Vulnerability Management: Run regular security scans, identify and prioritize vulnerabilities, and recommend actionable fixes for IT and OT systems.
System Protection & Hardening: Design, set up, and maintain security controls, as well as build technical guidelines and documentation.
SIEM & Monitoring: Connect system log sources to the SIEM platform, build custom alerts and dashboards, and analyze security events.
Data Loss Prevention (DLP): Manage and tune DLP policies to keep sensitive data secure.
Incident Response: Investigate, respond to, and resolve security threats and incidents.
System & Compliance Reviews: Conduct security reviews for new projects or system changes to ensure compliance with standards and regulations.
Team Collaboration: Partner with engineering teams, system owners, and vendors to integrate security into daily operations.
Reporting & Trends: Track security metrics (e.g., vulnerabilities, incident trends) for management and stay up to date on new cyber threats.
Education: Degree in Computer Science, IT, Cybersecurity, Engineering, or a related field.
Experience: At least 5 years of hands-on experience in IT/OT cybersecurity.
Core Technical Skills:
Strong background in vulnerability scanning, SIEM monitoring, log analysis, and incident investigation.
solid understanding of Windows, Linux, networking, firewalls, network segmentation, and endpoint security.
Experience with DLP configuration and monitoring.
OT / Industrial Knowledge (Bonus): Familiarity with industrial control systems (SCADA, PLC) or protocols (Modbus, DNP3, PROFINET, OPC) is a plus.
Certifications (Bonus): CISSP, CISM, GICSP, Security+, or similar certifications are advantageous.
Soft Skills: Problem-solving mindset, self-motivated, good project coordination skills, and comfortable managing vendors.
Languages: Fluency in English (written and spoken). Knowledge of Chinese (Cantonese/Putonghua) is an advantage.
