Manager, Information Security
About Dah Sing Group
The Dah Sing Group is a leading financial services group in Hong Kong offering banking, insurance, financial and other related services through its growing network of over 70 branches in Hong Kong, Macau and Mainland China.
Our currency is caring, teamwork and progressiveness. We accept that everyone is unique and different in talent, but alike in the capacity for growth. Our task is to shape a culture that creates a sense of pride in achieving something beyond just a job, and an environment where you can be your true and authentic self, like at home.
Role Purpose
Support the bank's cyber defence functions by assisting with MSSP operations, performing security assurance tasks, and participating in purple team exercises. This role provides hands on exposure to security monitoring, control testing, and threat based validation activities in a regulated banking environment.
Key Responsibilities
• Monitor MSSP alerts and escalations, ensuring timely follow up with internal teams.
• Perform initial triage security events under supervision.
• Assist in maintaining SIEM/EDR use cases and updating detection rules.
• Prepare MSSP performance summaries and KPI reports.
• Support control testing activities across EDR, network security, and application security.
• Collect evidence from system owners and validate completeness and accuracy.
• Assist in documenting test results, findings, and remediation tracking.
• Help maintain assurance documentation, checklists, and compliance records.
• Participate in purple team exercises by documenting attack steps, detection results, and gaps.
• Assist in mapping detection coverage to MITRE ATT&CK techniques.
• Update detection logic and playbooks based on purple team outcomes.
• Lead the end to end vulnerability management lifecycle: discovery, validation, risk rating, tracking, and closure.
• Coordinate patch cycles
• Conduct proactive threat hunting exercises to identify and mitigate advanced persistent threats (APTs) and other sophisticated attack vectors.
• Ability to conduct attack simulations (e.g., Metasploit, Cobalt strike) to validate detection coverage.
Qualifications & Experience
• Bachelor's degree in Information Security, Computer Science, or related discipline.
• 3-5 years of experience in cybersecurity, SOC, IT operations, or risk/compliance.
• Basic understanding of SIEM, EDR, network security, and common attack techniques.
• Familiarity with security frameworks (NIST CSF, ISO 27001, OWASP) is an advantage.
• Experience in banking or finance sectors is a plus
• Possession of relevant of HKMA ECF certifications in cybersecurity.
Please note that only shortlisted candidates will be notified.
The Dah Sing Group is a leading financial services group in Hong Kong offering banking, insurance, financial and other related services through its growing network of over 70 branches in Hong Kong, Macau and Mainland China.
Our currency is caring, teamwork and progressiveness. We accept that everyone is unique and different in talent, but alike in the capacity for growth. Our task is to shape a culture that creates a sense of pride in achieving something beyond just a job, and an environment where you can be your true and authentic self, like at home.
Role Purpose
Support the bank's cyber defence functions by assisting with MSSP operations, performing security assurance tasks, and participating in purple team exercises. This role provides hands on exposure to security monitoring, control testing, and threat based validation activities in a regulated banking environment.
Key Responsibilities
• Monitor MSSP alerts and escalations, ensuring timely follow up with internal teams.
• Perform initial triage security events under supervision.
• Assist in maintaining SIEM/EDR use cases and updating detection rules.
• Prepare MSSP performance summaries and KPI reports.
• Support control testing activities across EDR, network security, and application security.
• Collect evidence from system owners and validate completeness and accuracy.
• Assist in documenting test results, findings, and remediation tracking.
• Help maintain assurance documentation, checklists, and compliance records.
• Participate in purple team exercises by documenting attack steps, detection results, and gaps.
• Assist in mapping detection coverage to MITRE ATT&CK techniques.
• Update detection logic and playbooks based on purple team outcomes.
• Lead the end to end vulnerability management lifecycle: discovery, validation, risk rating, tracking, and closure.
• Coordinate patch cycles
• Conduct proactive threat hunting exercises to identify and mitigate advanced persistent threats (APTs) and other sophisticated attack vectors.
• Ability to conduct attack simulations (e.g., Metasploit, Cobalt strike) to validate detection coverage.
Qualifications & Experience
• Bachelor's degree in Information Security, Computer Science, or related discipline.
• 3-5 years of experience in cybersecurity, SOC, IT operations, or risk/compliance.
• Basic understanding of SIEM, EDR, network security, and common attack techniques.
• Familiarity with security frameworks (NIST CSF, ISO 27001, OWASP) is an advantage.
• Experience in banking or finance sectors is a plus
• Possession of relevant of HKMA ECF certifications in cybersecurity.
Please note that only shortlisted candidates will be notified.
Job ID 3989
The Dah Sing Financial Group is a leading financial services group in Hong Kong, active in providing banking, insurance, financial and other related s...
More jobs From Dah Sing Financial Group
Dah Sing Financial Group
Hong Kong
Dah Sing Financial Group
Hong Kong
Dah Sing Financial Group
Hong Kong
Dah Sing Financial Group
Hong Kong
Dah Sing Financial Group
Hong Kong
Dah Sing Financial Group
Hong Kong
Dah Sing Financial Group
Hong Kong
Dah Sing Financial Group
Hong Kong
Boost your career
Find thousands of job opportunities by signing up to eFinancialCareers today.More Jobs Like This