Cybersecurity Specialist

Hong KOng
location

Our client, a leading IT services company is currently seeking to hire a Cybersecurity Specialist.

Responsible to own the security posture of containers and cloud-native infrastructure and become hands-on practitioner responsible for operating CNAPP platform, hardening Kubernetes environments, and embedding security controls across our containerized workloads.

Responsibilities

  • Operate and tune the CNAPP platform: runtime threat detection, vulnerability management, compliance posture, and cloud security posture management (CSPM)
  • Monitor container runtime behaviour, respond to alerts, and lead incident triage for cloud-native threats
  • Conduct regular cluster hardening reviews against CIS Kubernetes Benchmark and NSA/CISA Kubernetes Hardening Guidance
  • Maintain continuous visibility into image vulnerabilities across the container registry and production workloads using solution of image scanning
  • Triage and track CVEs through their full lifecycle — severity classification, patch coordination with engineering, and residual risk acceptance
  • Partner with DevOps and platform engineering teams to embed security requirements into infrastructure-as-code (Terraform, Helm, Kustomize)
  • Develop and maintain runbooks, playbooks, and security baseline documentation for the engineering community

Skills And Qualifications
  • Bachelor's degree in Computer Science, Information Security, Engineering, or a closely related discipline
  • Minimum 2 years of hands-on experience in cybersecurity roles focused on cloud-native or microservices environments
  • Experience with CNAPP platforms (like Sysdig, NeuVector, Aqua, Prisma Cloud, Lacework, Wiz etc) — configuration, policy management, and alert triage
  • Practical experience with container security concepts: image hardening, registry scanning, runtime protection, and supply chain risks
  • Fluent in English — written and spoken (documentation, cross-functional communication)
  • Fluent in Cantonese — spoken (team and stakeholder communication in Hong Kong)
Having the following experience will be an advantage
  • Any experience integrating security gates into CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins, Tekton): SAST, DAST, SCA, container scanning
  • Infrastructure-as-code security review: Terraform or Helm chart analysis
  • OWASP Top 10 and API Security Top 10 knowledge applied in microservices context
  • Understanding of authentication and authorisation patterns: OAuth 2.0, OIDC, JWT, mTLS