The Job
Develop, maintain, and enforce cybersecurity policies, guidelines, and procedures;
Conduct security risk assessments and audits, vulnerability assessments, and penetration tests;
Monitor and respond to cybersecurity threats and incidents in timely manner;
Implement and manage cybersecurity and IT infrastructure tools and technologies including M365 security, firewalls, WAF, IDPS, EDR, NDR, VPN, PAM, SIEM, servers and network, etc.;
Collaborate with cross-functional teams to integrate security controls;
Lead and coordinate cybersecurity and IT infrastructure projects and initiatives;
Deliver security awareness training, maintain and promote a security-conscious culture;
Stay current with the latest cybersecurity trends, threats, industry regulations and standards to ensure compliance;
Perform vendor management and procurement processes;
Coordinate with and monitor the performance of appointed suppliers and service providers;
Work with various internal and external stakeholders to manage and improve security posture;
Experience with cloud security and data protection strategies would be an advantage;
Provide management information and technical advice, and recommend proposals to IT management on enhancements of the cybersecurity and IT infrastructure;
Assist in the preparation of annual budget and monitoring of expenditure for cybersecurity and IT infrastructure upgrades, enhancements, and maintenance; and
Perform other duties as assigned.
The Person
A recognized degree in Computer Science or Information Technology, or equivalent;
At least six years’ solid hands-on experience in large-scale, complex and mission-critical IT infrastructure implementation and support, and/or cybersecurity management;
Experience in most of the following network and security domains:
- Data centre and access network including wired and wireless
- Firewalls, WAF, IDPS, and Anti-DDoS
- Security solutions and devices (e.g. DLP, EDR, NDR, PAM, SIEM, etc.)
- Security risk assessment and audit, vulnerability assessment, and penetration test
- Web application security
- Compliance with cybersecurity frameworks and standards (e.g. NIST, ISO 27001, GDPR, etc.)
Holder of professional qualifications (e.g. CEH/OSCE/OSCP, CCNA/CCNP, CISP/CISM/CISA/CISSP, GIAC/CREST, etc.) and cloud platform certifications would be advantageous;
Able to communicate concisely and clearly to suit the audience and occasions;
Keen to improve and add value to work;
Good interpersonal, problem solving and analytical skills; and
Mature, customer-oriented, independent, flexible and a good team player.
Candidates with less experience will be considered for the position of Senior Infrastructure Architect.
Remuneration Package
A competitive remuneration and benefits package including a discretionary performance-linked variable pay, annual leave, medical, dental and life insurance coverage, and MPF will be offered. All new appointments will be made on a two-year fixed-term contract initially prior to consideration for appointment on a non-fixed-term basis.
To Apply
Interested candidates are invited to apply via our online application. The closing date for application is 9 December 2025. Applicants not contacted for follow-up within 3 months after the closing date for application may assume that their applications are not successful. Applications not selected for further processing may be considered for other relevant openings in the future but their applications will not be retained for more than a period of two years after the closing date. For enquiries, please email at hrdmpfa@mpfa.org.hk.
The information provided will be kept confidential and only be used for those purposes relating to your application. Please visit our website for the details of the MPFA’s Personal Information Collection Statement at https://www.mpfa.org.hk/en/mpfa/joining-mpfa/job-vacancies/personal-information-collection-statement. The MPFA and its subsidiary are equal opportunities employers and welcome applications from all qualified candidates.