Manager, Information Security

Dah Sing Bank Ltd
  • San Francisco, CA
    3 days ago

    Job Description

    Role Purpose

    Support the bank's cyber defence functions by assisting with MSSP operations, performing security assurance tasks, and participating in purple team exercises. This role provides hands on exposure to security monitoring, control testing, and threat based validation activities in a regulated banking environment.

    Key Responsibilities

    • Monitor MSSP alerts and escalations, ensuring timely follow up with internal teams.
    • Perform initial triage security events under supervision.
    • Assist in maintaining SIEM/EDR use cases and updating detection rules.
    • Prepare MSSP performance summaries and KPI reports.
    • Support control testing activities across EDR, network security, and application security.
    • Collect evidence from system owners and validate completeness and accuracy.
    • Assist in documenting test results, findings, and remediation tracking.
    • Help maintain assurance documentation, checklists, and compliance records.
    • Participate in purple team exercises by documenting attack steps, detection results, and gaps.
    • Assist in mapping detection coverage to MITRE ATT&CK techniques.
    • Update detection logic and playbooks based on purple team outcomes.
    • Lead the end to end vulnerability management lifecycle: discovery, validation, risk rating, tracking, and closure.
    • Coordinate patch cycles
    • Conduct proactive threat hunting exercises to identify and mitigate advanced persistent threats (APTs) and other sophisticated attack vectors.
    • Ability to conduct attack simulations (e.g., Metasploit, Cobalt strike) to validate detection coverage.

    Qualifications & Experience

    • Bachelor's degree in Information Security, Computer Science, or related discipline.
    • 3-5 years of experience in cybersecurity, SOC, IT operations, or risk/compliance.
    • Basic understanding of SIEM, EDR, network security, and common attack techniques.
    • Familiarity with security frameworks (NIST CSF, ISO 27001, OWASP) is an advantage.
    • Experience in banking or finance sectors is a plus
    • Possession of relevant of HKMA ECF certifications in cybersecurity.

    Numbers & Facts

    LocationSan Francisco, CA

    Skills

    • Applications Securityunmatched
    • Banking Servicesunmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Event Managementunmatched
    • Financeunmatched
    • Huntingunmatched
    • ISO (International Organization for Standardization)unmatched
    • Information/Data Security (InfoSec)unmatched
    • Internet Securityunmatched
    • Metasploitunmatched
    • Network Securityunmatched
    • Operations Security (OPSEC)unmatched
    • Patient Assessmentunmatched
    • Performance Metricsunmatched
    • Product Lifecycleunmatched
    • Riskunmatched
    • Security Attacksunmatched
    • Security Information and Event Management (SIEM)unmatched
    • Security Monitoringunmatched
    • Software Patchesunmatched
    • System Validationunmatched
    • Team Playerunmatched
    • Time Managementunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • Use Casesunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder