Systems Analyst
BID ref: 60980-1
Responsibilities:
(T26) The proposed staff shall take a leading role of facilitating the project implementation of the Mobile Device Management (MDM) and Endpoint Detection and Response (EDR). In addition, the staff will assume security engineering responsibilities, including the design, implementation, continuous improvement, and auditing of security controls such as vulnerability management, incident response, and compliance with government security policies and standards. (a) Technology Research & Technical Specs: Conduct deep technology research on the Mobile Device Management (MDM) and Endpoint Detection and Response (EDR) products/solutions, specialized distributed topologies, and hyper converged virtualized infrastructure. Draft precise technical specifications for all related IT procurement and design blueprints. (b) Endpoint Devices & Infrastructure Integration: Lead the technical setup, detailed system configuration, and hands-on system integration of the combined Windows-based platform and Android-based platform (EDR, MDM, and app-based VPN gateway) over the Diversified Cloud Infrastructure of DPO (Huawei-supported virtualized platform), verifying alignment with existing CSD infrastructure and central IT security policies. (c) Implementation & Testing: Coordinate multi-party integration workflows across technical users, government Bureau/Departments (B/Ds), and system vendors. Take charge of core end-to-end implementation activities including requirements analysis, layout design, technical training, user acceptance testing (UAT), and deployment planning (d) Operational Duties: Fulfill any other system administration, engineering, or supportive duties as assigned by infrastructure and project supervisors. (e) Cybersecurity Duties: Collaborate with cross-functional teams to ensure integration of security requirements into business process and projects. Coordinate multi-party to well-prepare for annual Hong Kong Attack and Defense Drill. Conduct regular security assessments, audits and inspections to identify gaps and areas for improvement. (f) Information Security: Ensure security tools integrate effectively with iCRMS and its infrastructure to support detection, response, and governance needs. Support internal audits, external assessments, and SRAA activities.
Requirements:
(a) The proposed candidate must possess solid working experience in the following domains: i. Development, maintenance, performance tuning, and technical production support of large-scale endpoint device management and detection/response solution. ii. System administration across complex enterprise virtualization platform, Kylin OS, Windows Server, and Linux ecosystems, and cloud deployment environments. iii. Strong technical analytical skills with the ability to act as a subject matter expert and execute complex integrations independently. iv. Solid, demonstrable working experience in the application of IT cybersecurity measures, including evaluation, design, and implementation of security controls to strengthen system defenses (b) The proposed candidate must hold at least one valid certificate from (i) and one valid certificate from (ii) before the closing of the bid: i. Certified Information Systems Security Professional from ISC2; or Certified Information Security Professional (CISP) from CNITSEC or Certified Information Systems Auditor (CISA) from ISACA ii. Certified Information Security Professional (OSCP) from OffSec or Offensive Security Experienced Penetration Tester (OSEP) from OffSec or Certified Information Security Professional &;#8211; Penetration Testing Engineer (CISP-PTE) from CNITSEC or Certified Information Security Professional &;#8211; Penetration Testing Specialist (CISP-PTS) from CNITSEC or Certified Ethical Hacker (CEH) from EC-Council or CompTIA Security+ from CompTIA or CompTIA Cybersecurity Analyst (CySA+) from CompTIA (c) Good command of verbal and written communication in both English and Chinese. (d) Self-motivated, independent, diligent, polite, pro-active, fast learning, highly resilient under pressure, and a natural team contributor. (e) Flexibility to work outside normal office hours to support scheduled maintenance windows, on-call production recoveries, and emergency cutovers. (f) Willingness to travel to and operate from remote correctional facilities for on-site technical deployment and emergency support services as needed. (g) Successful completion of an integrity check by the Hong Kong Police Force (HKPF) is a strict prerequisite.
Technical skills:
Coordination (24), Data Encryption Technology (36), Disaster Recovery Planning (24), Endpoint Security Solutions (36), Exp. in Managing Corporate IT Security Framework (12), Infrastructure (36), Internet/ Intranet (36), IT Procurement (24), IT Security (24), IT Security Scanning Tools (12), UNIX (24), Vendor Management (24)