Cybersecurity Specialist
Hong KOng
locationOur client, a leading IT services company is currently seeking to hire a Cybersecurity Specialist.
Responsible to own the security posture of containers and cloud-native infrastructure and become hands-on practitioner responsible for operating CNAPP platform, hardening Kubernetes environments, and embedding security controls across our containerized workloads.
Responsibilities
- Operate and tune the CNAPP platform: runtime threat detection, vulnerability management, compliance posture, and cloud security posture management (CSPM)
- Monitor container runtime behaviour, respond to alerts, and lead incident triage for cloud-native threats
- Conduct regular cluster hardening reviews against CIS Kubernetes Benchmark and NSA/CISA Kubernetes Hardening Guidance
- Maintain continuous visibility into image vulnerabilities across the container registry and production workloads using solution of image scanning
- Triage and track CVEs through their full lifecycle — severity classification, patch coordination with engineering, and residual risk acceptance
- Partner with DevOps and platform engineering teams to embed security requirements into infrastructure-as-code (Terraform, Helm, Kustomize)
- Develop and maintain runbooks, playbooks, and security baseline documentation for the engineering community
Skills And Qualifications
- Bachelor's degree in Computer Science, Information Security, Engineering, or a closely related discipline
- Minimum 2 years of hands-on experience in cybersecurity roles focused on cloud-native or microservices environments
- Experience with CNAPP platforms (like Sysdig, NeuVector, Aqua, Prisma Cloud, Lacework, Wiz etc) — configuration, policy management, and alert triage
- Practical experience with container security concepts: image hardening, registry scanning, runtime protection, and supply chain risks
- Fluent in English — written and spoken (documentation, cross-functional communication)
- Fluent in Cantonese — spoken (team and stakeholder communication in Hong Kong)
- Any experience integrating security gates into CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins, Tekton): SAST, DAST, SCA, container scanning
- Infrastructure-as-code security review: Terraform or Helm chart analysis
- OWASP Top 10 and API Security Top 10 knowledge applied in microservices context
- Understanding of authentication and authorisation patterns: OAuth 2.0, OIDC, JWT, mTLS
