技術;
- (5)精通以下至少一個範疇:(i)操作安全資訊與事件管理(SIEM)或網絡安全相關工具,特別是Splunk或Elastic SIEM;(ii)為安全運營中心或網絡安全團隊提供一線/二線支援;以及(iii)處理安全事故應變工作,例如調查、遏制、根除及復修;
- (6)持有以下資格者將獲優先考慮:Certified Information Systems Security Professional (CISSP)/Certified Information Security Manager (CISM)/Certified Cloud Security Professional (CCSP)/Certified Information Security Professional (CISP)/Certified SOC Analyst (CSA)/Practical SOC Analyst Associate (PSAA);
- (7)具備良好的人際溝通和游說技巧,能有效令各持份者採納網絡安全解決方案,以達到營運目標;
- (8)具備良好的中、英文會話和書寫能力;以及
- (9)勤奮進取,具備良好的分析和解難能力。
- (1)A Hong Kong bachelor’s degree in Information Technology (IT) or Computer Studies, or equivalent;
- (2)Level 2 (Grade E before 2007) or above in both Chinese Language and English Language (Syllabus B before 2007) in the Hong Kong Diploma of Secondary Education Examination (HKDSEE) or the Hong Kong Certificate of Education Examination (HKCEE), or equivalent;
- (3)A minimum of 3 years’ full-time post-qualification work experience in the IT field, of which a minimum of 1 year should be in cybersecurity related areas, with strong knowledge of network security, application security, cloud security, endpoint protection, etc.;
- (4)Solid hands-on experience in the following areas: security risk management, security solutions, and attack/defense techniques on common IT technology, such as Linux/Windows, Active Directory, mobile technology, cloud computing, network/application firewalls, IDS/IPS, load balancers, SSL VPN, end-point protection suites, DLP, DDoS, APT, encryption technologies, ransomware and cybersecurity standards;
- (5)Proficient in at least one of the following areas:
- (i)operating SIEM or cybersecurity tools, especially Splunk or Elastic SIEM;
- (ii)providing first/second line support for security operation centres (SOCs) or cybersecurity teams; and
- (iii)handling security incident response activities, such as investigation, containment, eradication and remediation;
- (6)Preference will be given to holders of Certified Information Systems Security Professional (CISSP) / Certified Information Security Manager (CISM) / Certified Cloud Security Professional (CCSP) / Certified Information Security Professional (CISP) / Certified SOC Analyst (CSA) / Practical SOC Analyst Associate (PSAA);
- (7)Good interpersonal and persuasive skills in managing multiple stakeholders to adopt cybersecurity solutions effectively to meet operational targets;
- (8)Good oral and written communication skills in both Chinese and English; and
- (9)Diligent with great initiative and good analytical and problem solving abilities.
入職條件(註)
2007年前的香港中學會考中國語文科和英國語文科(課程乙) C級及E級成績,在行政上會分別被視為等同2007年或之後香港中學會考中國語文科和英國語文科第3級和第2級成績。



