IT Security Engineer
On-siteHong Kong, Hong Kong
Job Summary
Conduct penetration testing across web, mobile, network, and API layers while executing red and purple team exercises. Perform vulnerability assessments, source code reviews, and security configuration checks for both cloud and on-premise environments. Review system architectures and document findings with remediation recommendations to improve security methodologies. Requires 1–2 years of offensive security experience, an offensive certification such as OSCP, and proficiency in Python, Bash, or PowerShell. Fluency in English is essential, with spoken Cantonese or Mandarin and written Chinese preferred. Financial services or regulated environment experience is a plus.
Required Qualifications
- 1–2 years experience in penetration testing, red teaming, or vulnerability assessment
- Bachelor's degree in CS, IT, or Cybersecurity
- At least one offensive certification: OSCP, OSWP, OSEP, GPEN, GWAPT, CREST, or eCPPT
- Scripting/programming: Python, Bash, or PowerShell
- Solid networking knowledge (TCP/IP, SSL/TLS, load balancers)
- Strong report writing and communication skills
- Fluent English (written/spoken)
- Fluent Cantonese or Mandarin (spoken)
- Written Chinese preferred
Desired Qualifications
- Financial services or regulated environment experience
- Knowledge of threat intelligence, reverse engineering, or SOC operations
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.