Systems Analyst

BID ref: 60489-2

2026-08-14Closing date
Location Mainly in Admiralty, Yau Ma Tei and Ho Man Tin, and may need to work in Wanchai, North Point, Kwun T

Responsibilities:
(T26) The appointed staff is required to work in the following areas: 1. Enhance, support and monitor threats and suspicious events of IT security infrastructure including but not limited to end-point protection solution, end-point / network detection and response system (EDR/NDR), web application firewall (WAF), privileged account management system (PAM), centralised log management system, security information and event management system (SIEM), mobile device management system (MDM), web filtering system, patch management system, etc.; 2. Manage the security aspects of network infrastructure including network appliances and firewalls; 3. Manage security matters including configuration and hardening of servers and network appliances, recommend on application / program hardening; 4. Serve as security administrator in IT security organisations including the Information Security Steering Committee and IT security management unit to provide updates on all IT security related matters; 5. Spell out, monitor and ensure necessary technical IT security controls are in place and functional throughout system development life-cycle and on-going system operations, in particular in the areas of access control, operations security, system acquisition / development / maintenance, business continuity, etc. Assist in user acceptance planning and execution in IT security perspectives. Ensure quality procedures, techniques and tools are used; 6. Review system development project deliverables, documentation and operating procedures, identify IT security shortfalls and recommend improvements; 7. Review and update the departmental IT security policies and guidelines according to the latest changes in Government-wide baseline or ad hoc circulars, and provide recommendations to plug the compliance gaps. 8. Coordinate application and infrastructure teams to produce and maintain IT security related system documentation including capacity management plan, up-to-date hardware and software list, configuration and network diagrams, etc.; 9. Monitor software end-of-support, produce migration plan, and ensure on-time completion of associated measures; 10. Identify new threats and known vulnerabilities, carry out technical assessments, perform risk assessments to determine mitigation approach, update security risk register, ensure on-time completion of mitigation measures and reporting to supervisory bodies; 11. Conduct in-house IT security risk assessment and IT security awareness training, managing IT security risk assessment and audit (SRAA) exercises, privacy impact assessments (PIA), as well as compliance audit/check by external parties; 12. Provide first-line support for security incidents; coordinate and lead disaster recovery drills and security incident drills; 13. Assist in procurement, setup, maintenance and support of IT equipment and services underpinning the security tools; 14. Provide technical advices to support latest IT security and business requirements; 15. Engage and collaborate with stakeholders to meet IT security related objectives; and 16. Carry out other technical and administrative duties assigned by the supervisor. Remark: On-site or remote support out of office hours is required when necessary, which will be compensated by time-off in lieu.

Requirements:
The appointed staff should have: 1. degree in computer subjects or related disciplines; 2. at least one of the industry-recognised IT security certifications (e.g. CISA, CISSP, CISP, etc.); 3. hands-on experience in technical support for IT security infrastructure, network equipment and security assessment tools (e.g., Cisco, H3C, Palo-Alto, Huawei, Nessus, OWASP Zap, etc.); 4. more than 3 years of hands-on experience working in the technology risk team, security operation team or security management unit of a sizeable organisation; 5. hands-on experience in IT security design, implementation and operations in application system development projects, preferably using the Government Cloud Infrastructure Services (GCIS) and GCIS Diversified Cloud Infrastructure (DCI); 6. experience in the technology and security risks of cloud-native applications running in a virtualised and/or containerized environment; 7. experience in compliance of government IT security policies and guidelines (e.g. S17, G3, SRAA, PIA), preferably for Tier 2 or Tier 3 systems; 8. experience in review and update IT security related documents; 9. good command of written and spoken English and Chinese; 10. good communication skills and customer service skills; 11. Conscientious, responsible, detail-oriented and ability to work seriously and independently; 12. pleasant personality, self-motivated and good interpersonal skills. The appointed staff will work mainly in Admiralty, Yau Ma Tei and Ho Man Tin, and may need to work in Wanchai, North Point, Kwun Tong, Cheung Sha Wan, Kowloon Bay and Sha Tau Kok when necessary.

Technical skills:
Anti-Virus Technology (36), Client Service (24), Endpoint Security Solutions (12), Exp. in Managing Corporate IT Security Framework (12), Intruder Detection/Alert Technology (24), IT Audit (24), IT Security (48), IT Security Scanning Tools (24), Network & System Management (36), Security Incident Detection and Handling (24), Security Risk Assessment and Audit (24), Work experience with/in the Government (12)